Commit Graph

  • c11ea35d53 adding some user input for "refreshing" cases (like redirect ones) Miroslav Stampar 2011-05-27 22:42:23 +00:00
  • cf69809c3c minor update Miroslav Stampar 2011-05-27 16:26:00 +00:00
  • 8227298057 user friendliness uber 9000 Miroslav Stampar 2011-05-27 08:30:52 +00:00
  • a8b58afdb2 minor update Miroslav Stampar 2011-05-27 08:21:02 +00:00
  • 48f52d7697 minor beautification Miroslav Stampar 2011-05-27 08:16:14 +00:00
  • 9f6b70f3f9 update Miroslav Stampar 2011-05-26 22:45:33 +00:00
  • 61b960f65f minor update related to the last one Miroslav Stampar 2011-05-26 22:05:10 +00:00
  • 45caadbd4a important update - finally found what was causing headache for UNION payloads in noticeable number of cases Miroslav Stampar 2011-05-26 21:54:19 +00:00
  • 97bd5355dd minor update Miroslav Stampar 2011-05-26 21:18:55 +00:00
  • 5d56e89cf5 minor update Miroslav Stampar 2011-05-26 21:08:46 +00:00
  • 06108b6da6 minor update related to the last commit Miroslav Stampar 2011-05-26 20:58:24 +00:00
  • 4f46a5ab63 minor usability enhancement regarding warning for --text-only switch Miroslav Stampar 2011-05-26 20:48:18 +00:00
  • ff030e4d24 minor cleanup of the leftover Miroslav Stampar 2011-05-26 17:37:24 +00:00
  • bf2b58ba82 minor update Miroslav Stampar 2011-05-26 15:23:28 +00:00
  • 79f0b3a92a adding support for --start and --stop for __pivotDumpTable Miroslav Stampar 2011-05-26 15:16:57 +00:00
  • b6fe5b12a4 adding --schema to the wizard/Basic as it looks like a cool thingy to put there Miroslav Stampar 2011-05-26 14:30:05 +00:00
  • 46ceb14f37 update of doc/THANKS Miroslav Stampar 2011-05-26 13:49:42 +00:00
  • 4f2c999146 fix for a bug reported by mail@8dh.de (UnicodeDecodeError: requestMsg += "\n%s" % requestHeaders) Miroslav Stampar 2011-05-26 13:47:20 +00:00
  • 9077eadf23 update of doc/THANKS Miroslav Stampar 2011-05-26 08:22:52 +00:00
  • a397baa89a fix for a bug reported by viniciusmaxdaloop@gmail.com and few related patches Miroslav Stampar 2011-05-26 08:17:21 +00:00
  • f3ed61af5f bug fix when using inference and kb.pageEncoding is None (like in binary cases) Miroslav Stampar 2011-05-25 21:12:12 +00:00
  • 5369657cd5 fix for cases with retrieved binary files (preventing difflib nagging around comparison) Miroslav Stampar 2011-05-25 20:54:30 +00:00
  • a1fd2898a0 added friendly tip message for url encoding GET and POST payloads Miroslav Stampar 2011-05-25 11:10:52 +00:00
  • 0e480a9921 adding SYS to the ORACLE_SYSTEM_DBS Miroslav Stampar 2011-05-25 10:55:47 +00:00
  • 2f456bee75 minor beautification Miroslav Stampar 2011-05-25 08:14:39 +00:00
  • 8b7a3c5a6b making it easier for totally dummy users Miroslav Stampar 2011-05-24 17:24:01 +00:00
  • bec2c04671 helping dummy users Miroslav Stampar 2011-05-24 17:15:25 +00:00
  • a3466ff79c serving everything for the users Miroslav Stampar 2011-05-24 16:34:08 +00:00
  • 69eb173eca minor just in case patch Miroslav Stampar 2011-05-24 15:07:37 +00:00
  • 0072c3af8e fix for a bug reported by aboynes@gmail.com (for elt in self.a) Miroslav Stampar 2011-05-24 15:03:21 +00:00
  • f774d8fea0 proper Tor settings (reverted r3915 and implemented it the right way) Miroslav Stampar 2011-05-24 11:06:58 +00:00
  • 0486d1cdaa minor module update Miroslav Stampar 2011-05-24 10:32:21 +00:00
  • 915c206e3d minor fix for socks proxy issues Miroslav Stampar 2011-05-24 09:47:10 +00:00
  • 0baf931669 real generic comment is "-- " not "--" (MySQL doesn't support "--") Miroslav Stampar 2011-05-24 09:16:21 +00:00
  • ad25bcc2be better way for dealing with relative paths Miroslav Stampar 2011-05-24 05:26:51 +00:00
  • a536bf210f improved redirection mechanism Miroslav Stampar 2011-05-23 23:20:03 +00:00
  • 128a012121 this was causing that --suffix trouble Miroslav Stampar 2011-05-23 19:59:07 +00:00
  • bfe8e51b7c minor fix for retrieving stuff like "SELECT * FROM testdb..users" Miroslav Stampar 2011-05-23 19:45:40 +00:00
