<?xml version="1.0" encoding="UTF-8"?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns="http://purl.org/rss/1.0/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:syn="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/">
  <channel rdf:about="http://blog.gmane.org/gmane.comp.security.sqlmap">
    <title>gmane.comp.security.sqlmap</title>
    <link>http://blog.gmane.org/gmane.comp.security.sqlmap</link>
    <description/>
    <syn:updatePeriod>hourly</syn:updatePeriod>
    <syn:updateFrequency>1</syn:updateFrequency>
    <syn:updateBase>1901-01-01T00:00+00:00</syn:updateBase>
    <items>
      <rdf:Seq>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.sqlmap/2749"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.sqlmap/2748"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.sqlmap/2747"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.sqlmap/2746"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.sqlmap/2745"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.sqlmap/2744"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.sqlmap/2743"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.sqlmap/2742"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.sqlmap/2741"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.sqlmap/2740"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.sqlmap/2739"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.sqlmap/2738"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.sqlmap/2737"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.sqlmap/2736"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.sqlmap/2735"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.sqlmap/2734"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.sqlmap/2733"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.sqlmap/2732"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.sqlmap/2731"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.sqlmap/2730"/>
      </rdf:Seq>
    </items>
    <image rdf:resource="http://gmane.org/img/gmane-25t.png"/>
    <textinput rdf:resource=""/>
  </channel>
  <image rdf:about="http://gmane.org/img/gmane-25t.png">
    <title>Gmane</title>
    <url>http://gmane.org/img/gmane-25t.png</url>
    <link>http://gmane.org</link>
  </image>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.sqlmap/2749">
    <title>Re: Not getting any sensitive data from database</title>
    <link>http://permalink.gmane.org/gmane.comp.security.sqlmap/2749</link>
    <description>&lt;pre&gt;Hi Marcell.

There is no such capability (and IMO it would be ugly to put a
--banner-md5:), although it makes sense what you are trying to do).

Nevertheless, you can go to xml/queries.xml and change (line 23):

&amp;lt;banner query="VERSION()"/&amp;gt;
to
&amp;lt;banner query="MD5(VERSION())"/&amp;gt;

Kind regards,
Miroslav Stampar


On Sat, May 18, 2013 at 7:36 AM, Marcell Fodor &amp;lt;fodor.email-Re5JQEeQqe8AvxtiuMwx3w&amp;lt; at &amp;gt;public.gmane.org&amp;gt;wrote:



&lt;/pre&gt;</description>
    <dc:creator>Miroslav Stampar</dc:creator>
    <dc:date>2013-05-18T12:37:51</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.sqlmap/2748">
    <title>Not getting any sensitive data from database</title>
    <link>http://permalink.gmane.org/gmane.comp.security.sqlmap/2748</link>
    <description>&lt;pre&gt;Heya,

Is it possible to get the version as md5 hash? I mean a simple
md5(&amp;lt; at &amp;gt;&amp;lt; at &amp;gt;version). The whole point it not pulling any sensitive data from
database. The question comes up when database owner only wants confirmation
of found injection point by md5 hash.

like --banner-md5


M
------------------------------------------------------------------------------
AlienVault Unified Security Management (USM) platform delivers complete
security visibility with the essential security capabilities. Easily and
efficiently configure, manage, and operate all of your security controls
from a single console and one unified framework. Download a free trial.
http://p.sf.net/sfu/alienvault_d2d_______________________________________________
sqlmap-users mailing list
sqlmap-users-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f&amp;lt; at &amp;gt;public.gmane.org
https://lists.sourceforge.net/lists/listinfo/sqlmap-users
&lt;/pre&gt;</description>
    <dc:creator>Marcell Fodor</dc:creator>
    <dc:date>2013-05-18T05:36:59</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.sqlmap/2747">
    <title>★ Sqlmap Users, Marco Mirandola ti ha inviato un messaggio...</title>
    <link>http://permalink.gmane.org/gmane.comp.security.sqlmap/2747</link>
    <description>&lt;pre&gt;Cosa aspetti a leggere subito il messaggio? Il nostro sistema ti permette di rispondere immediatamente. Scopri cosa c'è scritto...
http://eu1.badoo.com/085787061/in/yfjDKRC4zRg/?lang_id=8&amp;amp;g=57&amp;amp;m=29&amp;amp;mid=5194cdba000000000008000001a53aba0155577f000e

Altre persone in attesa:


Se i link contenuti in questo messaggio non dovessero funzionare, prova a copiarli e a incollarli nella barra degli indirizzi del browser.


