<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; defacement tool</title>
	<atom:link href="http://www.darknet.org.uk/tag/defacement-tool/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>MultiInjector v0.3 Released &#8211; Automatic SQL Injection and Defacement Tool</title>
		<link>http://www.darknet.org.uk/2008/12/multiinjector-v03-released-automatic-sql-injection-and-defacement-tool/</link>
		<comments>http://www.darknet.org.uk/2008/12/multiinjector-v03-released-automatic-sql-injection-and-defacement-tool/#comments</comments>
		<pubDate>Mon, 22 Dec 2008 09:40:14 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Database Hacking]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[defacement]]></category>
		<category><![CDATA[defacement tool]]></category>
		<category><![CDATA[defacing websites]]></category>
		<category><![CDATA[hacking-web-sites]]></category>
		<category><![CDATA[multiinjector]]></category>
		<category><![CDATA[sql-injection]]></category>
		<category><![CDATA[sql-injection-tool]]></category>
		<category><![CDATA[stealth sql injection]]></category>
		<category><![CDATA[stealth sql injection tool]]></category>
		<category><![CDATA[web site security]]></category>
		<category><![CDATA[web-application-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1333</guid>
		<description><![CDATA[You might remember a while ago we posted about MultiInjector which claims to the first configurable automatic website defacement tool, it got quite a bit of interest and shortly after that it was updated. Anyway, good or bad I think people deserve to know what is out there. Features Receives a list of URLs as [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>You might remember a while ago we posted about <a href="http://www.darknet.org.uk/2008/11/multiinjector-automated-stealth-sql-injection-tool/">MultiInjector which claims to the first configurable automatic website defacement tool</a>, it got quite a bit of interest and shortly after that it was updated. Anyway, good or bad I think people deserve to know what is out there.</p>
<p><strong>Features</strong></p>
<ul>
<li>
Receives a list of URLs as input</li>
<li>Recognizes the parameterized URLs from the list</li>
<li>Fuzzes all URL parameters to concatenate the desired payload once an injection is successful</li>
<li>Automatic defacement &#8211; you decide on the defacement content, be it a hidden script, or just pure old &#8220;cyber graffiti&#8221; fun</li>
<li>
OS command execution &#8211; remote enabling of XP_CMDSHELL on SQL server, subsequently running any arbitrary operating system command lines entered by the user</li>
<li>Configurable parallel connections exponentially speed up the attack process &#8211; one payload, multiple targets, simultaneous attacks</li>
<li>Optional use of an HTTP proxy to mask the origin of the attacks</li>
</ul>
<p><strong>Changes</strong></p>
<ul>
<li>Automatic defacement &#8211; Try to concatenate a string to all user-defined text fields in DB</li>
<li>Run any OS command as if you&#8217;re running a command console on the DB machine</li>
<li>
Execute SQL commands of your choice</li>
<li>Enable OS shell procedure on DB &#8211; Revive the good old XP_CMDSHELL where it was turned off</li>
<li>Add administrative user to DB server with password: T0pSeKret</li>
<li>Enable remote desktop on DB server</li>
<li>Fixed nvarchar cast to varchar. Verified against MS-SQL 2000</li>
<li>Added numeric / string parameter type detection</li>
<li>Improved defacement content handling by escaping quotation marks</li>
<li>
Improved support for Linux systems</li>
<li>Fixed the &#8220;invalid number of concurrent connections&#8221; failure due to non-parameterized URLs</li>
</ul>
<p>You can download MultiInjector v0.3 here</p>
<p><a href="http://www.sn3akers.com/downloads/MultiInjectorV0.3.tar.gz">MultiInjectorV0.3.tar.gz</a></p>
<p></p>
<p>Or read more <a href="http://chaptersinwebsecurity.blogspot.com/2008/11/multiinjector-v03-released.html">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=MultiInjector+v0.3+Released+%E2%80%93+Automatic+SQL+Injection+and+Defacement+Tool+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1333+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2008/12/multiinjector-v03-released-automatic-sql-injection-and-defacement-tool/&amp;t=MultiInjector+v0.3+Released+%E2%80%93+Automatic+SQL+Injection+and+Defacement+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2008/12/multiinjector-v03-released-automatic-sql-injection-and-defacement-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2008/12/multiinjector-v03-released-automatic-sql-injection-and-defacement-tool/&amp;title=MultiInjector+v0.3+Released+%E2%80%93+Automatic+SQL+Injection+and+Defacement+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2008/12/multiinjector-v03-released-automatic-sql-injection-and-defacement-tool/&amp;title=MultiInjector+v0.3+Released+%E2%80%93+Automatic+SQL+Injection+and+Defacement+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2008/12/multiinjector-v03-released-automatic-sql-injection-and-defacement-tool/&amp;title=MultiInjector+v0.3+Released+%E2%80%93+Automatic+SQL+Injection+and+Defacement+Tool" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2008/12/multiinjector-v03-released-automatic-sql-injection-and-defacement-tool/&amp;title=MultiInjector+v0.3+Released+%E2%80%93+Automatic+SQL+Injection+and+Defacement+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2008%2F12%2Fmultiinjector-v03-released-automatic-sql-injection-and-defacement-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2008/12/multiinjector-v03-released-automatic-sql-injection-and-defacement-tool/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

