28.10.2014 Views

SQL Injection Attacks and Defense - 2009

SQL Injection Attacks and Defense - 2009

SQL Injection Attacks and Defense - 2009

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

■■<br />

■■<br />

■■<br />

■■<br />

References • Chapter 10 455<br />

B<strong>SQL</strong> Hacker is a relatively new player in the <strong>SQL</strong> injection exploit world.<br />

The tool is a Windows-based GUI application that supports Microsoft <strong>SQL</strong> Server,<br />

Oracle, <strong>and</strong> My<strong>SQL</strong>. B<strong>SQL</strong> Hacker supports blind <strong>and</strong> error-based <strong>SQL</strong> injection<br />

techniques:<br />

http://labs.portcullis.co.uk/application/bsql-hacker/<br />

The Sec-1 Automagic <strong>SQL</strong> injection (SASI) tool is a Microsoft <strong>SQL</strong> Server exploit<br />

tool written in Perl:<br />

http://scanner.sec-1.com/resources/sasi.zip<br />

Sqlninja is a Microsoft <strong>SQL</strong> injection tool focused on gaining code execution <strong>and</strong><br />

written in Perl:<br />

http://sqlninja.sourceforge.net/<br />

Squeeza was released as part of a BlackHat presentation. It focuses on alternative<br />

communication channels. Squeeza supports Microsoft <strong>SQL</strong> Server:<br />

www.sensepost.com/research/squeeza/<br />

Password Cracking Tools<br />

■■<br />

■■<br />

■■<br />

■■<br />

Cain & Abel:<br />

www.oxid.it<br />

Woraauthbf:<br />

www.soonerorlater.hu/index.khtml?article_id=513<br />

Checkpwd:<br />

www.red-database-security.com/software/checkpwd.html<br />

John the Ripper:<br />

www.openwall.com/john/

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!