Commit Graph

  • 03220d34ba added Ctrl+C check in detection phase Miroslav Stampar 2010-12-18 10:42:09 +00:00
  • e355f92f22 bug fix Miroslav Stampar 2010-12-18 10:02:01 +00:00
  • fe67d3827c code refactoring and some fixes Miroslav Stampar 2010-12-18 09:51:34 +00:00
  • a067e805fa minor update Miroslav Stampar 2010-12-17 22:23:01 +00:00
  • 108a96c6b4 some fixes Miroslav Stampar 2010-12-17 21:45:20 +00:00
  • a19cb2c13a code refactoring (added UNKNOWN_DBMS_VERSION instead of "Unknown") Miroslav Stampar 2010-12-17 21:29:09 +00:00
  • b4450c6ddd added one more level of MSSQL version check (if first fails for some reason) Miroslav Stampar 2010-12-17 21:01:14 +00:00
  • 07609bfb53 minor fix Miroslav Stampar 2010-12-17 19:33:20 +00:00
  • bfdc4fa000 new error vector for MS SQL (from David Guimaraes' mail) Miroslav Stampar 2010-12-17 19:00:20 +00:00
  • 323af45ce4 added one more time request payload to confirm test results Miroslav Stampar 2010-12-17 07:53:58 +00:00
  • e3fa3b0e8e fix for a minor bug reported by nightman (AttributeError: 'NoneType' object has no attribute 'getFingerprint') Miroslav Stampar 2010-12-17 07:48:32 +00:00
  • 95b2c0803b minor fix Miroslav Stampar 2010-12-15 20:51:29 +00:00
  • de54219571 code refactoring Miroslav Stampar 2010-12-15 12:50:56 +00:00
  • cda00c7501 code refactoring Miroslav Stampar 2010-12-15 12:43:56 +00:00
  • 3f34b06a24 minor cosmetics Miroslav Stampar 2010-12-15 12:34:14 +00:00
  • 445cc3bf3c minor cosmetics Miroslav Stampar 2010-12-15 12:15:43 +00:00
  • c1c525aaea quick fix of a fix Miroslav Stampar 2010-12-15 12:10:33 +00:00
  • 7cfeb5447b minor update Miroslav Stampar 2010-12-15 11:46:28 +00:00
  • 4dec24d056 quick fix for a bug reported by Andreas Constantinides (KeyError: 5) Miroslav Stampar 2010-12-15 11:30:29 +00:00
  • f8a01ddaf8 minor update Miroslav Stampar 2010-12-15 11:21:47 +00:00
  • 63f5c35c23 bug fix Miroslav Stampar 2010-12-15 10:02:58 +00:00
  • 3ee44584d4 i've found a way! thank you hesus! fyea (ASC(MID) was just crashing when MID returned 'empty string') Miroslav Stampar 2010-12-14 12:57:59 +00:00
  • c3d0295d21 minor update (checking for --time-sec value) Miroslav Stampar 2010-12-14 12:37:21 +00:00
  • b75d7fa348 minor cache based optimization Miroslav Stampar 2010-12-14 12:22:17 +00:00
  • 270ae0f080 just in case as maybe there will be some boolean expression to check where we won't expect None, but explicitly True/False Miroslav Stampar 2010-12-14 09:05:00 +00:00
  • 4c6e902471 removed obsolete comment Miroslav Stampar 2010-12-14 07:49:30 +00:00
  • 04caef6de0 Tuning Bernardo Damele 2010-12-13 23:04:26 +00:00
  • cfcee6439e Cosmetics Bernardo Damele 2010-12-13 21:55:30 +00:00
  • 86690682c7 Minor bug fix to respect -v value in --common-tables and --common-columns Bernardo Damele 2010-12-13 21:37:12 +00:00
  • 4b79227b5a Minor bug fix to properly merge options from .conf file (-c) with command line switches Bernardo Damele 2010-12-13 21:36:23 +00:00
  • db844c1785 No point in showing the error-based inject payload, it's same as the one showed in -v3 Bernardo Damele 2010-12-13 21:35:20 +00:00
  • 698f30e65e Cosmetics Bernardo Damele 2010-12-13 21:34:35 +00:00