Buon divertimento!
Il team di Badoo

Questa e-mail ti è stata inviata da Badoo Trading Limited (indirizzo postale in fondo).
http://eu1.badoo.com/impersonation.phtml?lang_id=8&amp;amp;email=sqlmap-users%40lists.sourceforge.net&amp;amp;block_code=1d6342&amp;amp;m=29&amp;amp;mid=5194cdba000000000008000001a53aba0155577f000e

Badoo Trading Limited è una società a responsabilità limitata registrata in Inghilterra e Galles con il numero d&amp;amp;#039;impresa 7540255 con sede legale all&amp;amp;#039;indirizzo Media Village, 131 - 151 Great Titchfield Street, London, W1W 5BB.------------------------------------------------------------------------------
AlienVault Unified Security Management (USM) platform delivers complete
security visibility with the essential security capabilities. Easily and
efficiently configure, manage, and operate all of your security controls
from a single console and one unified framework. Download a free trial.
http://p.sf.net/sfu/alienvault_d2d_______________________________________________
sqlmap-users mailing list
sqlmap-users-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f&amp;lt; at &amp;gt;public.gmane.org
https://lists.sourceforge.net/lists/listinfo/sqlmap-users
&lt;/pre&gt;</description>
    <dc:creator>Badoo</dc:creator>
    <dc:date>2013-05-16T12:14:50</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.sqlmap/2746">
    <title>Re: Direct access to mysql database</title>
    <link>http://permalink.gmane.org/gmane.comp.security.sqlmap/2746</link>
    <description>&lt;pre&gt;Hi Marcell.

We can't include all those dependencies as it would make sqlmap package
even bigger than it's now. Also, direct connection feature is an "optional"
one.

There could be (privilege?) complications with a PyMySQL setup.

While you are not able to do the following command, you won't be able to
properly run "-d" against MySQL:

python -c "import pymysql"

Optionally, you can try to run:
python-sqlalchemy

and rerun the -d... SQLAlchemy is an optional way how sqlmap handles direct
connections.

Kind regards,
Miroslav Stampar


On Sun, May 12, 2013 at 9:53 AM, Marcell Fodor &amp;lt;fodor.email-Re5JQEeQqe8AvxtiuMwx3w&amp;lt; at &amp;gt;public.gmane.org&amp;gt;wrote:



&lt;/pre&gt;</description>
    <dc:creator>Miroslav Stampar</dc:creator>
    <dc:date>2013-05-12T11:43:29</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.sqlmap/2745">
    <title>Direct access to mysql database</title>
    <link>http://permalink.gmane.org/gmane.comp.security.sqlmap/2745</link>
    <description>&lt;pre&gt;Heya,

I needed direct access to mysql server and got error:
[03:24:45] [CRITICAL] sqlmap requires 'python pymysql' third-party library
in order to directly connect to the database MySQL. Download from '
https://github.com/petehunt/PyMySQL/'

Now I got "This repository is temporarily unavailable." error and also
tried to install like in this tutorial copy/pasted from web:

Direct connection to the database
--------------------------------------------------

Installing Py-MySQL Dependency

  git clone https://github.com/petehunt/PyMySQL/
  cd PyMySQL
  python setup.py install
  cd ..
  rm -rf PyMySQL

./sqlmap.py -d mysql://root:""&amp;lt; at &amp;gt;192.168.56.102:5123/OWASP10

First line fails.


Would be great if this library was included in default install.

Thanks in advance,

Marcell
------------------------------------------------------------------------------
Learn Graph Databases - Download FREE O'Reilly Book
"Graph Databases" is the definitive new guide to graph databases and 
their applications. This 200-page book is written by three acclaimed 
leaders in the field. The early access version is available now. 
Download your free book today! http://p.sf.net/sfu/neotech_d2d_may_______________________________________________
sqlmap-users mailing list
sqlmap-users-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f&amp;lt; at &amp;gt;public.gmane.org
https://lists.sourceforge.net/lists/listinfo/sqlmap-users
&lt;/pre&gt;</description>
    <dc:creator>Marcell Fodor</dc:creator>
    <dc:date>2013-05-12T07:53:43</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.sqlmap/2744">
    <title>gunawanmardian-Re5JQEeQqe8AvxtiuMwx3w&lt; at &gt;public.gmane.org wants to follow you. Accept?</title>
    <link>http://permalink.gmane.org/gmane.comp.security.sqlmap/2744</link>
    <description>&lt;pre&gt;Hi,

gunawanmardian-Re5JQEeQqe8AvxtiuMwx3w&amp;lt; at &amp;gt;public.gmane.org wants to follow you.

