<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; Database Hacking</title>
	<atom:link href="http://www.darknet.org.uk/tag/database-hacking/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>The Mole &#8211; Automatic SQL Injection SQLi Exploitation Tool</title>
		<link>http://www.darknet.org.uk/2011/12/the-mole-automatic-sql-injection-sqli-exploitation-tool/</link>
		<comments>http://www.darknet.org.uk/2011/12/the-mole-automatic-sql-injection-sqli-exploitation-tool/#comments</comments>
		<pubDate>Thu, 01 Dec 2011 16:50:44 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Database Hacking]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[automatic sql injection tool]]></category>
		<category><![CDATA[database-security]]></category>
		<category><![CDATA[exploitation tool]]></category>
		<category><![CDATA[hacking tool]]></category>
		<category><![CDATA[sql injection exploitation]]></category>
		<category><![CDATA[sql-injection]]></category>
		<category><![CDATA[sql-injection-tool]]></category>
		<category><![CDATA[sqli tool]]></category>
		<category><![CDATA[the mole]]></category>
		<category><![CDATA[the mole sql injection tool]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3234</guid>
		<description><![CDATA[The Mole is an automatic SQL Injection exploitation tool. Only by providing a vulnerable URL and a valid string on the site it can detect the injection and exploit it, either by using the union technique or a boolean query based technique. Features Support for injections using Mysql, SQL Server, Postgres and Oracle databases. Command [...]]]></description>
			<content:encoded><![CDATA[<p>The Mole is an automatic SQL Injection exploitation tool. Only by providing a vulnerable URL and a valid string on the site it can detect the injection and exploit it, either by using the union technique or a boolean query based technique.</p>
<p align="center"><img src="http://farm8.staticflickr.com/7016/6436951245_06f742897a.jpg" alt="The Mole SQL Injection Tool" /></p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<p><strong>Features</strong></p>
<ul>
<li>    Support for injections using Mysql, SQL Server, Postgres and Oracle databases.</li>
<li>    Command line interface. Different commands trigger different actions.</li>
<li>    Auto-completion for commands, command arguments and database, table and columns names.</li>
<li>    Support for query filters, in order to bypass certain IPS/IDS rules using generic filters, and the possibility of creating new ones easily.</li>
<li>    Developed in python 3.</li>
</ul>
<p>If you want to know how to use The Mole there&#8217;s a good tutorial <a href="http://themole.sourceforge.net/?q=tutorial">here</a>.</p>
<p>You can download The Mole here:</p>
<p>Windows: <a href="http://sourceforge.net/projects/themole/files/themole-0.2.6/themole-0.2.6-win32.zip/download">themole-0.2.6-win32.zip</a><br />
Linux: <a href="http://sourceforge.net/projects/themole/files/themole-0.2.6/themole-0.2.6-lin-src.tar.gz/download">themole-0.2.6-lin-src.tar.gz</a></p>
<p>Or read more <a href="http://themole.sourceforge.net/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=The+Mole+%E2%80%93+Automatic+SQL+Injection+SQLi+Exploitation+Tool+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3234+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/12/the-mole-automatic-sql-injection-sqli-exploitation-tool/&amp;t=The+Mole+%E2%80%93+Automatic+SQL+Injection+SQLi+Exploitation+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/12/the-mole-automatic-sql-injection-sqli-exploitation-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/12/the-mole-automatic-sql-injection-sqli-exploitation-tool/&amp;title=The+Mole+%E2%80%93+Automatic+SQL+Injection+SQLi+Exploitation+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/12/the-mole-automatic-sql-injection-sqli-exploitation-tool/&amp;title=The+Mole+%E2%80%93+Automatic+SQL+Injection+SQLi+Exploitation+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/12/the-mole-automatic-sql-injection-sqli-exploitation-tool/&amp;title=The+Mole+%E2%80%93+Automatic+SQL+Injection+SQLi+Exploitation+Tool" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/12/the-mole-automatic-sql-injection-sqli-exploitation-tool/&amp;title=The+Mole+%E2%80%93+Automatic+SQL+Injection+SQLi+Exploitation+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F12%2Fthe-mole-automatic-sql-injection-sqli-exploitation-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/12/the-mole-automatic-sql-injection-sqli-exploitation-tool/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>sqlsus 0.7.1 Released &#8211; MySQL Injection &amp; Takeover Tool</title>
		<link>http://www.darknet.org.uk/2011/11/sqlsus-0-7-1-released-mysql-injection-takeover-tool/</link>
		<comments>http://www.darknet.org.uk/2011/11/sqlsus-0-7-1-released-mysql-injection-takeover-tool/#comments</comments>
		<pubDate>Mon, 21 Nov 2011 14:15:08 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Database Hacking]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[database-security]]></category>
		<category><![CDATA[hacking mysql]]></category>
		<category><![CDATA[hacking toold]]></category>
		<category><![CDATA[mysql]]></category>
		<category><![CDATA[mysql hacking tool]]></category>
		<category><![CDATA[mysql injection]]></category>
		<category><![CDATA[mysql injection tool]]></category>
		<category><![CDATA[mysql security]]></category>
		<category><![CDATA[mysql takeover]]></category>
		<category><![CDATA[sql-injection]]></category>
		<category><![CDATA[sql-injection-tool]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1680</guid>
		<description><![CDATA[sqlsus is an open source MySQL injection and takeover tool, written in perl. Via a command line interface, you can retrieve the database(s) structure, inject your own SQL queries (even complex ones), download files from the web server, crawl the website for writable directories, upload and control a backdoor, clone the database(s), and much more&#8230;Whenever [...]]]></description>
			<content:encoded><![CDATA[<p>sqlsus is an open source MySQL injection and takeover tool, written in perl. Via a command line interface, you can retrieve the database(s) structure, inject your own SQL queries (even complex ones), download files from the web server, crawl the website for writable directories, upload and control a backdoor, clone the database(s), and much more&#8230;Whenever relevant, sqlsus will mimic a MySQL console output.</p>