  • a02dd6b55b Minor enhancement to speedup active dbms fingerprint (-f). Code cleanup and refactoring. Bernardo Damele 2010-12-13 21:33:42 +00:00
  • 207f63cebc Prepare for UNION query tests at detection phase Bernardo Damele 2010-12-13 21:31:34 +00:00
  • d56f47d530 fix for a bug reported by black zero (ValueError: invalid literal for int() with base 10: '1-20') Miroslav Stampar 2010-12-12 23:59:55 +00:00
  • 33639578ee minor update for MS Access Miroslav Stampar 2010-12-12 15:25:19 +00:00
  • 6a3c4485e6 minor update (removing extra ()) Miroslav Stampar 2010-12-12 14:44:39 +00:00
  • e98d9c08e1 dumping table is now possible on Firebird too Miroslav Stampar 2010-12-12 14:38:07 +00:00
  • f9bc6fc78f minor fix Miroslav Stampar 2010-12-11 22:14:35 +00:00
  • c93634b6c7 blind dumping of tables in sqlite implemented Miroslav Stampar 2010-12-11 22:13:19 +00:00
  • b1babeefe5 update regarding dumping of tables with blind on Sqlite Miroslav Stampar 2010-12-11 22:00:16 +00:00
  • f7344a5fc3 update Miroslav Stampar 2010-12-11 21:28:11 +00:00
  • 6a24048aa6 urllib2 doesn't play well with '\n' when non unescaped chars used Miroslav Stampar 2010-12-11 21:17:54 +00:00
  • e6c66fa37c update regarding expectingNone in fingerprinting mode to cancel drop down to other techniques available Miroslav Stampar 2010-12-11 17:55:28 +00:00
  • e32fa9df43 further update regarding bugtrace's report Miroslav Stampar 2010-12-11 17:32:15 +00:00
  • 5d18c98ec2 quick fix for a bug reported by bugtrace (not using __goBooleanProxy because we don't have a proper vector this moment) Miroslav Stampar 2010-12-11 17:20:39 +00:00
  • 03447acc1d avoiding some trashy match ratios Miroslav Stampar 2010-12-11 17:12:19 +00:00
  • d2a3e8f44f first time firebird error-based query success Miroslav Stampar 2010-12-11 11:17:24 +00:00
  • acc7d6d40c fix Miroslav Stampar 2010-12-11 11:03:32 +00:00
  • f021548bd0 added inference failsafe (like in for instance Firebirds SUBSTR always returns a string value, no matter which starting index you use) Miroslav Stampar 2010-12-11 10:52:04 +00:00
  • c17f444aab minor fix Miroslav Stampar 2010-12-11 10:22:18 +00:00
  • 1beb1dd2cc minor update Miroslav Stampar 2010-12-11 09:30:38 +00:00
  • 3dc0a51d34 major bug fix with boolean expressions Miroslav Stampar 2010-12-11 08:46:19 +00:00
  • ac9080c07b update Miroslav Stampar 2010-12-11 08:24:29 +00:00
  • 66db80804d fix Miroslav Stampar 2010-12-10 16:03:32 +00:00
  • 435f48b8cc polite cosmetics Miroslav Stampar 2010-12-10 15:28:56 +00:00
  • 977988c0ab cosmetics Miroslav Stampar 2010-12-10 15:24:25 +00:00
  • fa8d378e80 another update Miroslav Stampar 2010-12-10 15:18:15 +00:00
  • 1ef44cfe60 fix Miroslav Stampar 2010-12-10 15:06:53 +00:00
  • fe186cde55 proper fix Miroslav Stampar 2010-12-10 13:26:31 +00:00
  • 9957881040 you won't believe commit Miroslav Stampar 2010-12-10 13:20:59 +00:00
  • 7c87ad4065 Minor speedup in -f mysql Bernardo Damele 2010-12-10 13:05:46 +00:00
  • b02bd55edc minor refactoring Miroslav Stampar 2010-12-10 13:04:36 +00:00
  • 1fc9ed10a8 minor refactoring Miroslav Stampar 2010-12-10 12:30:36 +00:00
  • 4d8628e8fb fix for booleans Miroslav Stampar 2010-12-10 12:26:01 +00:00
  • fe2039f5ba coollyy little commits Miroslav Stampar 2010-12-10 11:32:46 +00:00