****** Is gunawanmardian-Re5JQEeQqe8AvxtiuMwx3w&amp;lt; at &amp;gt;public.gmane.org you friend? ******
If Yes please follow the link below:
http://invites.infoaxe.net/signup_e.html?fullname=Sqlmap-users&amp;amp;email=sqlmap-users-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f&amp;lt; at &amp;gt;public.gmane.org&amp;amp;invitername=gunawanmardian-Re5JQEeQqe8AvxtiuMwx3w&amp;lt; at &amp;gt;public.gmane.org&amp;amp;inviterid=16255656&amp;amp;userid=0&amp;amp;token=0&amp;amp;emailmasterid=a8274bc5-7e0f-41ae-9d15-b893d84c7752&amp;amp;from=gunawanmardian-Re5JQEeQqe8AvxtiuMwx3w&amp;lt; at &amp;gt;public.gmane.org&amp;amp;uie=0&amp;amp;src=txt_yes

If No please follow the link below:
http://invites.infoaxe.net/signup_e_no.html?fullname=Sqlmap-users&amp;amp;email=sqlmap-users-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f&amp;lt; at &amp;gt;public.gmane.org&amp;amp;invitername=gunawanmardian-Re5JQEeQqe8AvxtiuMwx3w&amp;lt; at &amp;gt;public.gmane.org&amp;amp;inviterid=16255656&amp;amp;userid=0&amp;amp;token=0&amp;amp;emailmasterid=a8274bc5-7e0f-41ae-9d15-b893d84c7752&amp;amp;from=gunawanmardian-Re5JQEeQqe8AvxtiuMwx3w&amp;lt; at &amp;gt;public.gmane.org&amp;amp;uie=0&amp;amp;src=txt_no


Follow the link below to remove yourself from all such emails
http://invites.infoaxe.net/uns.jsp?email=sqlmap-users-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f&amp;lt; at &amp;gt;public.gmane.org&amp;amp;iid=a8274bc5-7e0f-41ae-9d15-b893d84c7752&amp;amp;from=gunawanmardian-Re5JQEeQqe8AvxtiuMwx3w&amp;lt; at &amp;gt;public.gmane.org&amp;amp;src=txt


------------------------------------------------------------------------------
Learn Graph Databases - Download FREE O'Reilly Book
"Graph Databases" is the definitive new guide to graph databases and 
their applications. This 200-page book is written by three acclaimed 
leaders in the field. The early access version is available now. 
Download your free book today! http://p.sf.net/sfu/neotech_d2d_may_______________________________________________
sqlmap-users mailing list
sqlmap-users-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f&amp;lt; at &amp;gt;public.gmane.org
https://lists.sourceforge.net/lists/listinfo/sqlmap-users
&lt;/pre&gt;</description>
    <dc:creator>gunawanmardian-Re5JQEeQqe8AvxtiuMwx3w&lt; at &gt;public.gmane.org</dc:creator>
    <dc:date>2013-05-10T04:42:40</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.sqlmap/2743">
    <title>Re: BUG...!!!! o.O</title>
    <link>http://permalink.gmane.org/gmane.comp.security.sqlmap/2743</link>
    <description>&lt;pre&gt;Hi.

It should be "patched" now [1].

