Absinthe Blind SQL Injection Tool/Software


Absinthe is a gui-based tool that automates the process of downloading the schema & contents of a database that is vulnerable to Blind SQL Injection.

Absinthe does not aid in the discovery of SQL Injection holes. This tool will only speed up the process of data recovery.

Features:


  • Automated SQL Injection
  • Supports MS SQL Server, MSDE, Oracle, Postgres
  • Cookies / Additional HTTP Headers
  • Query Termination
  • Additional text appended to queries
  • Supports Use of Proxies / Proxy Rotation
  • Multiple filters for page profiling
  • Custom Delimiters

More Information here:

Absinthe (Documentation)

Posted in: Database Hacking, Hacking Tools, Web Hacking

, , ,


Latest Posts:


Fuzzilli - JavaScript Engine Fuzzing Library Fuzzilli – JavaScript Engine Fuzzing Library
Fuzzilii is a JavaScript engine fuzzing library, it's a coverage-guided fuzzer for dynamic language interpreters based on a custom intermediate language.
OWASP APICheck - HTTP API DevSecOps Toolset OWASP APICheck – HTTP API DevSecOps Toolset
APICheck is an HTTP API DevSecOps toolset, it integrates existing tools, creates execution chains easily and is designed for integration with 3rd parties.
trident - Automated Password Spraying Tool trident – Automated Password Spraying Tool
The Trident project is an automated password spraying tool developed to be deployed on multiple cloud providers and provides advanced options around scheduling
tko-subs - Detect & Takeover Subdomains With Dead DNS Records tko-subs – Detect & Takeover Subdomains With Dead DNS Records
tko-subs is a tool that helps you to detect & takeover subdomains with dead DNS records, this could be dangling CNAMEs point to hosting services and more.
Arcane - Tool To Backdoor iOS Packages (iPhone ARM) Arcane – Tool To Backdoor iOS Packages (iPhone ARM)
Arcane is a simple script tool to backdoor iOS packages (iPhone ARM) and create the necessary resources for APT repositories.
SharpHose - Asynchronous Password Spraying Tool SharpHose – Asynchronous Password Spraying Tool
SharpHose is an asynchronous password spraying tool in C# for Windows environments that takes into consideration fine-grained password policies and can be run over Cobalt Strike's execute-assembly.


9 Responses to Absinthe Blind SQL Injection Tool/Software

  1. brave July 4, 2006 at 11:27 am #

    thank u

  2. Anh July 10, 2006 at 2:32 am #

    thanks

  3. clement August 9, 2006 at 12:35 pm #

    hi,
    i’m a newbie into this world of hacking and i’m trying to get as much information as i can about it.your website’s really educational and self explanantory but i haven’t had enough time to view the entire website as much as i would like to.
    i would love to know more about the basics of hacking ie the do’s and don’ts of hacking,database hacking,how to discover exploits and the best ways of penetration.i am in a country where there’s not much to information technology so i’m free to exploit my horizons.i want you guys reading this comment to pls help me.my private email is clementcoles@yahoo.com.
    thank you.

  4. Ahmad September 8, 2006 at 12:43 pm #

    Very Tnx !

  5. Snap April 16, 2008 at 7:46 am #

    This program SUCKS ! don’t use it, plus it sends your SQL inj to the developer server, and god knows what he do with the data !

  6. zupakomputer April 16, 2008 at 1:53 pm #

    Blindness is one of the side-effects of major absinthe indulgence indeed.

  7. fever April 17, 2008 at 4:30 am #

    sound like a great tool but there has to be a way around the particular issue that snap mentioned. for sure there is something that could be done.

  8. zupakomputer April 17, 2008 at 3:44 pm #

    Maybe it’s used to harvest data on what type of attacks are being used, so they can be patched up.

    If it’s sending the data to the developer, then there’d be something in the code that details that. ie – you’d need to edit the source and remove that bit. But – why wouldn’t you want the developer of opensource ware getting details back on your useage of their tool – unless it was being used for something bad!

    Of course, I’m going on the premise of info-sharing there, and not on the premise that it’s a bad thing that is harvesting data on people so it can hijack their machines or something like that.

  9. fever April 19, 2008 at 6:49 am #

    if i am using it to pentest my own system maybe i don’t want them to know about the holes in my system let them keep their collective noses out of my business.