<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; mysql security</title>
	<atom:link href="http://www.darknet.org.uk/tag/mysql-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>MySQLPasswordAuditor &#8211; Free MySQL Audit/Password Recovery &amp; Cracking Tool</title>
		<link>http://www.darknet.org.uk/2011/12/mysqlpasswordauditor-free-mysql-auditpassword-recovery-cracking-tool/</link>
		<comments>http://www.darknet.org.uk/2011/12/mysqlpasswordauditor-free-mysql-auditpassword-recovery-cracking-tool/#comments</comments>
		<pubDate>Mon, 19 Dec 2011 19:12:34 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Database Hacking]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Password Cracking]]></category>
		<category><![CDATA[database-security]]></category>
		<category><![CDATA[hacking mysql]]></category>
		<category><![CDATA[mysql]]></category>
		<category><![CDATA[mysql password auditing]]></category>
		<category><![CDATA[mysql password cracking]]></category>
		<category><![CDATA[mysql password recovery]]></category>
		<category><![CDATA[mysql security]]></category>
		<category><![CDATA[mysqlpasswordauditor]]></category>
		<category><![CDATA[password-recovery]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3119</guid>
		<description><![CDATA[MysqlPasswordAuditor is the FREE Mysql password recovery and auditing software. Mysql is one of the popular and powerful database software used by most of the web based and server side applications. If you have ever lost or forgotten your Mysql database password then MysqlPasswordAuditor can help in recovering it easily. It can also help you [...]]]></description>
			<content:encoded><![CDATA[<p>MysqlPasswordAuditor is the FREE Mysql password recovery and auditing software. Mysql is one of the popular and powerful database software used by most of the web based and server side applications.</p>
<p>If you have ever lost or forgotten your Mysql database password then MysqlPasswordAuditor can help in recovering it easily. It can also help you to audit Mysql database server setup in an corporate environment by discovering the weak password configurations. This makes it one of the must have tool for IT administrators &#038; Penetration Testers.</p>
<p>MysqlPasswordAuditor is very easy to use with the simple dictionary based password recovery method. By default it includes small password list file, however you can find more password dictionary files at OpenWall collection. You can also use tools like Crunch, Cupp to generate custom password list files on your own and then use it with MysqlPasswordAuditor.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<p>MysqlPasswordAuditor works on wide range of platforms starting from Windows XP to latest operating system Windows 7.</p>
<p><strong>Features</strong></p>
<ul>
<li>Free and Simple software to Recover/Audit Mysql Password.</li>
<li>Very useful for IT administrators &#038; Penetration Testers</li>
<li>Dictionary based Password Recovery method</li>
<li>Detailed statistics such as  tested passwords, elapsed time, progress bar is displayed during Audit operation.</li>
<li>Simple, easy to use GUI interface</li>
<li>Integrated Installer for local Installation &#038; Uninstallation. </li>
</ul>
<p>You can download MysqlPasswordAuditor here:</p>
<p><a href="http://securityxploded.net/getfile.php?file=MysqlPasswordAuditor.zip">MysqlPasswordAuditor.zip</a></p>
<p>Or read more <a href="http://securityxploded.com/mysql-password-auditor.php">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=MySQLPasswordAuditor+%E2%80%93+Free+MySQL+Audit%2FPassword+Recovery+%26+Cracking+Tool+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3119+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/12/mysqlpasswordauditor-free-mysql-auditpassword-recovery-cracking-tool/&amp;t=MySQLPasswordAuditor+%E2%80%93+Free+MySQL+Audit%2FPassword+Recovery+%26+Cracking+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/12/mysqlpasswordauditor-free-mysql-auditpassword-recovery-cracking-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/12/mysqlpasswordauditor-free-mysql-auditpassword-recovery-cracking-tool/&amp;title=MySQLPasswordAuditor+%E2%80%93+Free+MySQL+Audit%2FPassword+Recovery+%26+Cracking+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/12/mysqlpasswordauditor-free-mysql-auditpassword-recovery-cracking-tool/&amp;title=MySQLPasswordAuditor+%E2%80%93+Free+MySQL+Audit%2FPassword+Recovery+%26+Cracking+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/12/mysqlpasswordauditor-free-mysql-auditpassword-recovery-cracking-tool/&amp;title=MySQLPasswordAuditor+%E2%80%93+Free+MySQL+Audit%2FPassword+Recovery+%26+Cracking+Tool" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/12/mysqlpasswordauditor-free-mysql-auditpassword-recovery-cracking-tool/&amp;title=MySQLPasswordAuditor+%E2%80%93+Free+MySQL+Audit%2FPassword+Recovery+%26+Cracking+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F12%2Fmysqlpasswordauditor-free-mysql-auditpassword-recovery-cracking-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/12/mysqlpasswordauditor-free-mysql-auditpassword-recovery-cracking-tool/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>sqlsus 0.7.1 Released &#8211; MySQL Injection &amp; Takeover Tool</title>