<p>sqlsus focuses on speed and efficiency, optimising the available injection space, making the best use (I can think of) of MySQL functions. It uses stacked subqueries and an powerful blind injection algorithm to maximise the data gathered per web server hit. Using multithreading on top of that, sqlsus is an extremely fast database dumper, be it for inband or blind injection.If the privileges are high enough, sqlsus will be a great help for uploading a backdoor through the injection point, and takeover the web server.</p>
<p>It uses SQLite as a backend, for an easier use of what has been dumped, and integrates a lot of usual features (see below) such as cookie support, socks/http proxying, https..</p>
<p><strong>What&#8217;s New</strong></p>
<p>Starting with version 0.7, sqlsus now supports time-based blind injection and automatically detects web server / suhosin / etc.. length restrictions.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<ul>
<li>Added time-based blind injection support (added option &#8220;blind_sleep&#8221;, and renamed &#8220;string_to_match&#8221; to &#8220;blind_string&#8221;).</li>
<li>It is now possible to force sqlsus to exit when it&#8217;s hanging (i.e.: retrieving data), by hitting Ctrl-C more than twice.</li>
<li>Rewrite of &#8220;autoconf max_sendable&#8221;, so that sqlsus will properly detect which length restriction applies (WEB server / layer above). (removed option &#8220;max_sendable&#8221;, added options &#8220;max_url_length&#8221; and &#8220;max_inj_length&#8221;)</li>
<li>Uploading a file now sends it into chunks under the length restriction.</li>
<li>sqlsus now saves variables after each command, so that forcing it to quit (or killing it) will not discard the changes that were made.</li>
<li>Added a progress bar to inband mode, sqlsus now determines the number of rows to be returned prior to fetching them.</li>
<li>get db (tables/columns) in inband mode now uses multithreading (like everything else).</li>
<li>clone now uses count(*) if available (set by &#8220;get count&#8221; / &#8220;get db&#8221;), instead of using fetch-ahead.</li>
<li>In blind mode, &#8220;start&#8221; will now test if things work the way they should, by injecting 2 queries : one true and one false.</li>
<li>sqlsus now prints what configuration options are overridden (when a saved value differs from the configuration file).</li>
</ul>
<p>You can download sqlsus 0.7.1 here:</p>
<p><a href="http://sourceforge.net/projects/sqlsus/files/sqlsus/sqlsus-0.7.1.tgz/download">sqlsus-0.7.1.tgz</a></p>
<p>Or read more <a href="http://sqlsus.sourceforge.net/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=sqlsus+0.7.1+Released+%E2%80%93+MySQL+Injection+%26+Takeover+Tool+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1680+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/11/sqlsus-0-7-1-released-mysql-injection-takeover-tool/&amp;t=sqlsus+0.7.1+Released+%E2%80%93+MySQL+Injection+%26+Takeover+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/11/sqlsus-0-7-1-released-mysql-injection-takeover-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/11/sqlsus-0-7-1-released-mysql-injection-takeover-tool/&amp;title=sqlsus+0.7.1+Released+%E2%80%93+MySQL+Injection+%26+Takeover+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/11/sqlsus-0-7-1-released-mysql-injection-takeover-tool/&amp;title=sqlsus+0.7.1+Released+%E2%80%93+MySQL+Injection+%26+Takeover+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/11/sqlsus-0-7-1-released-mysql-injection-takeover-tool/&amp;title=sqlsus+0.7.1+Released+%E2%80%93+MySQL+Injection+%26+Takeover+Tool" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/11/sqlsus-0-7-1-released-mysql-injection-takeover-tool/&amp;title=sqlsus+0.7.1+Released+%E2%80%93+MySQL+Injection+%26+Takeover+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F11%2Fsqlsus-0-7-1-released-mysql-injection-takeover-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/11/sqlsus-0-7-1-released-mysql-injection-takeover-tool/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>sqlmap 0.9 Released &#8211; Automatic Blind SQL Injection Tool</title>
		<link>http://www.darknet.org.uk/2011/04/sqlmap-0-9-released-automatic-blind-sql-injection-tool/</link>
		<comments>http://www.darknet.org.uk/2011/04/sqlmap-0-9-released-automatic-blind-sql-injection-tool/#comments</comments>
		<pubDate>Thu, 14 Apr 2011 09:16:51 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Database Hacking]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[automatic sql injection]]></category>
		<category><![CDATA[database-security]]></category>
		<category><![CDATA[sql-injection]]></category>
		<category><![CDATA[sql-injection-tool]]></category>
		<category><![CDATA[sqlmap]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[web-application-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3087</guid>
		<description><![CDATA[It&#8217;s been a while since we&#8217;ve written about sqlmap, the last time was when 0.7 was released back in July 2009 &#8211; sqlmap 0.7 Released – Automatic SQL Injection Tool. Well sqlmap 0.9 has been released and has a considerable amount of changes including an almost entirely re-written SQL Injection detection engine. For those that [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s been a while since we&#8217;ve written about <a href="http://www.darknet.org.uk/tag/sqlmap/">sqlmap</a>, the last time was when 0.7 was released back in July 2009 &#8211; <a href="http://www.darknet.org.uk/2009/07/sqlmap-0-7-released-automatic-sql-injection-tool/">sqlmap 0.7 Released – Automatic SQL Injection Tool</a>.</p>
<p>Well sqlmap 0.9 has been released and has a considerable amount of changes including an almost entirely re-written <a href="http://www.darknet.org.uk/tag/sql-injection/">SQL Injection</a> detection engine.</p>
<p>For those that aren&#8217;t familiar with the tool, sqlmap is an open source penetration testing tool that automates the process of detecting and exploiting SQL injection flaws and taking over of database servers. It comes with a kick-ass detection engine, many niche features for the ultimate penetration tester and a broad range of switches lasting from database fingerprinting, over data fetching from the database, to accessing the underlying file system and executing commands on the operating system via out-of-band connections.</p>
<p><strong>New Features/Changes</strong></p>
<ul>
<li>Rewritten SQL injection detection engine (Bernardo and Miroslav).</li>
<li>Support to directly connect to the database without passing via a SQL injection, -d switch (Bernardo and Miroslav).</li>
<li>Added full support for both time-based blind SQL injection and error-based SQL injection techniques (Bernardo and Miroslav).</li>