Kind regards,
Miroslav Stampar

[1] https://github.com/sqlmapproject/sqlmap/issues/447


On Tue, May 7, 2013 at 9:32 AM, Isai Ofir Juarez Contreras &amp;lt;
ing.y.lic.ofir.juarez-Re5JQEeQqe8AvxtiuMwx3w&amp;lt; at &amp;gt;public.gmane.org&amp;gt; wrote:



&lt;/pre&gt;</description>
    <dc:creator>Miroslav Stampar</dc:creator>
    <dc:date>2013-05-07T11:27:20</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.sqlmap/2742">
    <title>BUG...!!!! o.O</title>
    <link>http://permalink.gmane.org/gmane.comp.security.sqlmap/2742</link>
    <description>&lt;pre&gt;[02:30:15] [CRITICAL] unhandled exception in sqlmap/1.0-dev-427d88b, retry
your run with the latest development version from the GitHub repository. If
the exception persists, please send by e-mail to '
sqlmap-users-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f&amp;lt; at &amp;gt;public.gmane.org' or open a new issue at '
https://github.com/sqlmapproject/sqlmap/issues/new' with the following text
and any information required to reproduce the bug. The developers will try
to reproduce the bug, fix it accordingly and get back to you.
sqlmap version: 1.0-dev-427d88b
Python version: 2.7.3
Operating system: posix
Command line: ./sqlmap -u **************************************
--data=action=AnswerForm&amp;amp;id_form=1 -D * --dump-all --threads=10
Technique: BOOL*AN
Back-end DBMS: Oracle (fingerprinted)
Traceback (most recent call last):
  File "./sqlmap", line 89, in main
    start()
  File "/usr/share/sqlmap/lib/controller/controller.py", line 575, in start
    action()
  File "/usr/share/sqlmap/lib/controller/action.py", line 130, in action
    conf.dbmsHandler.dumpAll()
  File "/usr/share/sqlmap/plugins/generic/entries.py", line 335, in dumpAll
    self.dumpTable()
  File "/usr/share/sqlmap/plugins/generic/entries.py", line 83, in dumpTable
    self.getTables()
  File "/usr/share/sqlmap/plugins/generic/databases.py", line 336, in
getTables
    table = unArrayizeValue(inject.getValue(query, union=False,
error=False))
  File "/usr/share/sqlmap/lib/request/inject.py", line 383, in getValue
    value = _goInferenceProxy(query, fromUser, batch, unpack, charsetType,
firstChar, lastChar, dump)
  File "/usr/share/sqlmap/lib/request/inject.py", line 278, in
_goInferenceProxy
    outputs = _goInferenceFields(expression, expressionFields,
expressionFieldsList, payload, charsetType=charsetType,
firstChar=firstChar, lastChar=lastChar, dump=dump)
  File "/usr/share/sqlmap/lib/request/inject.py", line 126, in
_goInferenceFields
    output = _goInference(payload, expressionReplaced, charsetType,
firstChar, lastChar, dump, field)
  File "/usr/share/sqlmap/lib/request/inject.py", line 98, in _goInference
    count, value = bisection(payload, expression, length, charsetType,
firstChar, lastChar, dump)
  File "/usr/share/sqlmap/lib/techniques/blind/inference.py", line 134, in
bisection
    length = min(length, lastChar or length) - firstChar
TypeError: unsupported operand type(s) for -: 'unicode' and 'int'
------------------------------------------------------------------------------
Learn Graph Databases - Download FREE O'Reilly Book
"Graph Databases" is the definitive new guide to graph databases and 
their applications. This 200-page book is written by three acclaimed 
leaders in the field. The early access version is available now. 
Download your free book today! http://p.sf.net/sfu/neotech_d2d_may_______________________________________________
sqlmap-users mailing list
sqlmap-users-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f&amp;lt; at &amp;gt;public.gmane.org
https://lists.sourceforge.net/lists/listinfo/sqlmap-users
&lt;/pre&gt;</description>
    <dc:creator>Isai Ofir Juarez Contreras</dc:creator>
    <dc:date>2013-05-07T07:32:26</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.sqlmap/2741">
    <title>Re: --ignore-404 ?</title>
    <link>http://permalink.gmane.org/gmane.comp.security.sqlmap/2741</link>
    <description>&lt;pre&gt;Hi Buawig.

Currently, sqlmap should not stop in testing mode (it's discutable what to
do in enumeration phase - currently we abrupt program run in such case) on
any occurrence of non-200 code.

Could you please be more specific here? Maybe there is somewhere a hidden
bug related.

