@@ -17,35 +17,92 @@ for the latest version.
1717<sect>2010
1818
1919<itemize>
20- <item><bf>...</bf>
21- <item><bf>...</bf>
22- <item><bf>...</bf>
23- <item><bf>...</bf>
24- <item><bf>...</bf>
25- <item><bf>...</bf>
20+ <item><bf>March 14</bf>, <htmlurl name="Bernardo and Miroslav"
21+ url="http://sqlmap.sourceforge.net/#author"> release stable version of
22+ sqlmap <bf>0.8</bf> featuring many features. Amongst these, support to
23+ enumerate and dump all databases' tables containing user provided
24+ column(s), stabilization and enhancements to the takeover functionalities,
25+ updated integration with Metasploit 3.3.3 and a lot of minor features and
26+ bug fixes.
27+ <item><bf>January</bf>, Bernardo is <htmlurl name="invited"
28+ url="http://www.athcon.org/speakers/"> to present at <htmlurl
29+ name="AthCon" url="http://www.athcon.org"> conference in Greece on June
30+ 2010.
2631</itemize>
2732
2833
2934<sect>2009
3035
3136<itemize>
37+ <item><bf>December 18</bf>, Miroslav Stampar replies to my public call
38+ for developers. He contributes actively in the development of sqlmap from
39+ version <bf>0.8 release candidate 2</bf>.
40+
41+ <item><bf>December 12</bf>, Bernardo writes to the mailing list a post
42+ titled <htmlurl url="http://sourceforge.net/mailarchive/forum.php?thread_name=ffa432520912150559x7da484d0q5a580512abf4592f%40mail.gmail.com&forum_name=sqlmap-users"
43+ name="sqlmap state of art - 3 years later"> highlighting the goals
44+ achieved during these first three years of the project and launches a call
45+ for developers.
46+
47+ <item><bf>December 4</bf>, sqlmap-devel mailing list has been <htmlurl
48+ url="http://sourceforge.net/mailarchive/forum.php?thread_name=ffa432520912040135y55b92f63v356f77c74771f0d5%40mail.gmail.com&forum_name=sqlmap-users" name="merged"> into
49+ sqlmap-users <htmlurl name="mailing list" url="http://sqlmap.sourceforge.net/#ml">.
50+
51+ <item><bf>November 20</bf>, Bernardo and Guido present again their
52+ research on stealth database server takeover at CONfidence 2009 in Warsaw,
53+ Poland.
54+
55+ <item><bf>September 26</bf>, sqlmap version <bf>0.8 release candidate
56+ 1</bf> goes public on the <htmlurl name="Subversion repository"
57+ url="https://svn.sqlmap.org/sqlmap/trunk/sqlmap/">, with all the attack
58+ vectors unveiled at SOURCE Barcelona 2009 Conference. These include an
59+ enhanced version of the Microsoft SQL Server buffer overflow exploit to
60+ automatically bypass DEP memory protection, support to establish the
61+ out-of-band connection with the database server by executing in-memory
62+ the Metasploit shellcode via UDF <em>sys_bineval()</em> (anti-forensics
63+ technique), support to access the Windows registry hives and support to
64+ inject custom user-defined functions.
65+
66+ <item><bf>September 21</bf>, Bernardo and <htmlurl name="Guido Landi"
67+ url="http://www.pornosecurity.org"> <htmlurl name="present"
68+ url="http://www.sourceconference.com/index.php/pastevents/source-barcelona-2009/schedule"> their research (<htmlurl name="slides"
69+ url="http://www.slideshare.net/inquis/expanding-the-control-over-the-operating-system-from-the-database">) at SOURCE Conference 2009 in Barcelona, Spain.
70+
71+ <item><bf>August</bf>, Bernardo is accepted as a speaker to two others IT
72+ security conferences, <htmlurl url="http://www.sourceconference.com/index.php/pastevents/source-barcelona-2009" name="SOURCE Barcelona 2009"> and <htmlurl url="http://200902.confidence.org.pl/"
73+ name="CONfidence 2009 Warsaw">.
74+ This new research is titled <em>Expanding the control over the operating
75+ system from the database</em>.
76+
3277<item><bf>July 25</bf>, stable version of sqlmap <bf>0.7</bf> is out!
3378
79+ <item><bf>June 2</bf>, sqlmap version <bf>0.6.4</bf> has made it way to
80+ the official Ubuntu repository too.
81+
3482<item><bf>May</bf>, Bernardo presents again his research on operating
3583system takeover via SQL injection at <htmlurl
3684url="http://www.owasp.org/index.php/OWASP_AppSec_Europe_2009_-_Poland"
3785name="OWASP AppSec Europe 2009"> in Warsaw, Poland and at <htmlurl
3886url="http://eusecwest.com/" name="EUSecWest 2009"> in London, UK.
