<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: MultiInjector &#8211; Automated Stealth SQL Injection Tool</title>
	<atom:link href="http://www.darknet.org.uk/2008/11/multiinjector-automated-stealth-sql-injection-tool/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk/2008/11/multiinjector-automated-stealth-sql-injection-tool/</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Sat, 21 Nov 2009 06:04:59 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: navin</title>
		<link>http://www.darknet.org.uk/2008/11/multiinjector-automated-stealth-sql-injection-tool/#comment-125095</link>
		<dc:creator>navin</dc:creator>
		<pubDate>Thu, 13 Nov 2008 08:27:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1196#comment-125095</guid>
		<description>thanks for the update Raviv</description>
		<content:encoded><![CDATA[<p>thanks for the update Raviv</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Raviv Raz</title>
		<link>http://www.darknet.org.uk/2008/11/multiinjector-automated-stealth-sql-injection-tool/#comment-125093</link>
		<dc:creator>Raviv Raz</dc:creator>
		<pubDate>Thu, 13 Nov 2008 00:56:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1196#comment-125093</guid>
		<description>You may download MultiInjector v0.3 at:

http://chaptersinwebsecurity.blogspot.com/2008/11/multiinjector-v03-released.html

New features include:

1) Automatic defacement:
Try to concatenate a string to all user-defined text fields in DB

2) Run OS shell command on DB server:
Run any OS command as if you&#039;re running a command console on the DB machine

3) Run SQL query on DB server:
Execute SQL commands of your choice

4) Enable OS shell procedure on DB:
Revive the good old XP_CMDSHELL where it was turned off
(default mode in MSSQL-2005)

5) Add administrative user to DB server with password: T0pSeKret
Automagically join the Administrators family on DB machine

6) Enable remote desktop on DB server:
Turn remote terminal services back on...

It&#039;s a more stable and field-tested version.
Hope you enjoy.

Peace in the Middle East!
Raviv Raz</description>
		<content:encoded><![CDATA[<p>You may download MultiInjector v0.3 at:</p>
<p><a href="http://chaptersinwebsecurity.blogspot.com/2008/11/multiinjector-v03-released.html" rel="nofollow">http://chaptersinwebsecurity.blogspot.com/2008/11/multiinjector-v03-released.html</a></p>
<p>New features include:</p>
<p>1) Automatic defacement:<br />
Try to concatenate a string to all user-defined text fields in DB</p>
<p>2) Run OS shell command on DB server:<br />
Run any OS command as if you&#8217;re running a command console on the DB machine</p>
<p>3) Run SQL query on DB server:<br />
Execute SQL commands of your choice</p>
<p>4) Enable OS shell procedure on DB:<br />
Revive the good old XP_CMDSHELL where it was turned off<br />
(default mode in MSSQL-2005)</p>
<p>5) Add administrative user to DB server with password: T0pSeKret<br />
Automagically join the Administrators family on DB machine</p>
<p>6) Enable remote desktop on DB server:<br />
Turn remote terminal services back on&#8230;</p>
<p>It&#8217;s a more stable and field-tested version.<br />
Hope you enjoy.</p>
<p>Peace in the Middle East!<br />
Raviv Raz</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: l33t0n3</title>
		<link>http://www.darknet.org.uk/2008/11/multiinjector-automated-stealth-sql-injection-tool/#comment-125074</link>
		<dc:creator>l33t0n3</dc:creator>
		<pubDate>Fri, 07 Nov 2008 15:19:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1196#comment-125074</guid>
		<description>Traceback (most recent call last):
  File &quot;multiinjector.py&quot;, line 18, in 
    import psyco
ImportError: No module named psyco

wery thanks i get this :D</description>
		<content:encoded><![CDATA[<p>Traceback (most recent call last):<br />
  File &#8220;multiinjector.py&#8221;, line 18, in<br />
    import psyco<br />
ImportError: No module named psyco</p>
<p>wery thanks i get this <img src='http://www.darknet.org.uk/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: navin</title>
		<link>http://www.darknet.org.uk/2008/11/multiinjector-automated-stealth-sql-injection-tool/#comment-125066</link>
		<dc:creator>navin</dc:creator>
		<pubDate>Thu, 06 Nov 2008 10:22:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1196#comment-125066</guid>
		<description>yeah

now even skiddies will be able to flex their &#039;so-called&#039;  L337 &#124;-&#124;@x0r skills!!</description>
		<content:encoded><![CDATA[<p>yeah</p>
<p>now even skiddies will be able to flex their &#8217;so-called&#8217;  L337 |-|@x0r skills!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pantagruel</title>
		<link>http://www.darknet.org.uk/2008/11/multiinjector-automated-stealth-sql-injection-tool/#comment-125065</link>
		<dc:creator>Pantagruel</dc:creator>
		<pubDate>Wed, 05 Nov 2008 14:32:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1196#comment-125065</guid>
		<description>Oh dear, they just made a whole bunch of wannebee SQL crackers happy.

And indeed is this a good thing??, in a sense it is this allow even the pen-test nitwit to test their sql frontend before releasing it.</description>
		<content:encoded><![CDATA[<p>Oh dear, they just made a whole bunch of wannebee SQL crackers happy.</p>
<p>And indeed is this a good thing??, in a sense it is this allow even the pen-test nitwit to test their sql frontend before releasing it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: navin</title>
		<link>http://www.darknet.org.uk/2008/11/multiinjector-automated-stealth-sql-injection-tool/#comment-125061</link>
		<dc:creator>navin</dc:creator>
		<pubDate>Wed, 05 Nov 2008 10:40:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1196#comment-125061</guid>
		<description>whoa.....now i wonder how this can be a good thing!!</description>
		<content:encoded><![CDATA[<p>whoa&#8230;..now i wonder how this can be a good thing!!</p>
]]></content:encoded>
	</item>
</channel>
</rss>
