<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: sqlmap 0.7 Released &#8211; Automatic SQL Injection Tool</title>
	<atom:link href="http://www.darknet.org.uk/2009/07/sqlmap-0-7-released-automatic-sql-injection-tool/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk/2009/07/sqlmap-0-7-released-automatic-sql-injection-tool/</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 14 Feb 2012 00:17:07 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Madsen</title>
		<link>http://www.darknet.org.uk/2009/07/sqlmap-0-7-released-automatic-sql-injection-tool/#comment-158854</link>
		<dc:creator>Madsen</dc:creator>
		<pubDate>Sun, 30 Aug 2009 13:21:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1958#comment-158854</guid>
		<description>Hi guys.
The one for Windows has a trojan gen.
don&#039;t download it.

Cheers!</description>
		<content:encoded><![CDATA[<p>Hi guys.<br />
The one for Windows has a trojan gen.<br />
don&#8217;t download it.</p>
<p>Cheers!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Darknet</title>
		<link>http://www.darknet.org.uk/2009/07/sqlmap-0-7-released-automatic-sql-injection-tool/#comment-158822</link>
		<dc:creator>Darknet</dc:creator>
		<pubDate>Tue, 25 Aug 2009 14:57:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1958#comment-158822</guid>
		<description>&lt;strong&gt;GZero:&lt;/strong&gt; &quot;Or to route it though you to a fake target so it looks like someone else is port scanning while you just read the tcpdump&quot; I believe he&#039;s referring to &lt;a href=&quot;http://nmap.org/book/idlescan.html&quot; rel=&quot;nofollow&quot;&gt;idle scanning&lt;/a&gt; as discovered by Antirez the author of Hping2.</description>
		<content:encoded><![CDATA[<p><strong>GZero:</strong> &#8220;Or to route it though you to a fake target so it looks like someone else is port scanning while you just read the tcpdump&#8221; I believe he&#8217;s referring to <a href="http://nmap.org/book/idlescan.html" rel="nofollow">idle scanning</a> as discovered by Antirez the author of Hping2.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GZero</title>
		<link>http://www.darknet.org.uk/2009/07/sqlmap-0-7-released-automatic-sql-injection-tool/#comment-158820</link>
		<dc:creator>GZero</dc:creator>
		<pubDate>Tue, 25 Aug 2009 10:06:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1958#comment-158820</guid>
		<description>Yeah Fyodor must feel like a real fucking idiot. Total waste of time and energy, it&#039;s not like nmap can manipulate packets at all.

&quot;And yes I haveed crafted my own packets for port scanning&quot; - Bet you haven&#039;t
&quot;you need to when you scan behind a firewall. &quot; - No you don&#039;t, your firewall, your rules
&quot;Or to route it though you to a fake target so it looks like someone else is port scanning while you just read the tcpdump.&quot; - This sounds and smells like bullshit, are you ineptly referring to SRC spoofing?

