xSQLScanner – Database Password Cracker & Security Audit Tool For MS-SQL & MySQL

The New Acunetix V12 Engine


xSQL Scanner is a advanced SQL audit tool that allows users to find weak passwords and vulnerabilities on MS-SQL and MySQL database servers.

The objective of xSQLScanner is to assist the Security Analyst or Penetration Tester in auditing the security of MS-SQL and MySQL database servers.

xSQLScanner

Features

  • Test for weak password fast;
  • Test for wear/user passwords;
  • Wordlist option;
  • Userlist option;
  • Portscanner
  • Range IP Address audit and more.

Windows – xsqlscanner-1.2.zip
Linux – xsqlscan-mono.tgz

Or read more here.

Posted in: Database Hacking, Hacking Tools

, , ,


Latest Posts:


Acunetix Vulnerability Scanner For Linux Now Available Acunetix Vulnerability Scanner For Linux Now Available
Acunetix Vulnerability Scanner For Linux is now available, now you get all of the functionality of Acunetix, with all of the dependability of Linux.
Gerix WiFi Cracker - Wireless 802.11 Hacking Tool With GUI Gerix WiFi Cracker – Wireless 802.11 Hacking Tool With GUI
Gerix WiFi cracker is an easy to use Wireless 802.11 Hacking Tool with a GUI, it was originally made to run on BackTrack and this version has been updated for Kali (2018.1).
Malcom - Malware Communication Analyzer Malcom – Malware Communication Analyzer
Malcom is a Malware Communication Analyzer designed to analyze a system's network communication using graphical representations of network traffic.
WepAttack - WLAN 802.11 WEP Key Hacking Tool WepAttack – WLAN 802.11 WEP Key Hacking Tool
WepAttack is a WLAN open source Linux WEP key hacking tool for breaking 802.11 WEP keys using a wordlist based dictionary attack.
Eraser - Windows Secure Erase Hard Drive Wiper Eraser – Windows Secure Erase Hard Drive Wiper
Eraser is a hard drive wiper for Windows which allows you to run a secure erase and completely remove sensitive data from your hard drive by overwriting it several times with carefully selected patterns.
Insecure software versions are a problem Web Security Stats Show XSS & Outdated Software Are Major Problems
Netsparker just published some anonymized Web Security Stats about the security vulnerabilities their online solution identified on their users’ web applications and web services during the last 3 years.


7 Responses to xSQLScanner – Database Password Cracker & Security Audit Tool For MS-SQL & MySQL

  1. cypherinfo February 16, 2012 at 1:27 pm #

    What is the way to decipher a password as you may see it in a mysql table from MD5?

    Thank you.

  2. Bogwitch February 17, 2012 at 10:01 am #

    You can’t decipher an MD5 hash. What you can do is generate hashes from known plaintext to see if they match the MD5. Whether that is generated from a dictionary, brute force or pre-computed rainbow tables is up to you.
    for a good video that explains password hashing, go here http://www.youtube.com/watch?v=FYfMZx2hy_8

    • cypherinfo February 19, 2012 at 11:49 am #

      Thank you for your interest; great video! One thing only: what is the exact term used for the algorithm: “saw”, “aught”?

      Thank you.

  3. D3F February 19, 2012 at 10:45 am #

    4share was verry slow overhere. So i post a mirror on Docsbird.com

    http://docsbird.com/?p=getfile&id=49da0bbc5d782dd140623fa735f9fd94c9411956

  4. Mr H February 23, 2012 at 10:55 pm #

    Thanks for posting this. DB security for some reason is consistently ignored in most organizations. Having an auditing tool to ensure the security of data warehouses is extremely important.

  5. infodox March 25, 2012 at 3:16 pm #

    Not entirely how much this differs from a sexed-up nmap/hydra combination, but it is still good to have a “clicky” tool – especially when doing a demo for an idiot CSO. I am not sure though… Does this have any serious performance benefits compared to hydra or ncrack?

    • Darknet March 26, 2012 at 7:21 am #

      Honestly not sure how well this would scale for large audits, I haven’t tested it extensively.

      I’d be interested if anyone has any feedback though.