<li>Implemented support for SQLite 2 and 3 (Bernardo and Miroslav).</li>
<li>Implemented support for Firebird (Bernardo and Miroslav).</li>
<li>Implemented support for Microsoft Access, Sybase and SAP MaxDB (Miroslav).</li>
<li>Added support to tamper injection data with &#8211;tamper switch (Bernardo and Miroslav).</li>
<li>Added automatic recognition of password hashes format and support to crack them with a dictionary-based attack (Miroslav).</li>
<li>Added support to fetch unicode data (Bernardo and Miroslav).</li>
<li>Added support to use persistent HTTP(s) connection for speed improvement, &#8211;keep-alive switch (Miroslav).</li>
<li>Implemented several optimization switches to speed up the exploitation of SQL injections (Bernardo and Miroslav).</li>
<li>Support to parse and test forms on target url, &#8211;forms switch (Bernardo and Miroslav).</li>
<li>Added switches to brute-force tables names and columns names with a dictionary attack, &#8211;common-tables and &#8211;common-columns.</li>
</ul>
<p>The complete changelog is available for viewing <a href="https://svn.sqlmap.org/sqlmap/trunk/sqlmap/doc/ChangeLog">here</a>.</p>
<p>You can also download the user manual here [PDF] &#8211; <a href="http://sqlmap.sourceforge.net/doc/README.pdf">sqlmap README</a></p>
<p>You can download sqlmap 0.9 here:</p>
<p><a href="http://downloads.sourceforge.net/sqlmap/sqlmap-0.9.tar.gz">sqlmap-0.9.tar.gz</a></p>
<p>Or read more <a href="http://sqlmap.sourceforge.net/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=sqlmap+0.9+Released+%E2%80%93+Automatic+Blind+SQL+Injection+Tool+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3087+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/04/sqlmap-0-9-released-automatic-blind-sql-injection-tool/&amp;t=sqlmap+0.9+Released+%E2%80%93+Automatic+Blind+SQL+Injection+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/04/sqlmap-0-9-released-automatic-blind-sql-injection-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/04/sqlmap-0-9-released-automatic-blind-sql-injection-tool/&amp;title=sqlmap+0.9+Released+%E2%80%93+Automatic+Blind+SQL+Injection+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/04/sqlmap-0-9-released-automatic-blind-sql-injection-tool/&amp;title=sqlmap+0.9+Released+%E2%80%93+Automatic+Blind+SQL+Injection+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/04/sqlmap-0-9-released-automatic-blind-sql-injection-tool/&amp;title=sqlmap+0.9+Released+%E2%80%93+Automatic+Blind+SQL+Injection+Tool" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/04/sqlmap-0-9-released-automatic-blind-sql-injection-tool/&amp;title=sqlmap+0.9+Released+%E2%80%93+Automatic+Blind+SQL+Injection+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F04%2Fsqlmap-0-9-released-automatic-blind-sql-injection-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/04/sqlmap-0-9-released-automatic-blind-sql-injection-tool/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>SQLInject-Finder &#8211; Intelligent SQL Injection Detection Script</title>
		<link>http://www.darknet.org.uk/2010/12/sqlinject-finder-intelligent-sql-injection-detection-script/</link>
		<comments>http://www.darknet.org.uk/2010/12/sqlinject-finder-intelligent-sql-injection-detection-script/#comments</comments>
		<pubDate>Tue, 14 Dec 2010 10:51:53 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Database Hacking]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[database-security]]></category>
		<category><![CDATA[locate sql injection]]></category>
		<category><![CDATA[sql injection detection]]></category>
		<category><![CDATA[sql injection vulnerability]]></category>
		<category><![CDATA[sql-injection]]></category>
		<category><![CDATA[sql-injection-tool]]></category>
		<category><![CDATA[sqlinject-finder]]></category>
		<category><![CDATA[web-application-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3007</guid>
		<description><![CDATA[SQLInject-Finder is a simple python script that parses through a pcap and looks at the GET and POST request data for suspicious and possible SQL injects. Rules to check for SQL injection can be easily added. Output can be printed neatly on the command line or in tab delimited format. The output includes: The suspicious [...]]]></description>
			<content:encoded><![CDATA[<p>SQLInject-Finder is a simple python script that parses through a pcap and looks at the GET and POST request data for suspicious and possible SQL injects. Rules to check for SQL injection can be easily added. Output can be printed neatly on the command line or in tab delimited format.</p>
<p>The output includes:</p>
<ul>
<li>The suspicious IP address</li>
<li>The attacked webpage</li>
<li>The parameter and value used</li>
<li>The frame number of the packet within the pcap (can be used to find exactly where the packet is in Wireshark)</li>
<li>The reason why the request was flagged </li>
</ul>
<p><strong>Requirements</strong></p>
<p>This script was tested using Python 2.6.5. Other versions are not guaranteed to work.</p>
<p>This script depends on the <a href="http://code.google.com/p/dpkt/downloads/list ">dpkt libraries</a>.</p>
<p>You can download SQLInject-Finder here:</p>
<p><a href="http://sqlinject-finder.googlecode.com/files/sqlinject-finder.py">sqlinject-finder.py</a></p>
<p>Or read more <a href="http://code.google.com/p/sqlinject-finder/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=SQLInject-Finder+%E2%80%93+Intelligent+SQL+Injection+Detection+Script+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3007+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/12/sqlinject-finder-intelligent-sql-injection-detection-script/&amp;t=SQLInject-Finder+%E2%80%93+Intelligent+SQL+Injection+Detection+Script" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/12/sqlinject-finder-intelligent-sql-injection-detection-script/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/12/sqlinject-finder-intelligent-sql-injection-detection-script/&amp;title=SQLInject-Finder+%E2%80%93+Intelligent+SQL+Injection+Detection+Script" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/12/sqlinject-finder-intelligent-sql-injection-detection-script/&amp;title=SQLInject-Finder+%E2%80%93+Intelligent+SQL+Injection+Detection+Script" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/12/sqlinject-finder-intelligent-sql-injection-detection-script/&amp;title=SQLInject-Finder+%E2%80%93+Intelligent+SQL+Injection+Detection+Script" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/12/sqlinject-finder-intelligent-sql-injection-detection-script/&amp;title=SQLInject-Finder+%E2%80%93+Intelligent+SQL+Injection+Detection+Script" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F12%2Fsqlinject-finder-intelligent-sql-injection-detection-script%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/12/sqlinject-finder-intelligent-sql-injection-detection-script/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Exploit Next Generation SQL Fingerprint (ESF) &#8211; MS-SQL Server Fingerprinting Tool</title>
