10 March 2010 | 11,100 views

WebRaider – Automated Web Application Exploitation Tool

Prevent Network Security Leaks with Acunetix

WebRaider is a plugin based automated web application exploitation tool which focuses to get a shell from multiple targets or injection point

Idea of this attack is very simple. Getting a reverse shell from an SQL Injection with one request without using an extra channel such as TFTP, FTP to upload the initial payload.

  • It’s only one request therefore faster,
  • Simple, you don’t need a tool you can do it manually by using your browser or a simple MITM proxy,
  • Just copy paste the payload,
  • CSRF(able), It’s possible to craft a link and carry out a CSRF attack that will give you a reverse shell,
  • It’s not fixed, you can change the payload,
  • It’s short, Generally not more than 3.500 characters,
  • Doesn’t require any application on the target system like FTP, TFTP or debug.exe,
  • Easy to automate.

Dependencies

Internally WebRaider uses Metasploit. The authors use a specific version of Metasploit, they trimmed the fat from Metasploit to launch it faster and make it smaller. You can change the paths and make it work with the latest Metasploit of your own setup.

Also note due to the reverse shells and Metasploit components this software will be detected a virus by AV software.

You can download WebRaider here:

WebRaider-0.2.3.8.zip

Or read more here.



Recent in Database Hacking:
- Navy Sys Admin Hacks Into Databases From Aircraft Carrier
- aidSQL – PHP Application For SQL Injection Detection & Exploitation
- 1 Million Accounts Leaked From Banks, Government Agencies & Consultancy Firms

Related Posts:
- Samurai Web Testing Framework 0.6 Released – Web Application Security LiveCD
- Samurai Web Testing Framework – Web Application Security LiveCD
- Samurai Web Testing Framework v0.8 Released – Pen Testing Security LiveCD

Most Read in Database Hacking:
- Pangolin – Automatic SQL Injection Tool - 71,402 views
- bsqlbf 1.1 – Blind SQL Injection Tool - 53,737 views
- Absinthe Blind SQL Injection Tool/Software - 38,919 views

Advertise on Darknet

One Response to “WebRaider – Automated Web Application Exploitation Tool”

  1. alias 11 March 2010 at 12:02 am Permalink

    good tool