  • 1067d43f14 minor update Miroslav Stampar 2011-05-23 19:16:29 +00:00
  • 2b12b18357 incorporating metasploit patch from oliver.kuckertz@mologie.de Miroslav Stampar 2011-05-23 15:27:10 +00:00
  • 4542d4535f minor beautification Miroslav Stampar 2011-05-23 14:28:05 +00:00
  • 31b48ec11c removing space left Miroslav Stampar 2011-05-23 14:18:33 +00:00
  • 0ed03d474f now supporting "blank tables" - schema of the table will be preserved, even if it's empty - especially nice feature for --replicate Miroslav Stampar 2011-05-23 11:09:44 +00:00
  • 868fbe370b minor beautification Miroslav Stampar 2011-05-23 10:39:58 +00:00
  • 171a4c389b added MySQL >=4.1 <=5.0 error based WHERE/HAVING payload Miroslav Stampar 2011-05-23 06:24:45 +00:00
  • fb23beef6f most elegant way i could think of to deal with "collation incompatibilities" issue on some MySQL/UNION cases (affected about 5% of all targets tested) Miroslav Stampar 2011-05-22 19:14:36 +00:00
  • 4fdb6ac9b9 adding useful info Miroslav Stampar 2011-05-22 15:30:19 +00:00
  • 48c20a62ac minor nag fix Miroslav Stampar 2011-05-22 15:08:55 +00:00
  • 40971aca94 fixing nasty bug caused by retrying counter Miroslav Stampar 2011-05-22 10:59:56 +00:00
  • 712e238f33 another minor fix Miroslav Stampar 2011-05-22 10:29:25 +00:00
  • 2795aeff34 minor fix Miroslav Stampar 2011-05-22 10:27:45 +00:00
  • 806e898694 no more CRITICAL drop outs in test mode - lots of reports were related to this Miroslav Stampar 2011-05-22 10:21:49 +00:00
  • 7b52bbe3fb reverting that ignoreTimeout for --tables (because of this and that) Miroslav Stampar 2011-05-22 09:59:19 +00:00
  • 9b2623514a one bug fix for Host header (value should be without port number); one improvement for --tables - when no tables ask user if he wants to brute force them; one tweak - adding kb.ignoreTimeout for --tables Miroslav Stampar 2011-05-22 09:48:46 +00:00
  • 2ea613b170 type correction and adding global flag kb.ignoreTimeout which could be useful Miroslav Stampar 2011-05-22 08:24:13 +00:00
  • 27f0e73cc9 refactoring of 'target' flag in connect.py Miroslav Stampar 2011-05-22 07:46:09 +00:00
  • a58aaf2e1a better format for results file (easier for sorting when lots of files) Miroslav Stampar 2011-05-22 07:02:36 +00:00
  • 25fff8c135 changes in handling --tor (using SOCKS instead of HTTP for handling Tor - more standard way; doesn't require proxy bundle; fixes problems with default proxy ports on Win/Linux) Miroslav Stampar 2011-05-21 11:46:57 +00:00
  • 939e6541d0 far safer way for dealing with error-based payloads on MySQL (no timeouts with .CHARACTER_SETS on testing platforms versus when used .TABLES) Miroslav Stampar 2011-05-19 23:36:51 +00:00
  • 126cdf9e19 minor info update Miroslav Stampar 2011-05-19 23:28:27 +00:00
  • a034462c31 fixing annoying timeouts for basic DBMS check (reference: http://dev.mysql.com/doc/refman/5.0/en/date-and-time-functions.html#function_timestampadd) Miroslav Stampar 2011-05-19 23:03:00 +00:00
  • 5a979f7667 minor bug fix for empty colList; also added "do you want to use LIKE" (LIKE is default) question when -C used Miroslav Stampar 2011-05-19 17:35:33 +00:00
  • 9e5856caf8 improvement for recognition of scalar vs multiple-row commands Miroslav Stampar 2011-05-19 16:45:05 +00:00
  • db72428765 minor update Miroslav Stampar 2011-05-19 15:57:29 +00:00
  • f40c6b2ce7 added --cookie for maskSensitiveData too Miroslav Stampar 2011-05-19 15:42:59 +00:00
  • bd1b07fbc2 one more parameter replace payload for MySQL and rising level of GENERATE_SERIES for PostgreSQL Miroslav Stampar 2011-05-19 06:32:23 +00:00
  • 7f086916c0 decent parameter replace payload for PostgreSQL (GENERATE_SERIES) Miroslav Stampar 2011-05-18 23:40:42 +00:00
  • e58d6d2e00 removing (CBRT(LN(0)) because it's nothing special compared to standard 1/0; also, removing parameter replacement with returned value 1 as it doesn't have much sense in comparison to origvalue one (which is far more stable and usable) Miroslav Stampar 2011-05-18 23:20:02 +00:00