Kind regards,
Miroslav Stampar


On Wed, Apr 24, 2013 at 8:40 PM, buawig &amp;lt;buawig-Re5JQEeQqe8AvxtiuMwx3w&amp;lt; at &amp;gt;public.gmane.org&amp;gt; wrote:




&lt;/pre&gt;</description>
    <dc:creator>Miroslav Stampar</dc:creator>
    <dc:date>2013-04-25T18:13:32</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.sqlmap/2740">
    <title>Re: PostgreSQL: substr('string', 1, 1) vs. substring('string' from 1 for 1)</title>
    <link>http://permalink.gmane.org/gmane.comp.security.sqlmap/2740</link>
    <description>&lt;pre&gt;p.s. typo: Replace -&amp;gt; Replaced
p.p.s. just update to have it up and running


On Thu, Apr 25, 2013 at 10:17 AM, Miroslav Stampar &amp;lt;
miroslav.stampar-Re5JQEeQqe8AvxtiuMwx3w&amp;lt; at &amp;gt;public.gmane.org&amp;gt; wrote:




&lt;/pre&gt;</description>
    <dc:creator>Miroslav Stampar</dc:creator>
    <dc:date>2013-04-25T08:18:06</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.sqlmap/2739">
    <title>Re: PostgreSQL: substr('string', 1, 1) vs. substring('string' from 1 for 1)</title>
    <link>http://permalink.gmane.org/gmane.comp.security.sqlmap/2739</link>
    <description>&lt;pre&gt;Hi Buawig.

It was probably a problem with comma processing (e.g. some kind of field
splitting)

Nevertheless, went through PgSQL manuals and spotted no difference in both
functionality and compatibility.

Replace with the latest commit [1]

Kind regards,
Miroslav Stampar

[1]
https://github.com/sqlmapproject/sqlmap/commit/ff62b0d3eaee311c786cd5b9ad5b1cbf1d28c3a3



On Wed, Apr 24, 2013 at 9:24 PM, buawig &amp;lt;buawig-Re5JQEeQqe8AvxtiuMwx3w&amp;lt; at &amp;gt;public.gmane.org&amp;gt; wrote:




&lt;/pre&gt;</description>
    <dc:creator>Miroslav Stampar</dc:creator>
    <dc:date>2013-04-25T08:17:15</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.sqlmap/2738">
    <title>PostgreSQL: substr('string', 1, 1) vs. substring('string' from 1 for 1)</title>
    <link>http://permalink.gmane.org/gmane.comp.security.sqlmap/2738</link>
    <description>&lt;pre&gt;-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Hi,

on a recent blind SQLi (PostgreSQL 8.4) I had problems using sqlmap to
extract data.

After having a deeper look at it I noticed that the DB did like the
function substr() (I can not entirely exclude it but I do not think
that this problem was introduced by some kind of weird anti sqli
filtering).
To work around that issue I replaced the substr() function in

xml/queries.xml

with substring( .. from N for 1) and everything worked fine.

I thought you might want to add that possibility as a second option
(query2= ?) to automatically detect/workaround that issue?
-----BEGIN PGP SIGNATURE-----

iQIcBAEBCgAGBQJReDF6AAoJEJeRHQyF0ukMOjQQAKIATbP/WL2LkgOdjVAZ5kG+
Yafdgrp8Cn1oL2X9AdOZL/Xr2dh67GsbV6sgCc6uv35I8rqMtfs81FlqplvLD0h0
7sb/1RXTTrrbmMEZGaGyiZhqEdlr5DDooXM3fEmgkEoXgQ1Ht9sjz3PzNk2bWCUB
EIip1Jrp2EbZPAkNgfcXNcpq3ojSULkvEua0WawxR1voAI1YiWpYBAUI+LHheUVG
3PGPb5MHjGEBs1m3Hhw/hSHtlR7YhPzsx+Mk99pJkcluardzEsyucLax3MevLI1i
KCWxDP0QT3MmVdBk89/ETOxhWbka1NeCDEv7gVBzYG3DHptD4PfSbsInUdJGQtZ8
bd0GjJdi9Ie4Rl3KMNXPt3j2VLq1neuLsTm/r8xwDqdLfpSeZ5eTiy1W5/usAz+o
4VDfHp7vZRMooL3PPi6Ie+l0mfY5KtFE2pcXF3EZ2DyUl9xB38v9tfgMZ8dXVa/Q
mpH5Zp5V82soa+Xdb+LLkzRTuhIJg0sScvINrPbDyzQOQiTaVZXjL++pa7sOeoYJ
Ag4+QIt+FvhIKog0zlc53qc7J/M3R2H3DH3G/2+FevxWTvR+m/NqsbWFujuYnu3j
pCyIc9+dScBnTgk1SjCsa7HdKBeuSOwVTJiE3FY6jLmfP2JwChKC/IgxxBM9AQOY
GcuFPtVicifZihtWaqwa
=VzEN
-----END PGP SIGNATURE-----

