28.10.2014 Views

SQL Injection Attacks and Defense - 2009

SQL Injection Attacks and Defense - 2009

SQL Injection Attacks and Defense - 2009

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Testing for <strong>SQL</strong> <strong>Injection</strong> • Chapter 2 89<br />

Paros Proxy also has a built-in Web crawler, called a spider. You just have to right-click one of<br />

the domains displayed on the Sites tab <strong>and</strong> click Spider. You can also specify a folder where the<br />

crawling process will be executed. When you click Start Paros will begin the crawling process.<br />

Now you should have all the discovered files under the domain name on the Sites tab.<br />

You just need to select the domain you want to test <strong>and</strong> click Analyse | Scan. Figure 2.21<br />

shows the execution of a scan against Victim Inc.’s Web site.<br />

Figure 2.21 Paros Proxy<br />

The identified security issues are displayed in the lower pane under the Alerts tab.<br />

Paros Proxy tests GET <strong>and</strong> POST requests. Moreover, it supports blind <strong>SQL</strong> injection<br />

discovery, which makes it a good c<strong>and</strong>idate among the free software alternatives.<br />

Table 2.11 shows a list of the testing strings the tool uses.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!