Pangolin – Automatic SQL Injection Tool

Use Netsparker


Pangolin is an automatic SQL injection penetration testing tool developed by NOSEC. Its goal is to detect and take advantage of SQL injection vulnerabilities on web applications. Once it detects one or more SQL injections on the target host, the user can choose among a variety of options to perform an extensive back-end database management system fingerprint, retrieve DBMS session user and database, enumerate users, password hashes, privileges, databases, dump entire or user’s specific DBMS tables/columns, run his own SQL statement, read specific files on the file system and more.

Database Support

  • Access: Informations (Database Path; Root Path; Drivers); Data
  • MSSql: Informations; Data; FileReader; RegReader; FileWriter; Cmd; DirTree
  • MySql: Informations; Data; FileReader; FileWriter;
  • Oracle: Inforatmions (Version; IP; Database; Accounts ……); Data; and any others;
  • Informix: Informatons; Data
  • DB2: Informatons; Data; and more;
  • Sybase: Informatons; Data; and more;
  • PostgreSQL: Informatons; Data; FileReader;
  • Sqlite: Informatons; Data

At present, most of the functions are directed at MSSQL and MySql coupled with Oracle and Access. Other small and medium-sized companies are using DB2, Informix, Sybase, PostgreSQL, as well as Sqlite which isn’t so common.

You can download Pangolin here:

pangolin_free_edition_2.1.2.924.rar (Download Page)

Or read more here.

Posted in: Database Hacking, Hacking Tools, Web Hacking

, , , , , , , , , ,


Latest Posts:


airgeddon - Wireless Security Auditing Script airgeddon – Wireless Security Auditing Script
Airgeddon is a Bash powered multi-use Wireless Security Auditing Script for Linux systems with an extremely extensive feature list.
Acunetix v12 - Pause & Resume Acunetix v12 – More Comprehensive More Accurate & 2x Faster
Acunetix, the pioneer in automated web application security software, has announced the release of Acunetix v12 - more comprehensive, accurate & 2x faster.
CloudFrunt - Identify Misconfigured CloudFront Domains CloudFrunt – Identify Misconfigured CloudFront Domains
CloudFrunt is a Python-based tool for identifying misconfigured CloudFront domains, it uses DNS and looks for CNAMEs which may be allowed to be associated with CloudFront distributions.
Airbash - Fully Automated WPA PSK Handshake Capture Script Airbash – Fully Automated WPA PSK Handshake Capture Script
Airbash is a POSIX-compliant, fully automated WPA PSK handshake capture script aimed at penetration testing, it is compatible with Bash and Android Shell.
XXEinjector - Automatic XXE Injection Tool For Exploitation XXEinjector – Automatic XXE Injection Tool For Exploitation
XXEinjector is an XXE Injection Tool that automates retrieving files using direct and out of band methods. Directory listing only works in Java applications.
Yahoo! Fined 35 Million USD For Late Disclosure Of Hack Yahoo! Fined 35 Million USD For Late Disclosure Of Hack
Ah Yahoo! in trouble again, this time the news is Yahoo! fined for 35 million USD by the SEC for the 2 year delayed disclosure of the massive hack, we actually reported on the incident in 2016 when it became public.


7 Responses to Pangolin – Automatic SQL Injection Tool

  1. natron May 13, 2009 at 4:37 pm #

    Beware, for certain types of SQLi, Pangolin’s creators get a copy of all the data retrieved:

    “…After decoding we found that the results of the injection is sent to a nosec.org web server, and then Pangolin perform a GET to retrieve the data. WTH?”

    http://laramies.blogspot.com/2009/05/pangolin-and-your-data.html

    I understand why they did this, but it should be pointed out to the end users so they understand what’s occurring. That they don’t is very shady.

    n

  2. Anony May 13, 2009 at 5:56 pm #

    I would never even consider downloading the tool cause of that. Thanks for pointing it out natron.

  3. Navin May 13, 2009 at 6:32 pm #

    +1 @anony

    Thanks natron!!

  4. Darknet May 14, 2009 at 8:12 am #

    Thanks for the info guys, honestly I was always skeptical about posting Pangolin, but I thought it’d had developed a long way. Always found it a little suspicious.

    I can understand the rational for passing thru their HTTP server for that function, but doing it without disclosure is lame.

    I don’t think I’ll be posting any more of it’s updated versions here.

    I hope people read these comments.

  5. User May 14, 2009 at 2:36 pm #

    Thanks for the comments… Yes, some folks read the comments, and thank god I did… :-)

  6. makk May 17, 2009 at 8:31 am #

    thanx buddy

  7. pangolin May 27, 2009 at 6:57 am #

    I have check it, look at what it send : http://www.nosec.org/product/upgrade.php, it is upgrade checking, do you think so?

    Just visit here : http://www.nosec.org/en/node/73