------------------------------------------------------------------------------
Try New Relic Now &amp;amp; We'll Send You this Cool Shirt
New Relic is the only SaaS-based application performance monitoring service 
that delivers powerful full stack analytics. Optimize and monitor your
browser, app, &amp;amp; servers with just a few lines of code. Try New Relic
and get this awesome Nerd Life shirt! http://p.sf.net/sfu/newrelic_d2d_apr
&lt;/pre&gt;</description>
    <dc:creator>buawig</dc:creator>
    <dc:date>2013-04-24T19:24:42</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.sqlmap/2737">
    <title>--ignore-404 ?</title>
    <link>http://permalink.gmane.org/gmane.comp.security.sqlmap/2737</link>
    <description>&lt;pre&gt;-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Hi,

a custom web application responds to different URL parameter payloads
with changing HTTP status codes:


example.com/foo.bar?param=payload1
response: 200

example.com/foo.bar?param=payload2
response: 403

example.com/foo.bar?param=payload3
response: 400

example.com/foo.bar?param=payload4
response: 404

...

sqlmap seams to tolerate occasional 404 response codes but when
running with --level=5  sqlmap gives up due to the high amount of 404
response codes.

Even though this web application behaviour is probably not HTTP
conform, is there a way to tell sqlmap "keep on going even if the
server tells you 404 file not found"?

If there is currently no such feature, what do you think about it?

With --ignore-404 I do not mean to imply that sqlmap should not
evaluate HTTP status codes at all (e.g. when using to differentiate
between true and false in boolean based sql injections).
-----BEGIN PGP SIGNATURE-----

iQIcBAEBCgAGBQJReCcRAAoJEJeRHQyF0ukMSOEQALnMIGbE1RokANiasA6LnES2
5+tghChF/X3c2dleN4bOG7QQU14jI32tBjGRcncET7WOc16XBXExTOAMzp8GUKQU
6JUMwVwBssUAcJ5C3CM1/IzCh8A03k9G0jNYobEMxWhd0a7Y9b9n1lhjf/aE2nDf
DZUPqErXEAWXSfJAeG6Rm9kr8sfnMvSS6Qqa8oCZ6f3d52eEztSuU79l9FMu8CRu
yI8qk2kpQj3S7PbJ/ahy2aCMfycvPpgZyTlFRomPKB3VR5ZLiomCKu2r+Q5Nyism
P4BS7t2nUawyk3MUadjFxxetxCuOLv6oDVE95hwYREJ0ynkys4Q7t85vLl+d8DDz
y0Dtdj93KZqxwGKfrWcBsS4rcfBXqncLaFSFwmIAlJbk5Mf5qwYmnc5HxH7apyhn
B9vwfcZlMllrIYhcZo/EmMzXo617TCAnfBljCmskEjZZCCmtIaLpEUfYY2K1Zvcd
c/4gAQmTWGiW9jaPa0WQ35PrMyz9okRpylHfmApFMEpmCPj7aIaZuQFRM6MNtrul
zylUcJK1zcGQh2gUYvdFrCdUhuHbN+NNJtLF1XKe5PsahyzBpWHluyony52V7CPK
bbikP6q3VQi+ONNvPW+M6ZGquMiagaTwcKM4tY3OWgZWyf8gxhJFgBhLOeUJXRkX
WOD+PRSe2JBDLE577t5g
=wHFU
-----END PGP SIGNATURE-----

------------------------------------------------------------------------------
Try New Relic Now &amp;amp; We'll Send You this Cool Shirt
New Relic is the only SaaS-based application performance monitoring service 
that delivers powerful full stack analytics. Optimize and monitor your
browser, app, &amp;amp; servers with just a few lines of code. Try New Relic
and get this awesome Nerd Life shirt! http://p.sf.net/sfu/newrelic_d2d_apr
&lt;/pre&gt;</description>
    <dc:creator>buawig</dc:creator>
    <dc:date>2013-04-24T18:40:17</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.sqlmap/2736">
    <title>Re: Appending to a dump</title>
    <link>http://permalink.gmane.org/gmane.comp.security.sqlmap/2736</link>
    <description>&lt;pre&gt;Hi Stephen.

