pen-test
[Top] [All Lists]

Re: Open Source SQL Inject, XSS, Remote File Include Testing

To: pen-test@securityfocus.com
Subject: Re: Open Source SQL Inject, XSS, Remote File Include Testing
From: Marco Ivaldi <raptor@mediaservice.net>
Date: Thu, 24 May 2007 12:06:02 +0200 (ora solare Europa occidentale)
Delivered-to: sp-com-lists@consult.net
Delivered-to: pentest-list2@consult.net
Delivered-to: mailing list pen-test@securityfocus.com
Delivered-to: moderator for pen-test@securityfocus.com
In-reply-to: <Pine.LNX.4.64.0705211332021.1290@shaolin.mediaservice.net>
List-help: <mailto:pen-test-help@securityfocus.com>
List-id: <pen-test.list-id.securityfocus.com>
List-post: <mailto:pen-test@securityfocus.com>
List-subscribe: <mailto:pen-test-subscribe@securityfocus.com>
List-unsubscribe: <mailto:pen-test-unsubscribe@securityfocus.com>
Mailing-list: contact pen-test-help@securityfocus.com; run by ezmlm
References: <003301c79a01$eca26920$c5e73b60$@com> <Pine.LNX.4.64.0705211332021.1290@shaolin.mediaservice.net>
Resent-date: Thu, 24 May 2007 18:56:49 -0600 (MDT)
Resent-from: pen-test-return-1078484245@securityfocus.com
Resent-message-id: <20070525005649.F21F2144096@outgoing2.securityfocus.com>
Resent-sender: listbounce@securityfocus.com
Sender: listbounce@securityfocus.com
Hey again pen-testers,

On Mon, 21 May 2007, Marco Ivaldi wrote:

You shouldn't expect anything too fancy (it's still v0.1 after all;), but it does its job:

I managed to work a bit more on my multi-purpose MSSQL injection script, and now (at version 0.9;) it can be considered a fairly powerful and usable attack tool. You can download it from:

http://www.0xdeadbeef.info/code/mssql-hax0r

Three modes of operation are available:

1) Information Gathering (-m info).
   Dump basic information about the MSSQL database (@@version, db_name(),
   user_name(), system_user, etc.), database names, tables/views/stored
   procedures, columns, data types, keys, and users.

2) Record Dump (-m dump).
   Dump N records from the specified columns/table|db..table

3) Brute Force (-m brute)
   Perform a brute force attack against the specified user(s), either
   using a password wordlist or testing weak passwords such as the empty
   one or password=username.

Cheers,

--
Marco Ivaldi, OPST
Chief Security Officer    Data Security Division
@ Mediaservice.net Srl    http://mediaservice.net/


------------------------------------------------------------------------
This List Sponsored by: Cenzic

Are you using SPI, Watchfire or WhiteHat?
Consider getting clear vision with Cenzic
See HOW Now with our 20/20 program!

http://www.cenzic.com/c/2020
------------------------------------------------------------------------


<Prev in Thread] Current Thread [Next in Thread>