		<link>http://www.darknet.org.uk/2010/10/exploit-next-generation-sql-fingerprint-esf-ms-sql-server-fingerprinting-tool/</link>
		<comments>http://www.darknet.org.uk/2010/10/exploit-next-generation-sql-fingerprint-esf-ms-sql-server-fingerprinting-tool/#comments</comments>
		<pubDate>Tue, 12 Oct 2010 07:41:06 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Database Hacking]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[database fingerprinting]]></category>
		<category><![CDATA[database fingerprinting tool]]></category>
		<category><![CDATA[database hacking tool]]></category>
		<category><![CDATA[esf]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[microsoft sql]]></category>
		<category><![CDATA[microsoft sql server]]></category>
		<category><![CDATA[ms-sql]]></category>
		<category><![CDATA[ms-sql server fingerprint]]></category>
		<category><![CDATA[ms-sql server fingerprinting]]></category>
		<category><![CDATA[sql server fingerprint]]></category>
		<category><![CDATA[sql server fingerprinting]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2968</guid>
		<description><![CDATA[SQL Server fingerprinting can be a time consuming process. It involves a lot many trial and error methods to fingerprint the exact SQL Server version. Intentionally inserting an invalid input to obtain a typical error message or using certain alphabets that are unique for a certain server are two of the ways to possibly fingerprint [...]]]></description>
			<content:encoded><![CDATA[<p>SQL Server fingerprinting can be a time consuming process. It involves a lot many trial and error methods to fingerprint the exact SQL Server version. Intentionally inserting an invalid input to obtain a typical error message or using certain alphabets that are unique for a certain server are two of the ways to possibly fingerprint a server.</p>
<p>We have featured some other <a href="http://www.darknet.org.uk/tag/database-fingerprinting/">database-fingerprinting</a> tools before such as <a href="http://www.darknet.org.uk/2009/07/sqlmap-0-7-released-automatic-sql-injection-tool/">SQLmap the automated SQL injection tool</a>, which also carries out fingerprinting and the <a href="http://www.darknet.org.uk/2010/01/microsoft-sql-server-fingerprint-tool-beta4/">Microsoft SQL Server Fingerprint Tool</a> aimed specifically at MS-SQL installs similar to ESF. </p>
<p>The Exploit Next Generation SQL Fingerprint (ESF) is a powerful tool which performs version fingerprinting for:</p>
<ul>
<li>Microsoft SQL Server 2000;</li>
<li>Microsoft SQL Server 2005; and</li>
<li>Microsoft SQL Server 2008.</li>
</ul>
<p>The Exploit Next Generation SQL Fingerprint uses well-known techniques based on several public tools that are capable to identify the Microsoft SQL Server version (such as: SQLping and SQLver), but, instead of showing only the &#8220;raw version&#8221; (i.e., Microsoft SQL Version 10.00.2746), the Exploit Next Generation SQL Fingerprint shows the mapped Microsoft SQL Server version (i.e., Microsoft SQL 2008 SP1 (CU5)).</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<p>The strengths of Exploit Next Generation SQL Fingerprint are:</p>
<ul>
<li>
It uses both TCP and UDP protocols to determine the Microsoft SQL Server version, making it much more reliable than any other public or commercial tool.</li>
<li>
It is capable to identify multiple Microsoft SQL Server instances and their TCP communication ports.</li>
<li>It does not require any authentication method to identify the Microsoft SQL Server version.</li>
<li>It uses probabilistic algorithm to identify the Microsoft SQL Server version, combining both TCP and UDP fingerprint.</li>
</ul>
<p>The Exploit Next Generation SQL Fingerprint can also be used to identify vulnerable/unpatched Microsoft SQL Server version, and it is based on some techniques used by Exploit Next Generation Compliance Methodology to perform automated penetration testing. </p>
<p>SQL Server fingerprinting is necessary before performing any kind of penetration testing on database server and if you find its Microsoft SQL Server then this tool will surely help identifying granular level findings to further exploit database. </p>
<p>You can download ESF v1.10 here:</p>
<p><a href="http://esf.googlecode.com/files/ESF.exe">ESF.exe</a></p>
<p>Or read more <a href="http://code.google.com/p/esf/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Exploit+Next+Generation+SQL+Fingerprint+%28ESF%29+%E2%80%93+MS-SQL+Server+Fingerprinting+Tool+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2968+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/10/exploit-next-generation-sql-fingerprint-esf-ms-sql-server-fingerprinting-tool/&amp;t=Exploit+Next+Generation+SQL+Fingerprint+%28ESF%29+%E2%80%93+MS-SQL+Server+Fingerprinting+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/10/exploit-next-generation-sql-fingerprint-esf-ms-sql-server-fingerprinting-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/10/exploit-next-generation-sql-fingerprint-esf-ms-sql-server-fingerprinting-tool/&amp;title=Exploit+Next+Generation+SQL+Fingerprint+%28ESF%29+%E2%80%93+MS-SQL+Server+Fingerprinting+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/10/exploit-next-generation-sql-fingerprint-esf-ms-sql-server-fingerprinting-tool/&amp;title=Exploit+Next+Generation+SQL+Fingerprint+%28ESF%29+%E2%80%93+MS-SQL+Server+Fingerprinting+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/10/exploit-next-generation-sql-fingerprint-esf-ms-sql-server-fingerprinting-tool/&amp;title=Exploit+Next+Generation+SQL+Fingerprint+%28ESF%29+%E2%80%93+MS-SQL+Server+Fingerprinting+Tool" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/10/exploit-next-generation-sql-fingerprint-esf-ms-sql-server-fingerprinting-tool/&amp;title=Exploit+Next+Generation+SQL+Fingerprint+%28ESF%29+%E2%80%93+MS-SQL+Server+Fingerprinting+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F10%2Fexploit-next-generation-sql-fingerprint-esf-ms-sql-server-fingerprinting-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/10/exploit-next-generation-sql-fingerprint-esf-ms-sql-server-fingerprinting-tool/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>sqlninja v0.2.5 Released &#8211; Microsoft SQL Server (MS-SQL) SQL Injection Vulnerability Tool</title>
