Forums: Sql Inject Tools - Forums

Jump to content

Page 1 of 1

Sql Inject Tools some tools for sql injection

#1 User is offline   skydance 

  • Corporal
  • Icon
  • Group: Members
  • Posts: 176
  • Joined: 14-September 03

Posted 07 August 2005 - 03:30 AM

Absinthe - Automated Blind SQL Injection

Absinthe was designed to automate the process of exploiting blind SQL
injection holes on Microsoft SQL Server. It currently supports SQL
Server, Oracle and Postgres.

LiLith : http forms scanner/injector

LiLith is an http scanner to perform web application audits. This tool
analyses webpages and looks for html <form> tags , which often refer to
dynamic pages that might be subject to sql injection or other flaws.

WIS (Web Injection Scanner)

C:\>wis http://www.someaspsite.com/

Web Injection Scanner (Protype 0.4)
by netXeyes, 2004.05.08 http://www.netXeyes.com security@vip.sina.com
กก

Scanning http://www.someaspsite.com/, Page: Unlimited
Patient, Please....

(001 + 000) Checking: /shownews.asp?newsid=204
SQL Injection Found: /shownews.asp?newsid=204


WED (Web Entry Detector)

enjoy ;)

Attached File(s)


0

#2 User is offline   sandalwood 

  • Private
  • Icon
  • Group: Members
  • Posts: 11
  • Joined: 20-August 05

Posted 20 August 2005 - 03:40 AM

I appreciate you putting these tools together in one post. Auditing SQL injection is often a time consuming process and unless you know the right tools to use you can end up wasting a lot of time. I think absinthe is the most useful of these tools but still requires you find the holes yourself first. The nessus module for finding sql injection is pretty good (sql_injection.nasl). I tried to quote the relevant code from that module here, but the forum software choked and didn't let it post. You can find it with nessus or xscan in the nasl modules folder.
0

#3 User is offline   skydance 

  • Corporal
  • Icon
  • Group: Members
  • Posts: 176
  • Joined: 14-September 03

Posted 20 August 2005 - 08:31 AM

never played with that nessus module.... i'll give it a try, thanx for the info sandalwood.
0

#4 User is offline   silos 

  • Corporal
  • Icon
  • Group: Members
  • Posts: 180
  • Joined: 19-August 03

Posted 25 August 2005 - 12:59 PM

Yeah, good tools.
There is a windows prog. called 'Acunetix Vulnerability Scanner' that does SQL injection testing among other things like CGI, Parameter Testing , Directory Traversal stuff etc.

http://www.acunetix.com/
0

#5 User is offline   skydance 

  • Corporal
  • Icon
  • Group: Members
  • Posts: 176
  • Joined: 14-September 03

Posted 26 August 2005 - 12:44 AM

well i tryed nessus and xscan with sql_inject module against foundsone's hacme bank and didnt find any sql vuln but that app is loaded with sql inject bugs... :blink:

acunetix is not free and with the trial ver you can scan only their test site....
0

#6 User is offline   DataStreaM 

  • Private
  • Icon
  • Group: Members
  • Posts: 2
  • Joined: 05-February 06

Posted 05 February 2006 - 12:07 AM

I know this might be kind of out of date and all, but jave you ever tried using Perl script for SQL injections? There is a .pl called Injector.pl made by magicsqlinjector.zip. Check it out. NOTE: YOU need active state perl if you have windows and another version if you have any other operating system. You must have perl installed.

...::: DataStreaM :::...
0

#7 User is offline   inko.gnito 

  • Private
  • Icon
  • Group: Members
  • Posts: 16
  • Joined: 29-January 04

Posted 15 March 2006 - 09:57 AM

more tools on SQL injection:

BobCat: http://www.northern-...cat/bobcat.html
Automagical SQL injector (the tool mentioned by DataStreaM): http://scoobygang.org/automagic.zip ()
DataThief by AppSecInc: they removed it from their site, but may be found using search engines
WPoison: http://wpoison.sourceforge.net/ (currently not available)
Blind SQL Injection Perl Tool (bsqlbf): http://www.unsec.net...nload/bsqlbf.pl and a demo: http://www.unsec.net...load/bsqlbf.avi
Sqlbftools: http://www.reversing.org/node/view/11
Ecyware GreenBlue Inspector - Integrated Web Analyzer Environment: http://www.ecyware.com/ (commercial analysis tool for testing your web apps)
and the PHP injection scanner posted by LittleHacker: http://www.governmen...=0&#entry131613
0

#8 User is offline   Xenos 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 58
  • Joined: 26-August 03

Posted 16 March 2006 - 05:11 AM

Many thanks to all of you ;)

Sql injection auditing was not my best pentests skill.

I used to trust weel-known commercial tools such as Retina or Qualysguard or Nessus 3 (THAT I CONSIDER AS A COMMERCIAL ONE :( )

Thanks a lot again. I'll try to use these tools for my next security assesment ;)

Xenos
0

#9 User is offline   skydance 

  • Corporal
  • Icon
  • Group: Members
  • Posts: 176
  • Joined: 14-September 03

Posted 16 March 2006 - 09:12 AM

sql power injector: hxxp://www.sqlpowerinjector.com/

and wpoison ;) enjoy!

Attached File(s)


0

#10 User is offline   EhTi 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 37
  • Joined: 14-October 05

Posted 16 March 2006 - 04:14 PM

very nice post...

oh and here's DataThief. guess what.. it's already posted on GSO :P

here it is.. (its only available in google's cache) http://72.14.203.104...n&ct=clnk&cd=16

download: http://www.governmen...type=post&id=25
0

#11 User is offline   fuxord22 

  • Private
  • Icon
  • Group: Members
  • Posts: 13
  • Joined: 01-November 05

Posted 19 March 2006 - 12:43 PM

acunetix isnt free, but you can make it free..if you know what i mean :ph34r: B)
0

#12 User is offline   snafkin 

  • Private
  • Icon
  • Group: Members
  • Posts: 5
  • Joined: 10-October 05

Posted 21 March 2006 - 11:07 PM

very nice post...Bro
0

#13 User is offline   grimm703 

  • Private
  • Icon
  • Group: Members
  • Posts: 6
  • Joined: 23-August 08

Posted 18 October 2008 - 10:32 PM

nice man tks :P

edit Edu: man, dindt u read our rules?... NO thks post, and dont bump up topics from the last century without adding good quality info. warned
0

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users