<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Official release of SQL Power Injector 1.2 - Download Now!</title>
	<atom:link href="http://www.darknet.org.uk/2007/10/official-release-of-sql-power-injector-12-download-now/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk/2007/10/official-release-of-sql-power-injector-12-download-now/</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<pubDate>Thu, 04 Dec 2008 20:44:01 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.5</generator>
		<item>
		<title>By: dre</title>
		<link>http://www.darknet.org.uk/2007/10/official-release-of-sql-power-injector-12-download-now/#comment-69338</link>
		<dc:creator>dre</dc:creator>
		<pubDate>Thu, 25 Oct 2007 23:14:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2007/10/official-release-of-sql-power-injector-12-download-now/#comment-69338</guid>
		<description>i'm going to start using this FF extension instead of a lot of the command line tools I use.  Thanks for the pointer!

in the past, i've mostly used SQLiX from owasp, as well as a few manual methods (mostly using Burp).  if you want the latest on &lt;a href="http://www.securityexperiment.com/se/documents/Overlooked%20SQL%20Injection%2020071021.pdf" rel="nofollow"&gt;Overlooked SQL Injection&lt;/a&gt; techniques, look no further than &lt;a href="http://securityexperiment.com/se/" rel="nofollow"&gt;Paul Battista&lt;/a&gt;, who i recently saw give this talk at toorcon 9 in san diego.

dave aitel and jms also put together a sort of proxy fuzzer/monitor (basically an RDBMS spy) called &lt;a href="http://lists.immunitysec.com/pipermail/dailydave/2007-October/004677.html" rel="nofollow"&gt;SQL Hooker&lt;/a&gt;, which is certainly worth a look at.  i think bestorm does something similar in their products.  immunitysec is also working on a similar tool that would help with file monitoring to increase the intelligence behind manual or automated web application black-box security testing</description>
		<content:encoded><![CDATA[<p>i&#8217;m going to start using this FF extension instead of a lot of the command line tools I use.  Thanks for the pointer!</p>
<p>in the past, i&#8217;ve mostly used SQLiX from owasp, as well as a few manual methods (mostly using Burp).  if you want the latest on <a href="http://www.securityexperiment.com/se/documents/Overlooked%20SQL%20Injection%2020071021.pdf" rel="nofollow">Overlooked SQL Injection</a> techniques, look no further than <a href="http://securityexperiment.com/se/" rel="nofollow">Paul Battista</a>, who i recently saw give this talk at toorcon 9 in san diego.</p>
<p>dave aitel and jms also put together a sort of proxy fuzzer/monitor (basically an RDBMS spy) called <a href="http://lists.immunitysec.com/pipermail/dailydave/2007-October/004677.html" rel="nofollow">SQL Hooker</a>, which is certainly worth a look at.  i think bestorm does something similar in their products.  immunitysec is also working on a similar tool that would help with file monitoring to increase the intelligence behind manual or automated web application black-box security testing</p>
]]></content:encoded>
	</item>
</channel>
</rss>
