Commit Graph

  • 5dfb55effc revert of the last commit because of this http://osvdb.org/show/osvdb/26582 Miroslav Stampar 2011-04-14 06:46:32 +00:00
  • 786f305e1a minor update Miroslav Stampar 2011-04-14 06:43:08 +00:00
  • 21114d1748 added IGNORE_PARAMETERS to skip testing of state/session web server parameters Miroslav Stampar 2011-04-13 19:01:02 +00:00
  • 58a93c5b1f better beep for MacOSX Miroslav Stampar 2011-04-13 18:32:47 +00:00
  • bf55b0b77a more restrictions on crypt(3) hash recognition to prevent false positives Miroslav Stampar 2011-04-13 14:40:23 +00:00
  • d06ae9cd47 implemented retrieved items info for partial union too Miroslav Stampar 2011-04-13 14:33:15 +00:00
  • f5f2201bbc minor cosmetics for partial inband retrieval Miroslav Stampar 2011-04-13 11:25:42 +00:00
  • c193b896be just in case update to prevent gibberish "retrieved: " outputs Miroslav Stampar 2011-04-12 23:07:50 +00:00
  • f435f37d71 update of THANKS file Miroslav Stampar 2011-04-12 15:54:00 +00:00
  • 5346ecbb56 fix for a "accept certificate first time for svn" Miroslav Stampar 2011-04-12 14:25:17 +00:00
  • a883ce26b5 fix for a bug reported by ToR (AttributeError: 'NoneType' object has no attribute 'redcode') Miroslav Stampar 2011-04-12 13:25:28 +00:00
  • 1c51e11c5c Minor adjustments to PgSQL fingerprint Bernardo Damele 2011-04-12 10:35:33 +00:00
  • 7324d53997 reference (http://www.enterprisedb.com/docs/en/9.0/pg/release-9-0.html) Miroslav Stampar 2011-04-12 10:30:33 +00:00
  • bc4c2f320c cosmetics Miroslav Stampar 2011-04-12 10:24:09 +00:00
  • 2f1786e65f added active fingerprint for pgsql >= 9.0.3 (reference: http://www.postgresql.org/docs/9.0/static/release-9-0.html) Miroslav Stampar 2011-04-12 10:22:54 +00:00
  • 7c61931b96 Added notes on how to compile and get small shared libraries for UDF Bernardo Damele 2011-04-12 09:53:52 +00:00
  • b50b4cd961 MySQL Windows 32-bit DLL recompiled (Visual C++ 2005) and stripped (UPX) - this is the smallest we can get Bernardo Damele 2011-04-11 22:04:41 +00:00
  • fdbd8bfe37 initial support for PostgreSQL 9.0 - #223 Bernardo Damele 2011-04-11 22:02:00 +00:00
  • f4745a95ea Possible fix for bug reported by David Bernardo Damele 2011-04-11 21:45:25 +00:00
  • 136e85abf3 little refresh of PHPIDS rules for --check-payload Miroslav Stampar 2011-04-11 15:37:49 +00:00
  • 0ae74f27e4 avoiding annoying "payload 'None' possibly..." in case where payload is not specified Miroslav Stampar 2011-04-11 15:24:52 +00:00
  • 941daa1645 just in case to prevent "object of type 'NoneType' has no len()" error reports Miroslav Stampar 2011-04-11 11:59:02 +00:00
  • 2db2e9b6a2 now GET forms are also prone to "do you want to fill with random values" Miroslav Stampar 2011-04-11 11:38:41 +00:00
  • 08d14886fd added new dev version string Miroslav Stampar 2011-04-11 09:44:44 +00:00
  • e20848c711 first commit toward v1.0 (it's smarter to start testing for pivot point from shorter column names as they tend to be some kind of identifiers) Miroslav Stampar 2011-04-11 09:40:52 +00:00
  • 30377621b8 slight update Bernardo Damele 2011-04-11 00:33:42 +00:00
  • 07d6b18c4e cutting for 0.9 stable 0.9 Bernardo Damele 2011-04-11 00:24:51 +00:00
  • 2f8ddd156c done with the manual Bernardo Damele 2011-04-11 00:23:47 +00:00
  • ea3ebafba1 Removed outdated sentence Bernardo Damele 2011-04-10 23:59:49 +00:00
  • 75f286cf6d minor update conformant to http://dev.mysql.com/doc/refman/4.1/en/comments.html Miroslav Stampar 2011-04-10 23:41:00 +00:00
  • 3177c6023d lol. re-revert Miroslav Stampar 2011-04-10 23:30:56 +00:00
  • 572708f184 More version adjustment Bernardo Damele 2011-04-10 23:28:24 +00:00