		<link>http://www.darknet.org.uk/2010/05/sqlninja-v0-2-5-released-microsoft-sql-server-ms-sql-sql-injection-vulnerability-tool/</link>
		<comments>http://www.darknet.org.uk/2010/05/sqlninja-v0-2-5-released-microsoft-sql-server-ms-sql-sql-injection-vulnerability-tool/#comments</comments>
		<pubDate>Tue, 18 May 2010 05:22:03 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Database Hacking]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[attacking microsoft sql server]]></category>
		<category><![CDATA[attacking ms-sql]]></category>
		<category><![CDATA[automated sql injection]]></category>
		<category><![CDATA[bruteforce ms-sql]]></category>
		<category><![CDATA[bruteforce sa password]]></category>
		<category><![CDATA[fingerprinting sql]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[hacking-database]]></category>
		<category><![CDATA[hacking-ms-sql]]></category>
		<category><![CDATA[hacking-websites]]></category>
		<category><![CDATA[ids evasion]]></category>
		<category><![CDATA[microsoft sql server]]></category>
		<category><![CDATA[ms-sql]]></category>
		<category><![CDATA[ms-sql-security]]></category>
		<category><![CDATA[netcat]]></category>
		<category><![CDATA[sql-injection]]></category>
		<category><![CDATA[sqli]]></category>
		<category><![CDATA[sqlninja]]></category>
		<category><![CDATA[web-application-security]]></category>
		<category><![CDATA[web-application-testing]]></category>
		<category><![CDATA[xp_cmdshell]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2688</guid>
		<description><![CDATA[It&#8217;s been 2 years, but a new version of sqlninja is out at Sourceforge, we wrote about the previous release back in 2008 and we&#8217;ve actually been following this tool since 2006! Sqlninja is a tool to exploit SQL Injection vulnerabilities on a web application that uses Microsoft SQL Server as its back-end. Its main [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>It&#8217;s been 2 years, but a new version of sqlninja is out at Sourceforge, we wrote about the previous release <a href="http://www.darknet.org.uk/2008/05/sqlninja-023-released-advanced-automated-sql-injection-tool-for-ms-sql/">back in 2008</a> and we&#8217;ve actually been following this <a href="http://www.darknet.org.uk/2006/06/sqlninja-010alpha-ms-sql-injection-tool/">tool since 2006</a>! </p>
<p>Sqlninja is a tool to exploit SQL Injection vulnerabilities on a web application that uses Microsoft SQL Server as its back-end. Its main goal is to provide an interactive access on the vulnerable DB server, even in a very hostile environment. It should be used by penetration testers to help and automate the process of taking over a DB Server when a SQL Injection vulnerability has been discovered. </p>
<p><strong>Features</strong></p>
<ul>
<li>Fingerprint of the remote SQL Server (version, user performing the queries, user privileges, xp_cmdshell availability, DB authentication mode)</li>
<li>Bruteforce of &#8216;sa&#8217; password (in 2 flavors: dictionary-based and incremental)</li>
<li>Privilege escalation to sysadmin group if &#8216;sa&#8217; password has been found</li>
<li>Creation of a custom xp_cmdshell if the original one has been removed</li>
<li>Upload of netcat (or any other executable) using only normal HTTP requests (no FTP/TFTP needed)</li>
<li>TCP/UDP portscan from the target SQL Server to the attacking machine, in order to find a port that is allowed by the firewall of the target network and use it for a reverse shell</li>
<li>Direct and reverse bindshell, both TCP and UDP</li>
<li>DNS-tunneled pseudo-shell, when no TCP/UDP ports are available for a direct/reverse shell, but the DB server can resolve external hostnames</li>
<li>Evasion techniques to confuse a few IDS/IPS/WAF</li>
<li>Integration with <a href="http://www.darknet.org.uk/2009/11/metasploit-3-3-released-exploitation-framework/">Metasploit3</a>, to obtain a graphical access to the remote DB server through a VNC server injection</li>
</ul>
<p><strong>What&#8217;s New?</strong></p>
<ul>
<li>Proxy support (it was about time!)</li>
<li>No more 64k bytes limit in upload mode</li>
<li>Upload mode is also massively faster</li>
<li>Privilege escalation through token kidnapping (kudos to Cesar Cerrudo)</li>
<li>Other minor improvements</li>
</ul>
<p><strong>Compatibility</strong></p>
<p>It is written in Perl, it is released under the GPLv2 and so far has been successfully tested on:</p>
<ul>
<li>Linux</li>
<li>FreeBSD</li>
<li>Mac OS X</li>
</ul>
<p>You can download sqlninja v0.2.5 here:</p>
<p><a href="http://downloads.sourceforge.net/project/sqlninja/sqlninja/0.2.5/sqlninja-0.2.5.tgz?use_mirror=nchc">sqlninja-0.2.5.tgz</p>
<p></p>
<p></a>Or read more <a href="http://sqlninja.sourceforge.net">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=sqlninja+v0.2.5+Released+%E2%80%93+Microsoft+SQL+Server+%28MS-SQL%29+SQL+Injection+Vulnerability+Tool+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2688+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/05/sqlninja-v0-2-5-released-microsoft-sql-server-ms-sql-sql-injection-vulnerability-tool/&amp;t=sqlninja+v0.2.5+Released+%E2%80%93+Microsoft+SQL+Server+%28MS-SQL%29+SQL+Injection+Vulnerability+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/05/sqlninja-v0-2-5-released-microsoft-sql-server-ms-sql-sql-injection-vulnerability-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/05/sqlninja-v0-2-5-released-microsoft-sql-server-ms-sql-sql-injection-vulnerability-tool/&amp;title=sqlninja+v0.2.5+Released+%E2%80%93+Microsoft+SQL+Server+%28MS-SQL%29+SQL+Injection+Vulnerability+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/05/sqlninja-v0-2-5-released-microsoft-sql-server-ms-sql-sql-injection-vulnerability-tool/&amp;title=sqlninja+v0.2.5+Released+%E2%80%93+Microsoft+SQL+Server+%28MS-SQL%29+SQL+Injection+Vulnerability+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/05/sqlninja-v0-2-5-released-microsoft-sql-server-ms-sql-sql-injection-vulnerability-tool/&amp;title=sqlninja+v0.2.5+Released+%E2%80%93+Microsoft+SQL+Server+%28MS-SQL%29+SQL+Injection+Vulnerability+Tool" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/05/sqlninja-v0-2-5-released-microsoft-sql-server-ms-sql-sql-injection-vulnerability-tool/&amp;title=sqlninja+v0.2.5+Released+%E2%80%93+Microsoft+SQL+Server+%28MS-SQL%29+SQL+Injection+Vulnerability+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F05%2Fsqlninja-v0-2-5-released-microsoft-sql-server-ms-sql-sql-injection-vulnerability-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/05/sqlninja-v0-2-5-released-microsoft-sql-server-ms-sql-sql-injection-vulnerability-tool/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>sqlmap 0.7 Released &#8211; Automatic SQL Injection Tool</title>
