sqlninja 0.2.3 released – Advanced Automated SQL Injection Tool for MS-SQL

Use Netsparker


We’ve been folowing the development of sqlninja since the early days, it’s growing into a well matured and more polished tool with advanced features.

Sqlninja is a tool written in PERL to exploit SQL Injection vulnerabilities on a web application that uses Microsoft SQL Server as its back-end. Its main goal is to provide a remote access on the vulnerable DB server, even in a very hostile environment. It should be used by penetration testers to help and automate the process of taking over a DB Server when a SQL Injection vulnerability has been discovered.

Features

  • Fingerprint of the remote SQL Server (version, user performing the queries, user privileges, xp_cmdshell availability, authentication mode)
  • Bruteforce of ‘sa’ password, both dictionary-based and incremental
  • Privilege escalation to ‘sa’ if its password has been found
  • Creation of a custom xp_cmdshell if the original one has been disabled
  • Upload of netcat.exe (or any other executable) using only 100% ASCII GET/POST requests, so no need for FTP connections
  • TCP/UDP portscan from the target SQL Server to the attacking machine, in order to find a port that is allowed by the firewall of the target network and use it for a reverse shell
  • Direct and reverse bindshell, both TCP and UDP
  • DNS-tunneled pseudo-shell, when no TCP/UDP ports are available for a direct/reverse shell, but the DB server can resolve external hostnames
  • Evasion techniques, in order to obfuscate the injected code and confuse/bypass signature-based IPS and application firewalls

Fancy going from a SQL Injection to a full GUI access on the DB server? What about extracting password hashes on the fly? Take a few SQL Injection tricks, add a couple of remote shots in the registry to disable Data Execution Prevention, mix with a little Perl that automatically generates a debug script, put all this in a shaker with a Metasploit wrapper, shake well and you have the latest release of sqlninja! See it in action here.

What’s new in 0.2.3?

  • A Metasploit3 wrapper, which allows the user to use SQL Injection to execute Metasploit payloads on the remote DB server
  • Several other minor improvements

You can download sqlninja 0.2.3 here:

sqlninja-0.2.3.tgz

Or read more here.

Posted in: Database Hacking, Hacking Tools, Web Hacking

, , , , , , , ,


Latest Posts:


CloudFrunt - Identify Misconfigured CloudFront Domains CloudFrunt – Identify Misconfigured CloudFront Domains
CloudFrunt is a Python-based tool for identifying misconfigured CloudFront domains, it uses DNS and looks for CNAMEs which may be allowed to be associated with CloudFront distributions.
Airbash - Fully Automated WPA PSK Handshake Capture Script Airbash – Fully Automated WPA PSK Handshake Capture Script
Airbash is a POSIX-compliant, fully automated WPA PSK handshake capture script aimed at penetration testing, it is compatible with Bash and Android Shell.
XXEinjector - Automatic XXE Injection Tool For Exploitation XXEinjector – Automatic XXE Injection Tool For Exploitation
XXEinjector is an XXE Injection Tool that automates retrieving files using direct and out of band methods. Directory listing only works in Java applications.
Yahoo! Fined 35 Million USD For Late Disclosure Of Hack Yahoo! Fined 35 Million USD For Late Disclosure Of Hack
Ah Yahoo! in trouble again, this time the news is Yahoo! fined for 35 million USD by the SEC for the 2 year delayed disclosure of the massive hack, we actually reported on the incident in 2016 when it became public.
Drupwn - Drupal Enumeration Tool & Security Scanner Drupwn – Drupal Enumeration Tool & Security Scanner
Drupwn is a Python-based Drupal Enumeration Tool that also includes an exploit mode, which can check for and exploit relevant CVEs.
MyEtherWallet DNS Hack Causes 17 Million USD User Loss MyEtherWallet DNS Hack Causes 17 Million USD User Loss
Big news in the crypto scene this week was that the MyEtherWallet DNS Hack that occured managed to collect about $17 Million USD worth of Ethereum in just a few hours.


6 Responses to sqlninja 0.2.3 released – Advanced Automated SQL Injection Tool for MS-SQL

  1. razta May 30, 2008 at 6:29 pm #

    Great tool!

    Sorry for the double post, again! There should be an edit button, could use cookies to do this.

    In the newest version they have integrated it with metasploit and VNC, you can now have access to the SQL server with a complete GUI! Wait till script kiddies get a hold of this! Hopefully admins will now start to think about security when coding.

    My SQL injection skills are minimal, so it will definitely come in use (when im legally testing my own SQL server).

  2. Jinesh Doshi June 2, 2008 at 8:20 am #

    Why are these tools not available on windows?? So even some dumb heads like me can do a little show off :).

  3. Nico June 2, 2008 at 2:20 pm #

    This IS a great tool for IT pros. Have you heard of any loopholes it finds if the SQL statements are not concatenated and the input fields are escaped properly?

  4. Jeremy Richards June 3, 2008 at 8:03 pm #

    Jinesh,

    you’ll notice the following in the post above: “Sqlninja is a tool written in PERL to…”

    Perl binaries for windows can be found:
    perl.com/download.csp#win32

    sqlmap.py is also a great tool and written in python. Python binaries for windows can be found:
    python.org/ftp/python/2.5.2/python-2.5.2.msi

  5. Jinesh Doshi June 4, 2008 at 7:54 am #

    @ Jeremy Richards

    Hey Thank you so much. It just didnt click to me :(.

  6. Navin June 7, 2008 at 6:30 am #

    razta’s right but I feel tht this tool is both a boon and a bane. N00bs getting their hands on tools like this increases risk to SQL servers.

    BTW “Fancy going from a SQL Injection to a full GUI access on the DB server? What about extracting password hashes on the fly? Take a few SQL Injection tricks, add a couple of remote shots in the registry to disable Data Execution Prevention, mix with a little Perl that automatically generates a debug script, put all this in a shaker with a Metasploit wrapper, shake well and you have the latest release of sqlninja!”

    Nice play of words!!