  • 9ea4010508 Leave it as is :) Bernardo Damele 2011-04-10 23:20:35 +00:00
  • 3e680978a9 revert of that last commit (waiting for some better days) Miroslav Stampar 2011-04-10 23:18:38 +00:00
  • f532478a34 update of MySQL comments Miroslav Stampar 2011-04-10 23:08:18 +00:00
  • 8597409d9e lowering the value Miroslav Stampar 2011-04-10 22:57:17 +00:00
  • 14219a3dac Minor bug fix Bernardo Damele 2011-04-10 22:44:08 +00:00
  • 6012ab1c46 better one for previous commit Miroslav Stampar 2011-04-10 21:52:08 +00:00
  • af096b2c83 Leave it as is!!! Bernardo Damele 2011-04-10 21:47:23 +00:00
  • e6c50df4f9 preventing case duplicates for --common-tables (as some DBMSes have case sensitive table names we can't just use them all with the same case) Miroslav Stampar 2011-04-10 21:38:08 +00:00
  • d0cef21d9c fix Miroslav Stampar 2011-04-10 21:19:34 +00:00
  • 940c225d7c few fixes Miroslav Stampar 2011-04-10 20:53:27 +00:00
  • d324704844 Removed unused code Bernardo Damele 2011-04-10 20:39:15 +00:00
  • 9840a0491d more doc updates Bernardo Damele 2011-04-10 20:31:29 +00:00
  • fbf8e7f32d Minor bug fix to --file-read Bernardo Damele 2011-04-10 19:53:42 +00:00
  • decab6642d fix for that @chunk bug Miroslav Stampar 2011-04-10 16:46:33 +00:00
  • 7dd5bd9d59 Minor fix for --cleanup on MSSQL Bernardo Damele 2011-04-10 13:48:29 +00:00
  • 6d165861c8 Minor version increase Bernardo Damele 2011-04-10 13:30:27 +00:00
  • fe16360acb more doc updates Bernardo Damele 2011-04-10 13:28:14 +00:00
  • 723a7447b2 minor refactoring Miroslav Stampar 2011-04-10 07:16:19 +00:00
  • c714ac6421 added support for handling binary data values (no more garbish chars) Miroslav Stampar 2011-04-09 23:13:16 +00:00
  • 4ad73f9263 added two new valuable functions for dealing with binary data (e.g. binary representations of password hashes) and some cosmetics Miroslav Stampar 2011-04-09 22:39:03 +00:00
  • 277f16d6b3 removing commented out debug print Miroslav Stampar 2011-04-08 22:44:05 +00:00
  • c4c40308c6 no more annoying "no metasploit found" for case when msfpath provided with root directory of Metasploit (not the bin one) Miroslav Stampar 2011-04-08 22:42:07 +00:00
  • 83feb097ef greater flexibility for --batch when default is None Miroslav Stampar 2011-04-08 22:29:50 +00:00
  • 6fa2fd139c implemented support for __pivotDumpTable on MSSQL as normal tables tend to not play well with normal TOP 1 ..NOT IN..ORDER BY mechanism if the argument for ORDER BY is not the unique one (returns only number of rows equal to the number of distinct values for that field) Miroslav Stampar 2011-04-08 15:17:57 +00:00
  • beb98140b3 Minor improvement to --check-payload Bernardo Damele 2011-04-08 14:34:00 +00:00
  • d5fb1378cc Gone unnoticed for way too long Bernardo Damele 2011-04-08 11:15:19 +00:00
  • 228cc68747 fix for those ugly DEBUG messages in brute mode Miroslav Stampar 2011-04-08 11:02:21 +00:00
  • 5b21352656 cosmeticados ;) Bernardo Damele 2011-04-08 10:39:07 +00:00
  • 64fcc88be5 typo Bernardo Damele 2011-04-08 10:26:03 +00:00
  • 1be7f859c6 Minor updates Bernardo Damele 2011-04-08 10:25:37 +00:00
  • bcc4c52cf7 minor update Miroslav Stampar 2011-04-08 10:21:45 +00:00
  • 159789ba81 More user's manual updates Bernardo Damele 2011-04-08 10:20:42 +00:00
  • d305183447 More updates to user's manual Bernardo Damele 2011-04-08 09:50:34 +00:00
  • be11e2535e one more minor update Miroslav Stampar 2011-04-08 00:05:44 +00:00
  • 3435d549a9 minor update regarding the last commit Miroslav Stampar 2011-04-07 23:35:51 +00:00