  • fe50d09cc8 added new payload for PostgreSQL (parameter replace) Miroslav Stampar 2011-05-18 23:01:41 +00:00
  • 9832fc42d4 minor improvement for --tamper (now standard tamper scripts can be used like --tamper=randomcase) Miroslav Stampar 2011-05-18 21:47:40 +00:00
  • 3048e9f710 minor refactoring Miroslav Stampar 2011-05-17 23:03:31 +00:00
  • cc07e5dc97 added --charset option to force charset encoding of the retrieved data (e.g. when the backend collation is different than the current web page charset) as requested by devon.mitchell1988@y​ahoo.com Miroslav Stampar 2011-05-17 22:55:22 +00:00
  • dfe81cc66f minor yielding Miroslav Stampar 2011-05-16 20:14:10 +00:00
  • a5ad4621c9 minor refactoring Miroslav Stampar 2011-05-16 20:09:12 +00:00
  • ba1df457ab fix for a charset euc_tw reported by devon.mitchell1988@y​ahoo.com Miroslav Stampar 2011-05-16 19:26:58 +00:00
  • 6ba9dea640 just in case for trimmed output Miroslav Stampar 2011-05-16 06:17:37 +00:00
  • d2221e4604 fix for a minor "retrieved" cosmetic issue in partial union technique reported by Devon Mitchell (retrieved: "information_schema","COLUMNS</title><...) Miroslav Stampar 2011-05-16 00:23:50 +00:00
  • faa74cd2bc introducing results file for multiple target mode Miroslav Stampar 2011-05-15 22:21:38 +00:00
  • 90e84c9a6d removing xmlcharrefreplace error handler as it seems that it wasn't such a good idea at the end Miroslav Stampar 2011-05-15 21:43:38 +00:00
  • c3bb5a03e1 minor improvement Miroslav Stampar 2011-05-14 20:09:37 +00:00
  • 3484a4426b fix for a bug reported by itxx@qq.co​m (TypeError: encode() takes no keyword arguments) Miroslav Stampar 2011-05-14 19:57:28 +00:00
  • 053c245114 few minor fixes Miroslav Stampar 2011-05-13 09:56:12 +00:00
  • a7d7be5ce0 bug fix ('Host' header was being set to the conf.hostname for all getPages causing problems in some cases when retrieved page was not coming from that same Host) Miroslav Stampar 2011-05-13 01:01:53 +00:00
  • f11d5c91e3 minor update so that only one DNS request per scan is being done (before this commit there were two) Miroslav Stampar 2011-05-12 14:32:39 +00:00
  • 70688fb8b5 minor enhancement for dumping 'None' values (proper way should be empty string because None is too pythonic) Miroslav Stampar 2011-05-12 12:00:17 +00:00
  • c64eb38a8b same thing as for the last commit, but for error technique this time Miroslav Stampar 2011-05-12 11:52:18 +00:00
  • 84a7e5ffb9 "unfix" for r3172 which was causing "AttributeError: 'list' object has no attribute 'isdigit'" because of change of appereance Miroslav Stampar 2011-05-12 11:36:02 +00:00
  • 0b2da2f9f5 minor beautification for --tor switch Miroslav Stampar 2011-05-12 05:46:17 +00:00
  • e05a9c0554 i was probably very tired or very stupid to do this Miroslav Stampar 2011-05-11 13:13:46 +00:00
  • 2ab9e30f7a bug fix Miroslav Stampar 2011-05-11 12:54:33 +00:00
  • 4efc284b83 adding more info for --passwords Miroslav Stampar 2011-05-11 12:35:32 +00:00
  • 48ac9911c0 more graceful fix related to the last commit Miroslav Stampar 2011-05-11 09:42:35 +00:00
  • 402c623119 minor fix Miroslav Stampar 2011-05-11 09:40:11 +00:00
  • 53065ee1fb adding ordered set for kb.targetUrls (now the order of appereance in multiple targets mode will be respected) Miroslav Stampar 2011-05-11 08:55:48 +00:00
  • 5ee07b90b9 added -m switch for bulk loading multiple targets Miroslav Stampar 2011-05-11 08:46:40 +00:00
  • 120b0d756e unfix Miroslav Stampar 2011-05-10 21:33:06 +00:00
  • 6b66fce72c minor fix Miroslav Stampar 2011-05-10 20:52:43 +00:00
  • 192c685bc8 changing conf attribute to a more proper name Miroslav Stampar 2011-05-10 20:48:34 +00:00
  • deae534ee7 minor refactoring Miroslav Stampar 2011-05-10 20:44:36 +00:00
  • 97bc816aeb layout Bernardo Damele 2011-05-10 16:24:09 +00:00