  • d71e51e765 Minor improvement Bernardo Damele 2010-12-10 11:31:27 +00:00
  • 4741874e9e Enhancement to speedup MySQL fingerprint Bernardo Damele 2010-12-10 11:27:36 +00:00
  • e98b81fe32 another update Miroslav Stampar 2010-12-10 10:56:55 +00:00
  • d5e7a8d305 update Miroslav Stampar 2010-12-10 10:54:17 +00:00
  • b6dcbcef5b Minor fix Bernardo Damele 2010-12-10 10:52:55 +00:00
  • 471d9ccd65 another fix of my lala Miroslav Stampar 2010-12-10 10:11:25 +00:00
  • 029a6abba2 quick fix Miroslav Stampar 2010-12-10 09:54:25 +00:00
  • 441fc8dbd9 update regarding boolean based expressions Miroslav Stampar 2010-12-09 21:15:18 +00:00
  • d5fb921154 removed debug print Miroslav Stampar 2010-12-09 20:08:59 +00:00
  • 1492823de0 it wasn't pretty, now it's pretty Miroslav Stampar 2010-12-09 20:06:20 +00:00
  • bbffea2cbc bug fix Miroslav Stampar 2010-12-09 17:10:22 +00:00
  • 0eb2c408a9 code refactoring Miroslav Stampar 2010-12-09 16:49:02 +00:00
  • 7e2984b4b6 added stacked query support for Oracle Miroslav Stampar 2010-12-09 15:24:48 +00:00
  • 4bb40c0a06 Higher the level for Oracle stacked tests just in case the SQL inj is within a PL/SQL function ('cause of no support for stacked queries by design on Oracle) Bernardo Damele 2010-12-09 15:14:18 +00:00
  • d8edc5b244 adding stacked-query vector for Firebird Miroslav Stampar 2010-12-09 15:11:21 +00:00
  • 13b522efc2 Added error-based support for MySQL < 5.0 - closes #14 Bernardo Damele 2010-12-09 15:09:03 +00:00
  • 5aafd19957 added vector for SQLite's stacked query payload Miroslav Stampar 2010-12-09 15:06:40 +00:00
  • df5f6bc1b7 Little precaution Bernardo Damele 2010-12-09 14:06:43 +00:00
  • 9230877d98 cosmetics Bernardo Damele 2010-12-09 13:57:38 +00:00
  • 5114c887ea minor minor update Miroslav Stampar 2010-12-09 13:51:44 +00:00
  • 5fb04515d3 Added hidden (for the moment) switch --technique Bernardo Damele 2010-12-09 13:47:17 +00:00
  • b80a86a669 that's it for common stuff today Miroslav Stampar 2010-12-09 12:59:22 +00:00
  • b26e09fc71 another minor update Miroslav Stampar 2010-12-09 12:49:29 +00:00
  • f712d2477e removed duplicate entries inside common wordlists (tables & columns) and added a script which does that automatically Miroslav Stampar 2010-12-09 12:41:16 +00:00
  • c5b1f336ee another update Miroslav Stampar 2010-12-09 12:07:06 +00:00
  • 06395b5408 update Miroslav Stampar 2010-12-09 12:03:10 +00:00
  • cdff29ada7 update Miroslav Stampar 2010-12-09 11:23:44 +00:00
  • 196131bbca minor cosmetics Miroslav Stampar 2010-12-09 10:42:00 +00:00
  • 71761ba9a5 another fix for another beautiful heavy query payload which took a few 100 megs and 5 mins to run Miroslav Stampar 2010-12-09 10:35:18 +00:00
  • 094baadc5b bug fix (in SELECT based heavy queries COUNT(*) should be used; otherwise multiple row error happens without proper delay) Miroslav Stampar 2010-12-09 10:17:04 +00:00
  • ec5c08ca7a cosmetics Miroslav Stampar 2010-12-09 09:24:20 +00:00
  • 3fd1c37d53 update Miroslav Stampar 2010-12-09 07:49:18 +00:00
  • db39dc32fc minor update Miroslav Stampar 2010-12-09 00:59:39 +00:00
  • 0c01be0eeb Ugly work-around to avoid unescaping WAITFOR DELAY time between single quotes (unescaped CHAR(..) value does not work). Bernardo Damele 2010-12-09 00:34:02 +00:00