		<link>http://www.darknet.org.uk/2009/07/sqlmap-0-7-released-automatic-sql-injection-tool/</link>
		<comments>http://www.darknet.org.uk/2009/07/sqlmap-0-7-released-automatic-sql-injection-tool/#comments</comments>
		<pubDate>Fri, 31 Jul 2009 10:42:55 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Database Hacking]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[automatic sql injection]]></category>
		<category><![CDATA[database-security]]></category>
		<category><![CDATA[sql-injection]]></category>
		<category><![CDATA[sql-injection-tool]]></category>
		<category><![CDATA[sqlmap]]></category>
		<category><![CDATA[web-application-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1958</guid>
		<description><![CDATA[We&#8217;ve been following sqlmap since it first came out in Feburary 2007 and it&#8217;s been quite some time since the last update sqlmap 0.6.3 in December 2008. For those not familiar with the tool, sqlmap is an open source command-line automatic SQL injection tool. Its goal is to detect and take advantage of SQL injection [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>We&#8217;ve been following sqlmap since it <a href="http://www.darknet.org.uk/2007/02/sqlmap-automated-blind-sql-injection-tool/">first came out in Feburary 2007</a> and it&#8217;s been quite some time since the last update <a href="http://www.darknet.org.uk/2008/12/sqlmap-063-released-automatic-sql-injection-tool/">sqlmap 0.6.3 in December 2008</a>. </p>
<p>For those not familiar with the tool, sqlmap is an open source command-line automatic SQL injection tool. Its goal is to detect and take advantage of SQL injection vulnerabilities in web applications.</p>
<p>Once it detects one or more SQL injections on the target host, the user can choose among a variety of options to perform an extensive back-end database management system fingerprint, retrieve DBMS session user and database, enumerate users, password hashes, privileges, databases, dump entire or user&#8217;s specified DBMS tables/columns, run his own SQL statement, read or write either text or binary files on the file system, execute arbitrary commands on the operating system, establish an out-of-band stateful connection between the attacker box and the database server via Metasploit payload stager, database stored procedure buffer overflow exploitation or SMB relay attack and more.</p>
<p><strong>Recent Changes</strong></p>
<p>Along all the takeover features introduced in sqlmap 0.7 release candidate 1, some of the new features include:</p>
<ul>
<li>Adapted Metasploit wrapping functions to work with latest 3.3 development version too.</li>
<li>Adjusted code to make sqlmap 0.7 to work again on Mac OSX too.</li>
<li>Reset takeover OOB features (if any of &#8211;os-pwn, &#8211;os-smbrelay or &#8211;os-bof is selected) when running under Windows because msfconsole and msfcli are not supported on the native Windows Ruby interpreter.</li>
<li>This make sqlmap 0.7 to work again on Windows too.</li>
<li>Minor improvement so that sqlmap tests also all parameters with no value (eg. par=).</li>
<li>HTTPS requests over HTTP proxy now work on either Python 2.4, 2.5 and 2.6+.</li>
</ul>
<p>For a complete list of changes view the <a href="http://sqlmap.sourceforge.net/doc/ChangeLog">ChangeLog</a>.</p>
<p>The manual is available here &#8211; <a href="http://sqlmap.sourceforge.net/doc/README.pdf">README.pdf</a> [PDF]</p>
<p>You can download sqlmap 0.7 here:</p>
<p>Linux Source: <a href="http://downloads.sourceforge.net/sqlmap/sqlmap-0.7.tar.gz">sqlmap-0.7.tar.gz</a><br />
Windows Portable: <a href="http://downloads.sourceforge.net/sqlmap/sqlmap-0.7_exe.zip">sqlmap-0.7_exe.zip</a></p>
<p></p>
<p>Or read more <a href="http://sqlmap.sourceforge.net/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=sqlmap+0.7+Released+%E2%80%93+Automatic+SQL+Injection+Tool+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1958+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/07/sqlmap-0-7-released-automatic-sql-injection-tool/&amp;t=sqlmap+0.7+Released+%E2%80%93+Automatic+SQL+Injection+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/07/sqlmap-0-7-released-automatic-sql-injection-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/07/sqlmap-0-7-released-automatic-sql-injection-tool/&amp;title=sqlmap+0.7+Released+%E2%80%93+Automatic+SQL+Injection+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/07/sqlmap-0-7-released-automatic-sql-injection-tool/&amp;title=sqlmap+0.7+Released+%E2%80%93+Automatic+SQL+Injection+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/07/sqlmap-0-7-released-automatic-sql-injection-tool/&amp;title=sqlmap+0.7+Released+%E2%80%93+Automatic+SQL+Injection+Tool" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/07/sqlmap-0-7-released-automatic-sql-injection-tool/&amp;title=sqlmap+0.7+Released+%E2%80%93+Automatic+SQL+Injection+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F07%2Fsqlmap-0-7-released-automatic-sql-injection-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/07/sqlmap-0-7-released-automatic-sql-injection-tool/feed/</wfw:commentRss>
		<slash:comments>13</slash:comments>
		</item>
		<item>
		<title>sqlsus 0.2 Released &#8211; MySQL Injection &amp; Takeover Tool</title>
		<link>http://www.darknet.org.uk/2009/03/sqlsus-02-released-mysql-injection-takeover-tool/</link>
		<comments>http://www.darknet.org.uk/2009/03/sqlsus-02-released-mysql-injection-takeover-tool/#comments</comments>
		<pubDate>Mon, 23 Mar 2009 05:06:53 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Database Hacking]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[hacking mysql]]></category>
		<category><![CDATA[mysql hacking]]></category>
		<category><![CDATA[mysql injection tool]]></category>
		<category><![CDATA[mysql takeover tool]]></category>
		<category><![CDATA[perl]]></category>
		<category><![CDATA[sql-injection]]></category>
		<category><![CDATA[sql-injection-tool]]></category>
		<category><![CDATA[sqlsus]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1566</guid>
		<description><![CDATA[sqlsus is an open source MySQL injection and takeover tool, written in perl. Via a command line interface that mimics a mysql console, you can retrieve the database structure, inject a SQL query, download files from the web server, upload and control a backdoor, and much more&#8230; It is designed to maximize the amount of [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>sqlsus is an open source MySQL injection and takeover tool, written in perl.</p>