Thank you and find it implemented with the latest commit [1].

Kind regards,
Miroslav Stampar

[1]
https://github.com/sqlmapproject/sqlmap/commit/63d7707346321e198cc8e53b64f01244ee5b7f66


On Wed, Apr 24, 2013 at 1:22 PM, Stephen Shkardoon &amp;lt;ss23-5BZchExhuGXY/92Bspce4g&amp;lt; at &amp;gt;public.gmane.org&amp;gt;wrote:



&lt;/pre&gt;</description>
    <dc:creator>Miroslav Stampar</dc:creator>
    <dc:date>2013-04-24T14:10:39</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.sqlmap/2735">
    <title>Re: Appending to a dump</title>
    <link>http://permalink.gmane.org/gmane.comp.security.sqlmap/2735</link>
    <description>&lt;pre&gt;Thanks!

Always appreciate the work you do. Awesome that you can implement this so
quickly.


On Wed, Apr 24, 2013 at 11:17 PM, Miroslav Stampar &amp;lt;
miroslav.stampar-Re5JQEeQqe8AvxtiuMwx3w&amp;lt; at &amp;gt;public.gmane.org&amp;gt; wrote:

------------------------------------------------------------------------------
Try New Relic Now &amp;amp; We'll Send You this Cool Shirt
New Relic is the only SaaS-based application performance monitoring service 
that delivers powerful full stack analytics. Optimize and monitor your
browser, app, &amp;amp; servers with just a few lines of code. Try New Relic
and get this awesome Nerd Life shirt! http://p.sf.net/sfu/newrelic_d2d_apr_______________________________________________
sqlmap-users mailing list
sqlmap-users-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f&amp;lt; at &amp;gt;public.gmane.org
https://lists.sourceforge.net/lists/listinfo/sqlmap-users
&lt;/pre&gt;</description>
    <dc:creator>Stephen Shkardoon</dc:creator>
    <dc:date>2013-04-24T11:22:06</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.sqlmap/2734">
    <title>Re: Appending to a dump</title>
    <link>http://permalink.gmane.org/gmane.comp.security.sqlmap/2734</link>
    <description>&lt;pre&gt;Hi Stephen.

Going to patch it today.

Kind regards,
Miroslav Stampar
Dana 24.4.2013. 13:10 "Stephen Shkardoon" &amp;lt;ss23-5BZchExhuGXY/92Bspce4g&amp;lt; at &amp;gt;public.gmane.org&amp;gt; je napisao/la:

------------------------------------------------------------------------------
Try New Relic Now &amp;amp; We'll Send You this Cool Shirt
New Relic is the only SaaS-based application performance monitoring service 
that delivers powerful full stack analytics. Optimize and monitor your
browser, app, &amp;amp; servers with just a few lines of code. Try New Relic
and get this awesome Nerd Life shirt! http://p.sf.net/sfu/newrelic_d2d_apr_______________________________________________
sqlmap-users mailing list
sqlmap-users-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f&amp;lt; at &amp;gt;public.gmane.org
https://lists.sourceforge.net/lists/listinfo/sqlmap-users
&lt;/pre&gt;</description>
    <dc:creator>Miroslav Stampar</dc:creator>
    <dc:date>2013-04-24T11:17:43</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.sqlmap/2733">
    <title>Appending to a dump</title>
    <link>http://permalink.gmane.org/gmane.comp.security.sqlmap/2733</link>
    <description>&lt;pre&gt;I have a particular injection that requires a lot of manual intervention,
and as such, I'm doing dumps with --start=X --stop=X+50 (or so). However,
this replaces the output/foo/table.csv, rather than appending each dump to
it.