		<link>http://www.darknet.org.uk/2011/11/sqlsus-0-7-1-released-mysql-injection-takeover-tool/</link>
		<comments>http://www.darknet.org.uk/2011/11/sqlsus-0-7-1-released-mysql-injection-takeover-tool/#comments</comments>
		<pubDate>Mon, 21 Nov 2011 14:15:08 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Database Hacking]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[database-security]]></category>
		<category><![CDATA[hacking mysql]]></category>
		<category><![CDATA[hacking toold]]></category>
		<category><![CDATA[mysql]]></category>
		<category><![CDATA[mysql hacking tool]]></category>
		<category><![CDATA[mysql injection]]></category>
		<category><![CDATA[mysql injection tool]]></category>
		<category><![CDATA[mysql security]]></category>
		<category><![CDATA[mysql takeover]]></category>
		<category><![CDATA[sql-injection]]></category>
		<category><![CDATA[sql-injection-tool]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1680</guid>
		<description><![CDATA[sqlsus is an open source MySQL injection and takeover tool, written in perl. Via a command line interface, you can retrieve the database(s) structure, inject your own SQL queries (even complex ones), download files from the web server, crawl the website for writable directories, upload and control a backdoor, clone the database(s), and much more&#8230;Whenever [...]]]></description>
			<content:encoded><![CDATA[<p>sqlsus is an open source MySQL injection and takeover tool, written in perl. Via a command line interface, you can retrieve the database(s) structure, inject your own SQL queries (even complex ones), download files from the web server, crawl the website for writable directories, upload and control a backdoor, clone the database(s), and much more&#8230;Whenever relevant, sqlsus will mimic a MySQL console output.</p>
<p>sqlsus focuses on speed and efficiency, optimising the available injection space, making the best use (I can think of) of MySQL functions. It uses stacked subqueries and an powerful blind injection algorithm to maximise the data gathered per web server hit. Using multithreading on top of that, sqlsus is an extremely fast database dumper, be it for inband or blind injection.If the privileges are high enough, sqlsus will be a great help for uploading a backdoor through the injection point, and takeover the web server.</p>
<p>It uses SQLite as a backend, for an easier use of what has been dumped, and integrates a lot of usual features (see below) such as cookie support, socks/http proxying, https..</p>
<p><strong>What&#8217;s New</strong></p>
<p>Starting with version 0.7, sqlsus now supports time-based blind injection and automatically detects web server / suhosin / etc.. length restrictions.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<ul>
<li>Added time-based blind injection support (added option &#8220;blind_sleep&#8221;, and renamed &#8220;string_to_match&#8221; to &#8220;blind_string&#8221;).</li>
<li>It is now possible to force sqlsus to exit when it&#8217;s hanging (i.e.: retrieving data), by hitting Ctrl-C more than twice.</li>
<li>Rewrite of &#8220;autoconf max_sendable&#8221;, so that sqlsus will properly detect which length restriction applies (WEB server / layer above). (removed option &#8220;max_sendable&#8221;, added options &#8220;max_url_length&#8221; and &#8220;max_inj_length&#8221;)</li>
<li>Uploading a file now sends it into chunks under the length restriction.</li>
<li>sqlsus now saves variables after each command, so that forcing it to quit (or killing it) will not discard the changes that were made.</li>
<li>Added a progress bar to inband mode, sqlsus now determines the number of rows to be returned prior to fetching them.</li>
<li>get db (tables/columns) in inband mode now uses multithreading (like everything else).</li>
<li>clone now uses count(*) if available (set by &#8220;get count&#8221; / &#8220;get db&#8221;), instead of using fetch-ahead.</li>
<li>In blind mode, &#8220;start&#8221; will now test if things work the way they should, by injecting 2 queries : one true and one false.</li>
<li>sqlsus now prints what configuration options are overridden (when a saved value differs from the configuration file).</li>
</ul>
<p>You can download sqlsus 0.7.1 here:</p>
<p><a href="http://sourceforge.net/projects/sqlsus/files/sqlsus/sqlsus-0.7.1.tgz/download">sqlsus-0.7.1.tgz</a></p>