<p>Via a command line interface that mimics a mysql console, you can retrieve the database structure, inject a SQL query, download files from the web server, upload and control a backdoor, and much more&#8230;</p>
<p>It is designed to maximize the amount of data gathered per web server hit, making the best use of MySQL functions to optimize the available injection space.</p>
<p>sqlsus is focused on PHP/MySQL installations, and integrates some neat features, some of them being really specific to this DBMS.</p>
<p>It is not and won&#8217;t ever be a SQL injection scanner, it starts its job on the next step.</p>
<p>Both quoted and numeric injections are supported.</p>
<p>All quoted texts can be translated as their hex equivalent (eg : &#8220;sqlsus&#8221; will become 0x73716c737573)</p>
<p>sqlsus also supports these 2 scenarios of injection :</p>
<ul>
<li>sighted : the result of the request will be in the HTML returned by the web server</li>
<li>blind : when you can&#8217;t see the result of the request directly</li>
</ul>
<p>Support for GET and POST parameters injections.</p>
<p>Support for HTTP proxy and HTTP simple authentication.</p>
<p>Full logging support of your queries and the answers, allowing you to recall a command and its cached answer, even in a later re-use of the session.</p>
<p>Key variables can be edited on the fly, saved per session, and can be loaded in a later session on the same target server.</p>
<p><strong>Requirements</strong></p>
<p>On a Debian system, in addition to perl, you will need the following packages :</p>
<ul>
<li>libterm-readline-perl-perl</li>
<li>libipc-shareable-perl</li>
<li>libwww-mechanize-perl</li>
</ul>
<p>It also requires previous SQL injection knowledge, and.. well.. a brain helps.</p>
<p>You can download sqlsus 0.2 here:</p>
<p><a href="http://downloads.sourceforge.net/sqlsus/sqlsus-0.2.tgz">sqlsus-0.2.tgz</a></p>
<p></p>
<p>Or read more <a href="http://sqlsus.sourceforge.net/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=sqlsus+0.2+Released+%E2%80%93+MySQL+Injection+%26+Takeover+Tool+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1566+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/03/sqlsus-02-released-mysql-injection-takeover-tool/&amp;t=sqlsus+0.2+Released+%E2%80%93+MySQL+Injection+%26+Takeover+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/03/sqlsus-02-released-mysql-injection-takeover-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/03/sqlsus-02-released-mysql-injection-takeover-tool/&amp;title=sqlsus+0.2+Released+%E2%80%93+MySQL+Injection+%26+Takeover+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/03/sqlsus-02-released-mysql-injection-takeover-tool/&amp;title=sqlsus+0.2+Released+%E2%80%93+MySQL+Injection+%26+Takeover+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/03/sqlsus-02-released-mysql-injection-takeover-tool/&amp;title=sqlsus+0.2+Released+%E2%80%93+MySQL+Injection+%26+Takeover+Tool" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/03/sqlsus-02-released-mysql-injection-takeover-tool/&amp;title=sqlsus+0.2+Released+%E2%80%93+MySQL+Injection+%26+Takeover+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F03%2Fsqlsus-02-released-mysql-injection-takeover-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/03/sqlsus-02-released-mysql-injection-takeover-tool/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>sqlmap 0.6.3 Released &#8211; Automatic SQL Injection Tool</title>
		<link>http://www.darknet.org.uk/2008/12/sqlmap-063-released-automatic-sql-injection-tool/</link>
		<comments>http://www.darknet.org.uk/2008/12/sqlmap-063-released-automatic-sql-injection-tool/#comments</comments>
		<pubDate>Thu, 18 Dec 2008 12:02:17 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Database Hacking]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[automatic sql injection]]></category>
		<category><![CDATA[database-security]]></category>
		<category><![CDATA[sql-injection]]></category>
		<category><![CDATA[sql-injection-tool]]></category>
		<category><![CDATA[sqlmap]]></category>
		<category><![CDATA[web-application-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1324</guid>
		<description><![CDATA[sqlmap is an automatic SQL injection tool developed in Python. Its goal is to detect and take advantage of SQL injection vulnerabilities on web applications. Once it detects one or more SQL injections on the target host, the user can choose among a variety of options to perform an extensive back end database management system [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>sqlmap is an automatic SQL injection tool developed in Python. Its goal is to detect and take advantage of SQL injection vulnerabilities on web applications. Once it detects one or more SQL injections on the target host, the user can choose among a variety of options to perform an extensive back end database management system fingerprint, retrieve DBMS session user and database, enumerate users, password hashes, privileges, databases, dump entire or user&#8217;s specific DBMS  tables/columns, run his own SQL SELECT statement, read specific files on the file system and much more..</p>
<p><strong>Changes</strong></p>
<p>Some of the new features include:</p>
<ul>
<li>
Major enhancement to get list of targets to test from Burp proxy requests log file path or WebScarab proxy &#8216;conversations/&#8217; folder path with option -l;</li>
<li>Major enhancement to support Partial UNION query SQL injection technique;</li>
<li>Major enhancement to test if the web application technology sup ports stacked queries (multiple statements) by providing option &#8211;stacked-test which will be then used someday also by takeover functionality;</li>
<li>Major enhancement to test if the injectable parameter is affected by a time based blind SQL injection technique by providing option &#8211;time-test;</li>
<li>Major bug fix to correctly enumerate columns on Microsoft SQL Server;</li>
<li>Major bug fix so that when the user provide a SELECT statement to be processed with an asterisk as columns, now it also work if in the FROM<br />
there is no database name specified;</li>
</ul>
<p><a href="http://sqlmap.sourceforge.net/doc/ChangeLog">Complete ChangeLog</a></p>
<p>You can download sqlmap 0.6.3 here:</p>
<p><a href="http://downloads.sourceforge.net/sqlmap/sqlmap-0.6.3.tar.gz">sqlmap-0.6.3.tar.gz</a> (Linux)<br />
