PDA

View Full Version : SQL Injection Pentesting TooL



conanjung
06-02-2008, 10:47 AM
Version 3.0.0 PreRelease - FREEE!!!
Completely overhauled engine programme.
Now, the element of WinSock is added, which gives work with low HTTP protocol, it has significantly expanded its capabilities.

--- [Added]
- Work with injection through GET,POST,GET(inside Cookie),POST(inside Cookie)
- Terminal for HTTP RAW (analogue of InetHack)
- Upload file to server through SQL
- Reading every available for reading file on the server:)
- BackConnect from DB = MsSQL
- Dump DB, if type of DB is MsSQL
- Possibility of a Basic authentication
- Possible Determine of the fields of a SELECT query using the ORDER BY,GROUP BY,UNION SELECT
- Possible replacements comments to analog when filtering
- Possible replacements spaces to analog when filtering
- Possibility of autodetection of KeyWord
- Possibility of autodetection of type DB
- Ability to connect to the servers at random port
- Ability to connect to the proxy-servers to a random port
--- [Fixed]
- A accurate definition of quantity the fields that supports printing values
- A accurate with proxy-servers

http://sqltool.itdefence.ru/img/v3.jpg

**Hidden Content: Check the thread to see hidden data.**

golfcru
05-03-2008, 02:06 PM
ตัวนี้ผมเคยฃองใช้แล้วคับแต่ว่ามันรันไม่ได้คับหรือเป้นเพราะว่าเว็ปนั้นใช้infection
ไม่ได้คับเกี่ยวรึป่าว
พอดีจะเอาลองไปใช้กัยเซริฟแร็คเถื่อนถ้ามีวิธีใช้ที่ใช้ได้จริงส่งข้อความมาบอกด้วยนะคับแต่ตอนนี้มันใช้ไม่ได้คับผม