<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: sqlninja 0.2.3 released &#8211; Advanced Automated SQL Injection Tool for MS-SQL</title>
	<atom:link href="http://www.darknet.org.uk/2008/05/sqlninja-023-released-advanced-automated-sql-injection-tool-for-ms-sql/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk/2008/05/sqlninja-023-released-advanced-automated-sql-injection-tool-for-ms-sql/</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 14 Feb 2012 00:17:07 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Navin</title>
		<link>http://www.darknet.org.uk/2008/05/sqlninja-023-released-advanced-automated-sql-injection-tool-for-ms-sql/#comment-123292</link>
		<dc:creator>Navin</dc:creator>
		<pubDate>Sat, 07 Jun 2008 06:30:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=863#comment-123292</guid>
		<description>razta&#039;s right but I feel tht this tool is both a boon and a bane. N00bs getting their hands on tools like this increases risk to SQL servers.

BTW &quot;Fancy going from a SQL Injection to a full GUI access on the DB server? What about extracting password hashes on the fly? Take a few SQL Injection tricks, add a couple of remote shots in the registry to disable Data Execution Prevention, mix with a little Perl that automatically generates a debug script, put all this in a shaker with a Metasploit wrapper, shake well and you have the latest release of sqlninja!&quot; 

Nice play of words!!</description>
		<content:encoded><![CDATA[<p>razta&#8217;s right but I feel tht this tool is both a boon and a bane. N00bs getting their hands on tools like this increases risk to SQL servers.</p>
<p>BTW &#8220;Fancy going from a SQL Injection to a full GUI access on the DB server? What about extracting password hashes on the fly? Take a few SQL Injection tricks, add a couple of remote shots in the registry to disable Data Execution Prevention, mix with a little Perl that automatically generates a debug script, put all this in a shaker with a Metasploit wrapper, shake well and you have the latest release of sqlninja!&#8221; </p>
<p>Nice play of words!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jinesh Doshi</title>
		<link>http://www.darknet.org.uk/2008/05/sqlninja-023-released-advanced-automated-sql-injection-tool-for-ms-sql/#comment-123264</link>
		<dc:creator>Jinesh Doshi</dc:creator>
		<pubDate>Wed, 04 Jun 2008 07:54:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=863#comment-123264</guid>
		<description>@ Jeremy Richards

Hey Thank you so much. It just didnt click to me :(.</description>
		<content:encoded><![CDATA[<p>@ Jeremy Richards</p>
<p>Hey Thank you so much. It just didnt click to me :(.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jeremy Richards</title>
		<link>http://www.darknet.org.uk/2008/05/sqlninja-023-released-advanced-automated-sql-injection-tool-for-ms-sql/#comment-123262</link>
		<dc:creator>Jeremy Richards</dc:creator>
		<pubDate>Tue, 03 Jun 2008 20:03:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=863#comment-123262</guid>
		<description>Jinesh,

you&#039;ll notice the following in the post above: &quot;Sqlninja is a tool written in PERL to...&quot;

Perl binaries for windows can be found: 
perl.com/download.csp#win32

sqlmap.py is also a great tool and written in python.  Python binaries for windows can be found:
python.org/ftp/python/2.5.2/python-2.5.2.msi</description>
		<content:encoded><![CDATA[<p>Jinesh,</p>
<p>you&#8217;ll notice the following in the post above: &#8220;Sqlninja is a tool written in PERL to&#8230;&#8221;</p>
<p>Perl binaries for windows can be found:<br />
perl.com/download.csp#win32</p>
<p>sqlmap.py is also a great tool and written in python.  Python binaries for windows can be found:<br />
python.org/ftp/python/2.5.2/python-2.5.2.msi</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nico</title>
		<link>http://www.darknet.org.uk/2008/05/sqlninja-023-released-advanced-automated-sql-injection-tool-for-ms-sql/#comment-123254</link>
		<dc:creator>Nico</dc:creator>
		<pubDate>Mon, 02 Jun 2008 14:20:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=863#comment-123254</guid>
		<description>This IS a great tool for IT pros.  Have you heard of any loopholes it finds if the SQL statements are not concatenated and the input fields are escaped properly?</description>
		<content:encoded><![CDATA[<p>This IS a great tool for IT pros.  Have you heard of any loopholes it finds if the SQL statements are not concatenated and the input fields are escaped properly?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jinesh Doshi</title>
		<link>http://www.darknet.org.uk/2008/05/sqlninja-023-released-advanced-automated-sql-injection-tool-for-ms-sql/#comment-123251</link>
		<dc:creator>Jinesh Doshi</dc:creator>
		<pubDate>Mon, 02 Jun 2008 08:20:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=863#comment-123251</guid>
		<description>Why are these tools not available on windows?? So even some dumb heads like me can do a little show off :).</description>
		<content:encoded><![CDATA[<p>Why are these tools not available on windows?? So even some dumb heads like me can do a little show off :).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: razta</title>
		<link>http://www.darknet.org.uk/2008/05/sqlninja-023-released-advanced-automated-sql-injection-tool-for-ms-sql/#comment-123231</link>
		<dc:creator>razta</dc:creator>
		<pubDate>Fri, 30 May 2008 18:29:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=863#comment-123231</guid>
		<description>Great tool!

Sorry for the double post, again! There should be an edit button, could use cookies to do this.

In the newest version they have integrated it with metasploit and VNC, you can now have access to the SQL server with a complete GUI! Wait till script kiddies get a hold of this! Hopefully admins will now start to think about security when coding.

My SQL injection skills are minimal, so it will definitely come in use (when im legally testing my own SQL server).</description>
		<content:encoded><![CDATA[<p>Great tool!</p>
<p>Sorry for the double post, again! There should be an edit button, could use cookies to do this.</p>
<p>In the newest version they have integrated it with metasploit and VNC, you can now have access to the SQL server with a complete GUI! Wait till script kiddies get a hold of this! Hopefully admins will now start to think about security when coding.</p>
<p>My SQL injection skills are minimal, so it will definitely come in use (when im legally testing my own SQL server).</p>
]]></content:encoded>
	</item>
</channel>
</rss>