<a href="http://downloads.sourceforge.net/sqlmap/sqlmap-0.6.3_exe.zip">sqlmap-0.6.3_exe.zip</a> (Windows)</p>
<p></p>
<p>Or read more <a href="http://sqlmap.sourceforge.net/">here</a> (<a href="http://sqlmap.sourceforge.net/doc/README.pdf">User Manual</a>).</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=sqlmap+0.6.3+Released+%E2%80%93+Automatic+SQL+Injection+Tool+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1324+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2008/12/sqlmap-063-released-automatic-sql-injection-tool/&amp;t=sqlmap+0.6.3+Released+%E2%80%93+Automatic+SQL+Injection+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2008/12/sqlmap-063-released-automatic-sql-injection-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2008/12/sqlmap-063-released-automatic-sql-injection-tool/&amp;title=sqlmap+0.6.3+Released+%E2%80%93+Automatic+SQL+Injection+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2008/12/sqlmap-063-released-automatic-sql-injection-tool/&amp;title=sqlmap+0.6.3+Released+%E2%80%93+Automatic+SQL+Injection+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2008/12/sqlmap-063-released-automatic-sql-injection-tool/&amp;title=sqlmap+0.6.3+Released+%E2%80%93+Automatic+SQL+Injection+Tool" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2008/12/sqlmap-063-released-automatic-sql-injection-tool/&amp;title=sqlmap+0.6.3+Released+%E2%80%93+Automatic+SQL+Injection+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2008%2F12%2Fsqlmap-063-released-automatic-sql-injection-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2008/12/sqlmap-063-released-automatic-sql-injection-tool/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>sqlmap 0.6.1 released &#8211; Automatic SQL Injection Tool</title>
		<link>http://www.darknet.org.uk/2008/10/sqlmap-061-released-automatic-sql-injection-tool/</link>
		<comments>http://www.darknet.org.uk/2008/10/sqlmap-061-released-automatic-sql-injection-tool/#comments</comments>
		<pubDate>Tue, 28 Oct 2008 08:01:32 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Database Hacking]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[automatic sql injection]]></category>
		<category><![CDATA[database-security]]></category>
		<category><![CDATA[sql-injection]]></category>
		<category><![CDATA[sql-injection-tool]]></category>
		<category><![CDATA[sqlmap]]></category>
		<category><![CDATA[web-application-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1162</guid>
		<description><![CDATA[sqlmap is an automatic SQL injection tool developed in Python. Its goal is to detect and take advantage of SQL injection vulnerabilities on web applications. Once it detects one or more SQL injections on the target host, the user can choose among a variety of options to perform an extensive back-end database management system fingerprint, [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>sqlmap is an automatic SQL injection tool developed in Python. Its goal is to detect and take advantage of SQL injection vulnerabilities on web applications. Once it detects one or more SQL injections on the target host, the user can choose among a variety of options to perform an extensive back-end database management system fingerprint, retrieve DBMS session user and database, enumerate users, password hashes, privileges, databases, dump entire or user&#8217;s specific DBMS tables/columns, run his own SQL SELECT statement, read specific files on the file system and much more.</p>
<p><strong>Features</strong></p>
<ul>
<li>Full support for MySQL, Oracle, PostgreSQL and Microsoft SQL Server back-end database management systems. Besides these four database management systems, sqlmap can also identify Microsoft Access, DB2, Informix, Sybase and Interbase.</li>
<li>Extensive back-end database management system fingerprint based upon inband error messages, banner parsing, functions output comparison and specific features such as MySQL comment injection. It is also possible to force the back-end database management system name if you already know it.</li>
<li>Full support for two SQL injection techniques: blind SQL injection and inband SQL injection.</li>
</ul>
<p><strong>Changes</strong></p>
<p>Some of the new features include:</p>
<ul>
<li>Added a Metasploit Framework 3 auxiliary module to run sqlmap;</li>
<li>Implemented possibility to test for and inject also on LIKE statements;</li>
<li>Implemented &#8211;start and &#8211;stop options to set the first and the last table entry to dump;</li>
<li>Added non-interactive/batch-mode (&#8211;batch) option to make it easy to wrap sqlmap in Metasploit and any other tool.</li>
</ul>
<p>Complete list of changes at <a href="http://sqlmap.sourceforge.net/doc/ChangeLog">ChangeLog</a>.</p>
<p>You can also grab the <a href="http://sqlmap.sourceforge.net/doc/README.pdf">User Manual</a> here.</p>
<p>You can download sqlmap 0.6.1 here:</p>
<p>Source &#8211; <a href="http://downloads.sourceforge.net/sqlmap/sqlmap-0.6.1.tar.gz">sqlmap-0.6.1.tar.gz</a></p>
<p>Windows &#8211; <a href="http://downloads.sourceforge.net/sqlmap/sqlmap-0.6.1_exe.zip">sqlmap-0.6.1_exe.zip</a></p>
<p></p>
<p>Or read more <a href="http://sqlmap.sourceforge.net/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=sqlmap+0.6.1+released+%E2%80%93+Automatic+SQL+Injection+Tool+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1162+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2008/10/sqlmap-061-released-automatic-sql-injection-tool/&amp;t=sqlmap+0.6.1+released+%E2%80%93+Automatic+SQL+Injection+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2008/10/sqlmap-061-released-automatic-sql-injection-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2008/10/sqlmap-061-released-automatic-sql-injection-tool/&amp;title=sqlmap+0.6.1+released+%E2%80%93+Automatic+SQL+Injection+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2008/10/sqlmap-061-released-automatic-sql-injection-tool/&amp;title=sqlmap+0.6.1+released+%E2%80%93+Automatic+SQL+Injection+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2008/10/sqlmap-061-released-automatic-sql-injection-tool/&amp;title=sqlmap+0.6.1+released+%E2%80%93+Automatic+SQL+Injection+Tool" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2008/10/sqlmap-061-released-automatic-sql-injection-tool/&amp;title=sqlmap+0.6.1+released+%E2%80%93+Automatic+SQL+Injection+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2008%2F10%2Fsqlmap-061-released-automatic-sql-injection-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2008/10/sqlmap-061-released-automatic-sql-injection-tool/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

