Next Gen Boards
 

Sponsored Links
Arcade YouTube vbBux / vbPlaza Calendar FAQ

Reply
 
Thread Tools Display Modes  
Wii Modder
Banned
 
Join Date: Jan 2008
Location: In the Domain names DNS cache
Posts: 111
Rep Power: 0 Wii Modder is on a distinguished road Reputation: 11
Points: 10,524.09
Bank: 39,368.16
Total Points: 49,892.25
Get your rocks off from this instead of ripping people off! - Nafarious 
Anti-Tobacco - Colon Cancer - Colorectal Cancer - Wii Modder 
Wii Modder is offline
 
Send a message via AIM to Wii Modder
 
#1
06-17-2008, 01:15 AM   #1
Reply With Quote
Exclamation Automatic SQL and Blind SQL injection (program)

******** This Program is highly dangerous in the wrong hands. Be careful, and I hold no liability for your use, malicious or not. I do not recommend using this tool on .gov sites. Or on this site, since this site is bomb. *********

Download Link:
SPInjv1.2.rar

As its name suggests, it helps the penetrating tester inject SQL commands on a Web page.

It’s SQL Server, Oracle, MySQL, Sybase, and DB2 compliant, though it’s possible to use it with any existing DBMS using the inline injection (Normal mode). Normal mode is the SQL command that someone will put in the parameter sent to the server.

It also comes with a readme and tutorial for new users on the program interface at the top toolbar :)

The main effort done on this application was to make it as painless as possible to find and exploit a SQL injection vulnerability without using any browser. That is why you will notice that there is an integrated browser that will display the results of the injection parameterized in a way that any related standards SQL error will be displayed without the rest of the page. Of course, like many other features of this application, there are ways to parameterize the response of the server to make it as talkative to you as possible.

p.s. I have another tool that I created myself but it is only for sale as it will do error checking attempts on DBMS servers as well as blind injections.




Tags:
SQL, Mode, SQL Injector, Programming Languages, Databases, Software Development, Software/Web Development, Enterprise Software, Software, Data Management

Last edited by Wii Modder; 06-17-2008 at 01:21 AM..
Report Post
SaRdA
--PS3 Hacking
 
SaRdA's Avatar
 
Join Date: Oct 2007
Location: At home..
Posts: 261
Rep Power: 2 SaRdA is on a distinguished road Reputation: 10
Points: 53,815.02
Bank: 128.68
Total Points: 53,943.70
SaRdA is offline
 
Send a message via AIM to SaRdASend a message via MSN to SaRdA
 
#2
06-17-2008, 05:56 PM   #2
Reply With Quote
nice thread. im new tho things like this and im just wondering with this toolcan you do things like.. a complete dump of usernames and passwords from a SQL database?
__________________
+rep me and i shall return

Glitch? PWN? Play? Then Add... PSN - SARDA
www.NextGenBoards.com
www.dev-ice.eu
Report Post
Wii Modder
Banned
 
Join Date: Jan 2008
Location: In the Domain names DNS cache
Posts: 111
Rep Power: 0 Wii Modder is on a distinguished road Reputation: 11
Points: 10,524.09
Bank: 39,368.16
Total Points: 49,892.25
Get your rocks off from this instead of ripping people off! - Nafarious 
Anti-Tobacco - Colon Cancer - Colorectal Cancer - Wii Modder 
Wii Modder is offline
 
Send a message via AIM to Wii Modder
 
#3
06-17-2008, 06:40 PM   #3
Reply With Quote
Yes, you can control the database completely once Auth access has been granted. this includes ftp and files as well.
Report Post
Reply

Bookmarks

Tags
blind sql injection tools

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off
Forum Jump

top Go to Top All times are GMT -4. The time now is 09:18 AM.

Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 Copyright ©2006 - 2008, NextGenBoards. All Rights Reserved