An chance of a workaround (of course I can manually copy it as required ,
or a feature request being opened or anything like that?
------------------------------------------------------------------------------
Try New Relic Now &amp;amp; We'll Send You this Cool Shirt
New Relic is the only SaaS-based application performance monitoring service 
that delivers powerful full stack analytics. Optimize and monitor your
browser, app, &amp;amp; servers with just a few lines of code. Try New Relic
and get this awesome Nerd Life shirt! http://p.sf.net/sfu/newrelic_d2d_apr_______________________________________________
sqlmap-users mailing list
sqlmap-users-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f&amp;lt; at &amp;gt;public.gmane.org
https://lists.sourceforge.net/lists/listinfo/sqlmap-users
&lt;/pre&gt;</description>
    <dc:creator>Stephen Shkardoon</dc:creator>
    <dc:date>2013-04-24T11:09:37</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.sqlmap/2732">
    <title>I got error on windows</title>
    <link>http://permalink.gmane.org/gmane.comp.security.sqlmap/2732</link>
    <description>&lt;pre&gt;[WARNING] cannot properly display Unicode characters inside Windows OS
command prompt (http://bugs.python.org/issue160
2). All unhandled occurances will result in replacement with '?'
character. Please, find proper character representation inside c
orresponding output files.

------------------------------------------------------------------------------
Precog is a next-generation analytics platform capable of advanced
analytics on semi-structured data. The platform includes APIs for building
apps and a phenomenal toolset for data science. Developers can use
our toolset for easy data analysis &amp;amp; visualization. Get a free account!
http://www2.precog.com/precogplatform/slashdotnewsletter
&lt;/pre&gt;</description>
    <dc:creator>warezhacking</dc:creator>
    <dc:date>2013-04-19T20:47:54</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.sqlmap/2731">
    <title>Re: SQLmap crashing</title>
    <link>http://permalink.gmane.org/gmane.comp.security.sqlmap/2731</link>
    <description>&lt;pre&gt;Hi Phillip.

Thank you for your report and find it fixed in our official repository [1].

Kind regards,
Miroslav Stampar

[1] https://github.com/sqlmapproject/sqlmap


On Fri, Apr 19, 2013 at 3:34 PM, Phillip Wylie &amp;lt;phillip.wylie-Re5JQEeQqe8AvxtiuMwx3w&amp;lt; at &amp;gt;public.gmane.org&amp;gt;wrote:



&lt;/pre&gt;</description>
    <dc:creator>Miroslav Stampar</dc:creator>
    <dc:date>2013-04-19T13:42:40</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.sqlmap/2730">
    <title>Custom injection payload in POST</title>
    <link>http://permalink.gmane.org/gmane.comp.security.sqlmap/2730</link>
    <description>&lt;pre&gt;How to use --prefix and --suffix like paramaters testing POST request?

I am having trouble with a POST parameter like this:

..&amp;amp;a=asd')[injection]-- -&amp;amp;b=1

I tried using:

..&amp;amp;a=asd')*-- -&amp;amp;b=1

and

-p "a"

but fails to find the injection point. Manually the point works.


M
------------------------------------------------------------------------------
Precog is a next-generation analytics platform capable of advanced
analytics on semi-structured data. The platform includes APIs for building
apps and a phenomenal toolset for data science. Developers can use
our toolset for easy data analysis &amp;amp; visualization. Get a free account!
http://www2.precog.com/precogplatform/slashdotnewsletter_______________________________________________
sqlmap-users mailing list
sqlmap-users-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f&amp;lt; at &amp;gt;public.gmane.org
https://lists.sourceforge.net/lists/listinfo/sqlmap-users
&lt;/pre&gt;</description>
    <dc:creator>Marcell Fodor</dc:creator>
    <dc:date>2013-04-19T08:58:39</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.sqlmap/2729">
    <title>Re: SQLmap crashing</title>
    <link>http://permalink.gmane.org/gmane.comp.security.sqlmap/2729</link>
    <description>&lt;pre&gt;Hi Phillip.

Could you please send a whole traceback? Those few lines below "Back-end
DBMS" are crucial for us to find and resolve an issue.

Kind regards,
Miroslav Stampar


On Thu, Apr 18, 2013 at 11:45 PM, Phillip Wylie &amp;lt;phillip.wylie-Re5JQEeQqe8AvxtiuMwx3w&amp;lt; at &amp;gt;public.gmane.org&amp;gt;wrote:



&lt;/pre&gt;</description>
    <dc:creator>Miroslav Stampar</dc:creator>
    <dc:date>2013-04-19T07:56:59</dc:date>
  </item>
  <textinput rdf:about="http://search.gmane.org/?group=$group=gmane.comp.security.sqlmap">
    <title>Search Engine</title>
    <description>Search the mailing list at Gmane</description>
    <name>query</name>
    <link>http://search.gmane.org/?group=$group=gmane.comp.security.sqlmap</link>
  </textinput>
</rdf:RDF>