When you do your &quot;mostly ASCII&quot; blind SQL injections, using your handcrafted requests and techniques. How long does it take?</description>
		<content:encoded><![CDATA[<p>Yeah Fyodor must feel like a real fucking idiot. Total waste of time and energy, it&#8217;s not like nmap can manipulate packets at all.</p>
<p>&#8220;And yes I haveed crafted my own packets for port scanning&#8221; &#8211; Bet you haven&#8217;t<br />
&#8220;you need to when you scan behind a firewall. &#8221; &#8211; No you don&#8217;t, your firewall, your rules<br />
&#8220;Or to route it though you to a fake target so it looks like someone else is port scanning while you just read the tcpdump.&#8221; &#8211; This sounds and smells like bullshit, are you ineptly referring to SRC spoofing?</p>
<p>When you do your &#8220;mostly ASCII&#8221; blind SQL injections, using your handcrafted requests and techniques. How long does it take?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anony</title>
		<link>http://www.darknet.org.uk/2009/07/sqlmap-0-7-released-automatic-sql-injection-tool/#comment-158781</link>
		<dc:creator>Anony</dc:creator>
		<pubDate>Fri, 21 Aug 2009 03:13:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1958#comment-158781</guid>
		<description>Jeff, you&#039;re an idiot. SQLMap comes in hand when it&#039;s blind sql and you don&#039;t want to waste all fucking day brute forcing letter by letter to try get the whole DB content.</description>
		<content:encoded><![CDATA[<p>Jeff, you&#8217;re an idiot. SQLMap comes in hand when it&#8217;s blind sql and you don&#8217;t want to waste all fucking day brute forcing letter by letter to try get the whole DB content.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: S0L0</title>
		<link>http://www.darknet.org.uk/2009/07/sqlmap-0-7-released-automatic-sql-injection-tool/#comment-158584</link>
		<dc:creator>S0L0</dc:creator>
		<pubDate>Thu, 06 Aug 2009 20:59:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1958#comment-158584</guid>
		<description>Jeff Price aka jp is a troll. Check out his other posts.</description>
		<content:encoded><![CDATA[<p>Jeff Price aka jp is a troll. Check out his other posts.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jp</title>
		<link>http://www.darknet.org.uk/2009/07/sqlmap-0-7-released-automatic-sql-injection-tool/#comment-158579</link>
		<dc:creator>jp</dc:creator>
		<pubDate>Thu, 06 Aug 2009 14:43:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1958#comment-158579</guid>
		<description>you you would be one of those retarded script kiddies</description>
		<content:encoded><![CDATA[<p>you you would be one of those retarded script kiddies</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pyus</title>
		<link>http://www.darknet.org.uk/2009/07/sqlmap-0-7-released-automatic-sql-injection-tool/#comment-158563</link>
		<dc:creator>Pyus</dc:creator>
		<pubDate>Thu, 06 Aug 2009 10:29:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1958#comment-158563</guid>
		<description>sometimes i touch myself behind my firewall with nmap</description>
		<content:encoded><![CDATA[<p>sometimes i touch myself behind my firewall with nmap</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jp</title>
		<link>http://www.darknet.org.uk/2009/07/sqlmap-0-7-released-automatic-sql-injection-tool/#comment-158496</link>
		<dc:creator>jp</dc:creator>
		<pubDate>Sun, 02 Aug 2009 23:11:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1958#comment-158496</guid>
		<description>lets see you use nmap to scan a computer behind a firewall.</description>
		<content:encoded><![CDATA[<p>lets see you use nmap to scan a computer behind a firewall.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: um</title>
		<link>http://www.darknet.org.uk/2009/07/sqlmap-0-7-released-automatic-sql-injection-tool/#comment-158490</link>
		<dc:creator>um</dc:creator>
		<pubDate>Sun, 02 Aug 2009 16:30:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1958#comment-158490</guid>
		<description>Jeff, I&#039;m pretty sure you wasted your time. I can&#039;t think of any reason a hand crafted packet could be more effective from behind a firewall than what nmap can create. And I know for a fact nmap can spoof the source address.

And yeah, you can compare the too. Both tools automate a time consuming and repetitive task so you can focus on the results without wasting time getting them.</description>
		<content:encoded><![CDATA[<p>Jeff, I&#8217;m pretty sure you wasted your time. I can&#8217;t think of any reason a hand crafted packet could be more effective from behind a firewall than what nmap can create. And I know for a fact nmap can spoof the source address.</p>
<p>And yeah, you can compare the too. Both tools automate a time consuming and repetitive task so you can focus on the results without wasting time getting them.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jeff Price</title>
		<link>http://www.darknet.org.uk/2009/07/sqlmap-0-7-released-automatic-sql-injection-tool/#comment-158471</link>
		<dc:creator>Jeff Price</dc:creator>
		<pubDate>Sat, 01 Aug 2009 01:09:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1958#comment-158471</guid>
		<description>sql injection is way different then making ethernet frames. Mostly ascii. You can&#039;t really compare the two. And yes I haveed crafted my own packets for port scanning, you need to when you scan behind a firewall. Or to route it though you to a fake target so it looks like someone else is port scanning while you just read the tcpdump.</description>
		<content:encoded><![CDATA[<p>sql injection is way different then making ethernet frames. Mostly ascii. You can&#8217;t really compare the two. And yes I haveed crafted my own packets for port scanning, you need to when you scan behind a firewall. Or to route it though you to a fake target so it looks like someone else is port scanning while you just read the tcpdump.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