3987
88+ <item><bf>May 8</bf>, sqlmap version <bf>0.6.4</bf> has been officially
89+ accepted in Debian repository. Details on <htmlurl
90+ url="http://bernardodamele.blogspot.com/2009/05/sqlmap-in-debian-package-repository.html"
91+ name="this blog post">.
92+
4093<item><bf>April 22</bf>, sqlmap version <bf>0.7 release candidate 1</bf>
41- is published, with all the attack vectors unveiled at Black Hat Conference.
42- This include execution of arbitrary commands on the underlying operating
94+ goes public, with all the attack vectors unveiled at Black Hat Europe 2009
95+ Conference.
96+ These include execution of arbitrary commands on the underlying operating
4397system, full integration with Metasploit to establish an out-of-band
44- TCP connection, first publicly available exploit for MS09-004 and others
98+ TCP connection, first publicly available exploit for Microsoft Security
99+ Bulletin <htmlurl url="http://www.microsoft.com/technet/security/Bulletin/MS09-004.mspx"
100+ name="MS09-004"> against Microsoft SQL Server 2000 and 2005 and others
45101attacks to takeover the database server as a whole, not only the data from
46102the database.
47- <item><bf>April 16</bf>, Bernardo <htmlurl url="http://www.slideshare.net/inquis/advanced-sql-injection-to-operating-system-full-control-slides"
48- name="presents"> his research (<htmlurl
103+
104+ <item><bf>April 16</bf>, Bernardo <htmlurl url="http://www.blackhat.com/html/bh-europe-09/bh-eu-09-archives.html#Damele"
105+ name="presents"> his research (<htmlurl url="http://www.slideshare.net/inquis/advanced-sql-injection-to-operating-system-full-control-slides" name="slides">, <htmlurl
49106url="http://sqlmap.sourceforge.net/doc/BlackHat-Europe-09-Damele-A-G-Advanced-SQL-injection-whitepaper.pdf"
50107name="whitepaper">) at Black Hat Europe 2009 in Amsterdam, The Netherlands.
51108The feedback from the audience is good and there has been some
@@ -60,79 +117,77 @@ name="Front Range OWASP Conference 2009"> in Denver, USA. The presentation
60117is titled <em>SQL injection: Not only AND 1=1</em>.
61118
62119<item><bf>February 24</bf>, Bernardo is accepted as a <htmlurl
63- url="http://www.blackhat.com/html/bh-europe-09/bh-eu-09-archives .html#Damele"
120+ url="http://www.blackhat.com/html/bh-europe-09/bh-eu-09-speakers .html#Damele"
64121name="speaker"> at <htmlurl url="http://www.blackhat.com/html/bh-europe-09/bh-eu-09-main.html"
65122name="Black Hat Europe 2009"> with a presentation titled <em>Advanced SQL
66123injection exploitation to operating system full control</em>.
67124
68125<item><bf>February 3</bf>, sqlmap <bf>0.6.4</bf> is the last point release
69- of 0.6: taking advantage of the stacked queries test implemented in 0.6.3,
70- sqlmap can now be used to execute arbitrarly any SQL statement, not only
71- SELECTs . Also, many features have been stabilized, tweaked and improved in
72- terms of speed in this release.
126+ for 0.6: taking advantage of the stacked queries test implemented in 0.6.3,
127+ sqlmap can now be used to execute any arbitrary SQL statement, not only
128+ <em>SELECT</em> anymore . Also, many features have been stabilized, tweaked
129+ and improved in terms of speed in this release.
73130
74131<item><bf>January 9</bf>, Bernardo <htmlurl url="http://www.slideshare.net/inquis/sql-injection-exploitation-internals-presentation"
75132name="presents"> <em>SQL injection exploitation internals</em> at a
76- Corporate event.
133+ private event in London, UK .
77134</itemize>
78135
79136
80137<sect>2008
81138
82139<itemize>
83- <item><bf>December 18</bf>, to celebrate Bernardo's first daughter birthday,
84- sqlmap <bf>0.6.3</bf> is released featuring support to retrieve targets
85- from Burp and WebScarab proxies log files, support to test for stacked
86- queries ant time-based blind SQL injection, rough fingerprint of the web
87- server and web application technologies in use and more options to
88- customize the HTTP requests and enumerate further data from the database.
140+ <item><bf>December 18</bf>, sqlmap <bf>0.6.3</bf> is released featuring
141+ support to retrieve targets from Burp and WebScarab proxies log files,
142+ support to test for stacked queries ant time-based blind SQL injection,
143+ rough fingerprint of the web server and web application technologies in
144+ use and more options to customize the HTTP requests and enumerate more
145+ information from the database.
89146
90147<item><bf>November 2</bf>, sqlmap version <bf>0.6.2</bf> is a "bug fixes"
91148release only.