<p>Or read more <a href="http://sqlsus.sourceforge.net/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=sqlsus+0.7.1+Released+%E2%80%93+MySQL+Injection+%26+Takeover+Tool+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1680+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/11/sqlsus-0-7-1-released-mysql-injection-takeover-tool/&amp;t=sqlsus+0.7.1+Released+%E2%80%93+MySQL+Injection+%26+Takeover+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/11/sqlsus-0-7-1-released-mysql-injection-takeover-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/11/sqlsus-0-7-1-released-mysql-injection-takeover-tool/&amp;title=sqlsus+0.7.1+Released+%E2%80%93+MySQL+Injection+%26+Takeover+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/11/sqlsus-0-7-1-released-mysql-injection-takeover-tool/&amp;title=sqlsus+0.7.1+Released+%E2%80%93+MySQL+Injection+%26+Takeover+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/11/sqlsus-0-7-1-released-mysql-injection-takeover-tool/&amp;title=sqlsus+0.7.1+Released+%E2%80%93+MySQL+Injection+%26+Takeover+Tool" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/11/sqlsus-0-7-1-released-mysql-injection-takeover-tool/&amp;title=sqlsus+0.7.1+Released+%E2%80%93+MySQL+Injection+%26+Takeover+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F11%2Fsqlsus-0-7-1-released-mysql-injection-takeover-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/11/sqlsus-0-7-1-released-mysql-injection-takeover-tool/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>GreenSQL &#8211; Open Source Database Firewall Software</title>
		<link>http://www.darknet.org.uk/2010/02/greensql-open-source-database-firewall-software/</link>
		<comments>http://www.darknet.org.uk/2010/02/greensql-open-source-database-firewall-software/#comments</comments>
		<pubDate>Wed, 10 Feb 2010 10:11:28 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[Database Hacking]]></category>
		<category><![CDATA[Security Software]]></category>
		<category><![CDATA[data integrity]]></category>
		<category><![CDATA[data-security]]></category>
		<category><![CDATA[database firewall]]></category>
		<category><![CDATA[database-security]]></category>
		<category><![CDATA[green sql]]></category>
		<category><![CDATA[greensql]]></category>
		<category><![CDATA[guardium]]></category>
		<category><![CDATA[hacking-databases]]></category>
		<category><![CDATA[imperva]]></category>
		<category><![CDATA[mysql firewall]]></category>
		<category><![CDATA[mysql security]]></category>
		<category><![CDATA[postgresql firewall]]></category>
		<category><![CDATA[postgresql security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2516</guid>
		<description><![CDATA[GreenSQL is an Open Source database firewall used to protect databases from SQL injection attacks. GreenSQL works as a proxy for SQL commands and has built in support for MySQL &#038; PostgreSQL . The logic is based on evaluation of SQL commands using a risk scoring matrix as well as blocking known db administrative commands [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>GreenSQL is an Open Source database firewall used to protect databases from SQL injection attacks. GreenSQL works as a proxy for SQL commands and has built in support for MySQL &#038; PostgreSQL . The logic is based on evaluation of SQL commands using a risk scoring matrix as well as blocking known db administrative commands (DROP, CREATE, etc). GreenSQL is distributed under the GPL license.</p>
<p><strong>GreenSQL Architecture</strong></p>
<p>GreenSQL works as a reverse proxy for MySQL connections. This means, that instead of connecting TO THE MySQL server, your applications will connect to THE GreenSQL server. GreenSQL will analyze SQL queries and then, if they&#8217;re safe, will forward them to the back-end MySQL server.</p>
<p><strong>New Changes</strong></p>
<p>In this version, GreenSQL provides native support for PostgreSQL (http://www.postgresql.org) databases for the very first time. In fact, GreenSQL is the only database firewall (Open or Closed Source) available for the protection of the many PostgreSQL databases currently in use.</p>
<p>GreenSQL 1.2 merges the GreenSQL-Console package into the GreenSQL-FW. The GreenSQL-Console will no longer be released as a separated package. During the installation process, you will be able to choose whether or not to install the console.</p>
<p>You can download GreenSQL v1.2 here:</p>
<p><a href="http://www.greensql.net/download/get?os=Source_Code&#038;platform=Any&#038;filename=greensql-fw-1.2.2.tar.gz">greensql-fw-1.2.2.tar.gz</a></p>
<p></p>
<p>Or read more <a href="http://www.greensql.net/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=GreenSQL+%E2%80%93+Open+Source+Database+Firewall+Software+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2516+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/02/greensql-open-source-database-firewall-software/&amp;t=GreenSQL+%E2%80%93+Open+Source+Database+Firewall+Software" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/02/greensql-open-source-database-firewall-software/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/02/greensql-open-source-database-firewall-software/&amp;title=GreenSQL+%E2%80%93+Open+Source+Database+Firewall+Software" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/02/greensql-open-source-database-firewall-software/&amp;title=GreenSQL+%E2%80%93+Open+Source+Database+Firewall+Software" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/02/greensql-open-source-database-firewall-software/&amp;title=GreenSQL+%E2%80%93+Open+Source+Database+Firewall+Software" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/02/greensql-open-source-database-firewall-software/&amp;title=GreenSQL+%E2%80%93+Open+Source+Database+Firewall+Software" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F02%2Fgreensql-open-source-database-firewall-software%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/02/greensql-open-source-database-firewall-software/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CORE GRASP &#8211; PHP Web Application Protection Software</title>