  • 726155383d higher compatibility with MSSQL 2000 ("ORDER BY items must appear in the select list if the statement contains a UNION operator.") as we always take the first field from the list as the one for referencing (field = expressionFieldsList[0]) Miroslav Stampar 2011-04-07 23:32:07 +00:00
  • e8259a7665 minor update (now --dump also supports only -D parameter) Miroslav Stampar 2011-04-07 22:38:13 +00:00
  • bac53eeef1 Allow --dump-all to accept -D switch in order to dump all tables' entries for only one (or more, comma-separated) specified database(s) Bernardo Damele 2011-04-07 22:08:10 +00:00
  • b288e5ef57 implemented DNS caching mechanism Miroslav Stampar 2011-04-07 21:39:18 +00:00
  • ae4ea0af45 fix for a bug reported by m4l1c3 (AttributeError: 'NoneType' object has no attribute 'replace') Miroslav Stampar 2011-04-07 13:57:07 +00:00
  • 02eeeccd33 Added UNION query SQL injection tests also with a random number for columns (not only NULL) Bernardo Damele 2011-04-07 13:39:36 +00:00
  • 6a8a5db9aa minor code restyling Miroslav Stampar 2011-04-07 13:27:29 +00:00
  • e33a48d40f minor refactoring Miroslav Stampar 2011-04-07 12:54:30 +00:00
  • c6b9d89d31 Accept [RANDNUM] as <char> in payloads.xml and handle it accordingly Bernardo Damele 2011-04-07 11:10:35 +00:00
  • ca009e9fe2 minor update Miroslav Stampar 2011-04-07 10:43:19 +00:00
  • 672abc27fd minor adjustment of livetests for new flavor of --technique Miroslav Stampar 2011-04-07 10:41:12 +00:00
  • 9e8c933333 cosmetics Bernardo Damele 2011-04-07 10:40:58 +00:00
  • 68828d68a5 removed integers from --technique Miroslav Stampar 2011-04-07 10:37:48 +00:00
  • fced81b6be minor update Miroslav Stampar 2011-04-07 10:32:39 +00:00
  • 845533e92f minor refactoring Miroslav Stampar 2011-04-07 10:27:22 +00:00
  • 1880f18367 Minor layout adjustments Bernardo Damele 2011-04-07 10:07:52 +00:00
  • 17844eb87c Refactoring to --technique Bernardo Damele 2011-04-07 10:00:47 +00:00
  • 287f74dbd2 update Bernardo Damele 2011-04-06 14:59:51 +00:00
  • 05d12790f1 closes #219 - unhidden switch --technique and adapted code accordingly (renamed conf.technique to conf.tech to fit properly in the -h help message) Bernardo Damele 2011-04-06 14:41:44 +00:00
  • 8b14a9eaa7 Minor code adjustments Bernardo Damele 2011-04-06 14:40:45 +00:00
  • a379463213 cosmeticado Miroslav Stampar 2011-04-06 08:40:06 +00:00
  • b327bbcd9b minor fix (it was quite ... to have this check at the later stage) Miroslav Stampar 2011-04-06 08:39:24 +00:00
  • fdef6726cf minor update Miroslav Stampar 2011-04-06 08:30:50 +00:00
  • 72555f3b28 user's manual updated.. we are getting close to 0.9 stable, stay tuned! Bernardo Damele 2011-04-06 08:21:13 +00:00
  • d436ba2da5 Minor "fix" when reading hashes from a local sqlite3 (result of --replicate) and there is an int as value Bernardo Damele 2011-04-06 08:19:56 +00:00
  • 81034140c0 Reduced number of threads to 3 when -o is provided Bernardo Damele 2011-04-06 08:15:20 +00:00
  • 265fa52600 minor code cosmetics Miroslav Stampar 2011-04-04 18:24:16 +00:00
  • 018b6b9430 fix for a charset encoding reported by Kirill Miroslav Stampar 2011-04-04 18:20:09 +00:00
  • a1bde071d8 Minor adjustments Bernardo Damele 2011-04-04 09:26:20 +00:00
  • 2c01fc56e6 minor update regarding misusage of --proxy and --ignore-proxy switches Miroslav Stampar 2011-04-04 09:19:43 +00:00
  • 3253882071 minor cosmetics on tamper scripts Miroslav Stampar 2011-04-04 08:18:26 +00:00
  • 33d987805d minor revisit of encoding tampering scripts Miroslav Stampar 2011-04-04 08:11:11 +00:00
  • e957c4400c minor revisit of tampering script(s) functionality (urlencode one is removed as it's currently obsolete regarding the whole process of automatic urlencoding) Miroslav Stampar 2011-04-04 08:04:47 +00:00