<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Pangolin &#8211; Automatic SQL Injection Tool</title>
	<atom:link href="http://www.darknet.org.uk/2009/05/pangolin-automatic-sql-injection-tool/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk/2009/05/pangolin-automatic-sql-injection-tool/</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Sat, 21 Nov 2009 06:04:59 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: pangolin</title>
		<link>http://www.darknet.org.uk/2009/05/pangolin-automatic-sql-injection-tool/#comment-154212</link>
		<dc:creator>pangolin</dc:creator>
		<pubDate>Wed, 27 May 2009 06:57:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1790#comment-154212</guid>
		<description>I have check it, look at what it send : http://www.nosec.org/product/upgrade.php, it is upgrade checking, do you think so?

Just visit here : http://www.nosec.org/en/node/73</description>
		<content:encoded><![CDATA[<p>I have check it, look at what it send : <a href="http://www.nosec.org/product/upgrade.php" rel="nofollow">http://www.nosec.org/product/upgrade.php</a>, it is upgrade checking, do you think so?</p>
<p>Just visit here : <a href="http://www.nosec.org/en/node/73" rel="nofollow">http://www.nosec.org/en/node/73</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: makk</title>
		<link>http://www.darknet.org.uk/2009/05/pangolin-automatic-sql-injection-tool/#comment-151265</link>
		<dc:creator>makk</dc:creator>
		<pubDate>Sun, 17 May 2009 08:31:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1790#comment-151265</guid>
		<description>thanx buddy</description>
		<content:encoded><![CDATA[<p>thanx buddy</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: User</title>
		<link>http://www.darknet.org.uk/2009/05/pangolin-automatic-sql-injection-tool/#comment-150556</link>
		<dc:creator>User</dc:creator>
		<pubDate>Thu, 14 May 2009 14:36:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1790#comment-150556</guid>
		<description>Thanks for the comments... Yes, some folks read the comments, and thank god I did... :-)</description>
		<content:encoded><![CDATA[<p>Thanks for the comments&#8230; Yes, some folks read the comments, and thank god I did&#8230; <img src='http://www.darknet.org.uk/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Darknet</title>
		<link>http://www.darknet.org.uk/2009/05/pangolin-automatic-sql-injection-tool/#comment-150482</link>
		<dc:creator>Darknet</dc:creator>
		<pubDate>Thu, 14 May 2009 08:12:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1790#comment-150482</guid>
		<description>Thanks for the info guys, honestly I was always skeptical about posting Pangolin, but I thought it&#039;d had developed a long way. Always found it a little suspicious.

I can understand the rational for passing thru their HTTP server for that function, but doing it without disclosure is lame.

I don&#039;t think I&#039;ll be posting any more of it&#039;s updated versions here.

I hope people read these comments.</description>
		<content:encoded><![CDATA[<p>Thanks for the info guys, honestly I was always skeptical about posting Pangolin, but I thought it&#8217;d had developed a long way. Always found it a little suspicious.</p>
<p>I can understand the rational for passing thru their HTTP server for that function, but doing it without disclosure is lame.</p>
<p>I don&#8217;t think I&#8217;ll be posting any more of it&#8217;s updated versions here.</p>
<p>I hope people read these comments.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Navin</title>
		<link>http://www.darknet.org.uk/2009/05/pangolin-automatic-sql-injection-tool/#comment-150350</link>
		<dc:creator>Navin</dc:creator>
		<pubDate>Wed, 13 May 2009 18:32:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1790#comment-150350</guid>
		<description>+1 @anony

Thanks natron!!</description>
		<content:encoded><![CDATA[<p>+1 @anony</p>
<p>Thanks natron!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anony</title>
		<link>http://www.darknet.org.uk/2009/05/pangolin-automatic-sql-injection-tool/#comment-150343</link>
		<dc:creator>Anony</dc:creator>
		<pubDate>Wed, 13 May 2009 17:56:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1790#comment-150343</guid>
		<description>I would never even consider downloading the tool cause of that. Thanks for pointing it out natron.</description>
		<content:encoded><![CDATA[<p>I would never even consider downloading the tool cause of that. Thanks for pointing it out natron.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: natron</title>
		<link>http://www.darknet.org.uk/2009/05/pangolin-automatic-sql-injection-tool/#comment-150334</link>
		<dc:creator>natron</dc:creator>
		<pubDate>Wed, 13 May 2009 16:37:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1790#comment-150334</guid>
		<description>Beware, for certain types of SQLi, Pangolin&#039;s creators get a copy of all the data retrieved:

&quot;...After decoding we found that the results of the injection is sent to a nosec.org web server, and then Pangolin perform a GET to retrieve the data. WTH?&quot;

http://laramies.blogspot.com/2009/05/pangolin-and-your-data.html

I understand why they did this, but it should be pointed out to the end users so they understand what&#039;s occurring.  That they don&#039;t is very shady.

n</description>
		<content:encoded><![CDATA[<p>Beware, for certain types of SQLi, Pangolin&#8217;s creators get a copy of all the data retrieved:</p>
<p>&#8220;&#8230;After decoding we found that the results of the injection is sent to a nosec.org web server, and then Pangolin perform a GET to retrieve the data. WTH?&#8221;</p>
<p><a href="http://laramies.blogspot.com/2009/05/pangolin-and-your-data.html" rel="nofollow">http://laramies.blogspot.com/2009/05/pangolin-and-your-data.html</a></p>
<p>I understand why they did this, but it should be pointed out to the end users so they understand what&#8217;s occurring.  That they don&#8217;t is very shady.</p>
<p>n</p>
]]></content:encoded>
	</item>
</channel>
</rss>