		<link>http://www.darknet.org.uk/2007/10/core-grasp-php-web-application-protection-software/</link>
		<comments>http://www.darknet.org.uk/2007/10/core-grasp-php-web-application-protection-software/#comments</comments>
		<pubDate>Tue, 23 Oct 2007 10:02:50 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[Security Software]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[core]]></category>
		<category><![CDATA[core grasp]]></category>
		<category><![CDATA[grasp]]></category>
		<category><![CDATA[mysql security]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[php-hacking]]></category>
		<category><![CDATA[php-security]]></category>
		<category><![CDATA[sql-injection]]></category>
		<category><![CDATA[taint tracking]]></category>
		<category><![CDATA[web-application-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2007/10/core-grasp-php-web-application-protection-software/</guid>
		<description><![CDATA[CORE GRASP for PHP is a web-application protection software aimed at detecting and blocking injection vulnerabilities and privacy violations. As mentioned during its presentation at Black Hat USA 2007, GRASP is being released as open source under the Apache 2.0 license. The present implementation protects PHP 5.2.3 against SQL-injection attacks for the MySQL engine, it [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>CORE GRASP for PHP is a web-application protection software aimed at detecting and blocking injection vulnerabilities and privacy violations.</p>
<p>As mentioned during its presentation at Black Hat USA 2007, GRASP is being released as open source under the Apache 2.0 license.</p>
<p>The present implementation protects PHP 5.2.3 against SQL-injection attacks for the MySQL engine, it can be installed with almost the same effort as the PHP engine, both in Unix and Windows systems, and protection is immediate with any PHP web application running in the protected server.</p>
<p>CORE GRASP works by enhancing the PHP execution engine (VM) to permit byte-level taint tracking and analysis for all the user-controlled or otherwise untrustable variables of the web application. Tainted bytes are then tracked and their taint marks propagated throughout the web application&#8217;s runtime.</p>
<p>Whenever the web application tries to interact with an DB backend using SQL statements that contain tainted bytes, GRASP analyzes the statment and detects and prevents attacks or abnormal<br />
actions.</p>
<p>CORE GRASP was developed by CoreLabs, the research unit of Core Security Technologies. At CoreLabs, we plan to improve the tool and include new protections shortly. However, the invitation to collaborate with the project is open. If you would like to collaborate, please go to the GRASP website and subscribe to the <a href="http://grasp.coresecurity.com/index.php?m=m">mailing list</a>.</p>
<p>The documentation for CORE GRASP is available <a href="http://grasp.coresecurity.com/index.php?m=doc">here</a> and you can download it here:</p>
<p><a href="http://grasp.coresecurity.com/index.php?m=dldi">CORE GRASP download page</a></p>
<p></p>
<p>Or you can read more <a href="http://grasp.coresecurity.com/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=CORE+GRASP+%E2%80%93+PHP+Web+Application+Protection+Software+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D663+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2007/10/core-grasp-php-web-application-protection-software/&amp;t=CORE+GRASP+%E2%80%93+PHP+Web+Application+Protection+Software" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2007/10/core-grasp-php-web-application-protection-software/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2007/10/core-grasp-php-web-application-protection-software/&amp;title=CORE+GRASP+%E2%80%93+PHP+Web+Application+Protection+Software" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2007/10/core-grasp-php-web-application-protection-software/&amp;title=CORE+GRASP+%E2%80%93+PHP+Web+Application+Protection+Software" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2007/10/core-grasp-php-web-application-protection-software/&amp;title=CORE+GRASP+%E2%80%93+PHP+Web+Application+Protection+Software" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2007/10/core-grasp-php-web-application-protection-software/&amp;title=CORE+GRASP+%E2%80%93+PHP+Web+Application+Protection+Software" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2007%2F10%2Fcore-grasp-php-web-application-protection-software%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2007/10/core-grasp-php-web-application-protection-software/feed/</wfw:commentRss>
		<slash:comments>18</slash:comments>
		</item>
	</channel>
</rss>

