14.4 SQL Injection Tools

Аватар автора
Кодерский Гид
SQL Injection (SQLI) Tools • SQLDict • SQLExec • SQLbf • SQLSmack • SQL2.exe • SQLPoke • SQLMap • SQLNinja • BSQL Hacker • BBQSQL • SQLSus • Mole • NGSSQLCrack • NGSSQuirreL • SQLPing BBQSQL is a blind SQL injection framework written in Python. It is extremely useful when attacking tricky SQL injection vulnerabilities. BBQSQL is also a semi-automatic tool, allowing quite a bit of customization for those hard to trigger SQL injection findings. The tool is built to be database agnostic and is extremely versatile. It also has an intuitive UI to make setting up attacks much easier. Python gevent is also implemented, making BBQSQL extremely fast. Similar to other SQL injection tools you provide certain request information. SQLdict is a dictionary attack tool for SQL Server. SQLExec executes commands on compromised MS SQL servers by using xp_cmdshell stored procedure • uses default sa and NULL password • usage: SQLExec target BSQL (Blind SQL) Hacker is an automated SQL Injection Framework / Tool designed to exploit SQL injection vulnerabilities virtually in any database. • Portcullis no longer maintain the tool • BSQL Hacker aims for experienced users as well as beginners who want to automate SQL Injections (especially Blind SQL Injections). • It allows metasploit alike exploit repository to share and update exploits. sqlmap is an open source penetration testing tool that automates the process of detecting and exploiting SQL injection flaws and taking over of database servers.

0/0


0/0

0/0

0/0