- November 4, release 0.5 marks the end of the OWASP
Spring of Code 2007 contest participation. Bernardo has
-accomplished all the propsed objects which include initial support
-for Oracle, enhanced support for UNION query SQL injection and support to
-test and exploit injections on HTTP Cookie and User-Agent headers.
+accomplished all the propsed objects which include also initial
+support for Oracle, enhanced support for UNION query SQL injection and
+support to test and exploit SQL injections in HTTP Cookie and User-Agent
+headers.
- June 15, Bernardo releases version 0.4 as a
result of the first OWASP Spring of Code 2007 milestone. This release
@@ -677,7 +678,7 @@ Metasploit's
getsystem command which include, among others,
the
kitrap0d technique (
MS10-015) or via
-Windows Access Tokens kidnapping by using Meterpreter's
+Windows Access Tokens insecure design by using Meterpreter's
incognito extension.
- Support to access (read/add/delete) Windows registry hives.
diff --git a/doc/README.pdf b/doc/README.pdf
index dbf4f3121..f6c391208 100644
Binary files a/doc/README.pdf and b/doc/README.pdf differ
diff --git a/doc/README.sgml b/doc/README.sgml
index 0a2e583da..b5c61a509 100644
--- a/doc/README.sgml
+++ b/doc/README.sgml
@@ -226,9 +226,9 @@ name="AthCon" url="http://www.athcon.org"> conference in Greece on June
-- December 18, Miroslav Stampar replies to my public call
-for developers. He contributes actively in the development of sqlmap from
-version 0.8 release candidate 2.
+
- December 18, Miroslav Stampar replies to the call for
+developers. Along with Bernardo, he actively develops sqlmap from version
+0.8 release candidate 2.
- December 12, Bernardo writes to the mailing list a post
titled highlighting the goals
achieved during these first three years of the project and launches a call
for developers.
-
- December 4, sqlmap-devel mailing list has been merged
+
- December 4, sqlmap-devel mailing list has been merged into
sqlmap-users .
- November 20, Bernardo and Guido present again their
@@ -259,7 +259,7 @@ url="http://www.pornosecurity.org"> their research () at SOURCE Conference 2009 in Barcelona, Spain.
-
- August, Bernardo is accepted as a speaker to two others IT
+
- August, Bernardo is accepted as a speaker at two others IT
security conferences, and .
This new research is titled Expanding the control over the operating
@@ -274,7 +274,7 @@ an updated version of his
Digital Security Forum" url="http://www.digitalsecurityforum.eu/"> in
Lisbon, Portugal.
-
- June 2, sqlmap version 0.6.4 has made it way to
+
- June 2, sqlmap version 0.6.4 has made its way to
the official Ubuntu repository too.
- May, Bernardo presents again his research on operating
@@ -372,9 +372,10 @@ away from SourceForge and goes private for a while.
- November 4, release 0.5 marks the end of the OWASP
Spring of Code 2007 contest participation. Bernardo has all the propsed objects which include initial support
-for Oracle, enhanced support for UNION query SQL injection and support to
-test and exploit injections on HTTP Cookie and User-Agent headers.
+name="accomplished"> all the propsed objects which include also initial
+support for Oracle, enhanced support for UNION query SQL injection and
+support to test and exploit SQL injections in HTTP Cookie and User-Agent
+headers.
- June 15, Bernardo releases version 0.4 as a
result of the first OWASP Spring of Code 2007 milestone. This release
@@ -624,8 +625,8 @@ url="http://archives.neohapsis.com/archives/fulldisclosure/2010-01/0346.html"
name="kitrap0d"> technique () or via by using Meterpreter's
+url="http://labs.mwrinfosecurity.com/files/Publications/mwri_security-implications-of-windows-access-tokens_2008-04-14.pdf"
+name="Windows Access Tokens insecure design"> by using Meterpreter's
incognito extension.
- Support to access (read/add/delete) Windows registry hives.