92149
93- <item><bf>October 20</bf>, sqlmap first point release, <bf>0.6.1</bf> goes
150+ <item><bf>October 20</bf>, sqlmap first point release, <bf>0.6.1</bf>, goes
94151public. This includes minor bug fixes and the first contact between the
95152tool and <htmlurl url="http://metasploit.com/framework" name="Metasploit">:
96153an auxiliary module to launch sqlmap from within Metasploit Framework.
97- sqlmap <htmlurl url="https://svn.sqlmap.org/sqlmap/trunk/sqlmap/"
98- name="subversion development repository"> goes public again.
154+ The <htmlurl url="https://svn.sqlmap.org/sqlmap/trunk/sqlmap/"
155+ name="Subversion development repository"> goes public again.
99156
100157<item><bf>September 1</bf>, nearly one year after the previous release,
101- sqlmap <bf>0.6</bf> comes to life featuring the first major code
102- refactoring, support to execute arbitrary SQL SELECT statements, more
103- options to enumerate and dump specific information are added, brand new
104- installation packages for Debian, Red Hat, Windows and much more.
158+ sqlmap <bf>0.6</bf> comes to life featuring a complete code
159+ refactoring, support to execute arbitrary SQL <em> SELECT</em> statements,
160+ more options to enumerate and dump specific information are added, brand
161+ new installation packages for Debian, Red Hat, Windows and much more.
105162
106163<item><bf>August</bf>, two public <htmlurl name="mailing lists"
107164url="http://sqlmap.sourceforge.net/#ml"> are created on SourceForge.
108165
109- <item><bf>January</bf>, sqlmap development repository is moved away from
110- SourceForge and goes private.
166+ <item><bf>January</bf>, sqlmap Subversion development repository is moved
167+ away from SourceForge and goes private for a while .
111168</itemize>
112169
113170
114171<sect>2007
115172
116173<itemize>
117- <item><bf>December 15</bf>, Bernardo's first daughter is born and will
118- keep him quite busy for the next months.
119-
120- <item><bf>November 4</bf>, release <bf>0.5</bf> marks the end of the Spring
121- of Code contest participation. Bernardo has <htmlurl
174+ <item><bf>November 4</bf>, release <bf>0.5</bf> marks the end of the OWASP
175+ Spring of Code 2007 contest participation. Bernardo has <htmlurl
122176url="http://www.owasp.org/index.php/SpoC_007_-_SQLMap_-_Progress_Page"
123177name="accomplished"> all the propsed objects which include initial support
124178for Oracle, enhanced support for UNION query SQL injection and support to
125- inject on HTTP Cookie and User-Agent headers.
179+ test and exploit injections on HTTP Cookie and User-Agent headers.
126180
127181<item><bf>June 15</bf>, Bernardo releases version <bf>0.4</bf> as a
128- result of the first Spring of Code milestone. This release features,
129- amongst others, improvements to the DBMS fingerprint engine, support to
130- calculate the estimated time of arrival, options to enumerate specific
131- data from the database server and brand new logging system.
182+ result of the first OWASP Spring of Code 2007 milestone. This release
183+ features, amongst others, improvements to the DBMS fingerprint engine,
184+ support to calculate the estimated time of arrival, options to enumerate
185+ specific data from the database server and brand new logging system.
132186
133187<item><bf>April</bf>, even though sqlmap was <bf>not</bf> and is <bf>not</bf>
134188an OWASP project, it gets <htmlurl url="http://www.owasp.org/index.php/SpoC_007_-_SqlMap"
135- name="accepted">, amongst many other open source projects to SpoC 2007.
189+ name="accepted">, amongst many other open source projects to OWASP Spring
190+ of Code 2007.
136191
137192<item><bf>March 30</bf>, Bernardo applies to OWASP <htmlurl
138193url="http://www.owasp.org/index.php/OWASP_Spring_Of_Code_2007_Applications#Bernardo_-_sqlmap"
@@ -153,16 +208,17 @@ major enhancements to the DBMS fingerprint functionalities and replacement
153208of the old inference algorithm with the bisection algorithm.
154209
155210<item><bf>September</bf>, Daniele leaves the project, <htmlurl
156- url="http://bernardodamele.blogspot.com" name="Bernardo Damele"> takes it
157- over.
211+ url="http://bernardodamele.blogspot.com" name="Bernardo Damele A. G.">
212+ takes it over.
158213
159214<item><bf>August</bf>, Daniele adds initial support for PostgreSQL and releases
160215version <bf>0.1</bf>.
161216
162217<item><bf>July 25</bf>, <htmlurl url="http://dbellucci.blogspot.com" name="Daniele Bellucci">
163218registers the sqlmap project on SourceForge and develops it on the
164- SourceForge Subversion repository. The skeleton is implemented and limited
165- support for MySQL added.
219+ <htmlurl url="http://sqlmap.svn.sourceforge.net/viewvc/sqlmap/"
220+ name="SourceForge Subversion repository">. The skeleton is implemented and
221+ limited support for MySQL added.
166222</itemize>
167223
168224
0 commit comments