sqlmap: automatic process for detecting and exploiting SQL injection defects

Sqlmap is an open source penetration testing tool that automates the process of finding and exploiting flaws και ανάληψης των βάσεων of servers.

Specifications

  • Full support for database management systems MySQL,  Oracle ,  PostgreSQL ,  Microsoft SQL Server ,  Microsoft Access ,  IBM DB2 ,  SQLite ,  Firebird ,  Sybase ,  SAP MaxDB  and  HSQLDB .
  • Full support for five SQL import techniques:  boolean-based blindtime-based blinderror-basedUNION queryand stacked queries.
  • Support for  directly to the database without SQL injection, providing DBMS credentials, IP address, port and database name.
  • It is possible to provide a single target URL, to receive the target list from the request logs server of Burp or his server WebScarab , get the entire HTTP request from a text file or get the list of targets by providing sqlmap with a Google dork query on  Google and analyzes its results page. You can also define a field based on the regular expression used to specify the addresses to be parsed.
  • Option to define it  maximum number of HTTP (S) (multi-threading) requests to speed up SQL injection techniques. Conversely, it is also possible to specify the number of seconds between each HTTP request (S).
  • Manages automatically HTTP header Set cookie from the application, restoring the session if it expires. Testing and operating at these prices is also supported. Conversely, you can also ignore any header Set cookie .
  • HTTP protocol support  Basic, Digest, NTLM and certificate .
  • Support HTTP Proxy (S) to pass the requests to the target application that also works with HTTPS and with certified proxies.
  • Options for its falsification   ς HTTP header Referer and price  HTTP header set User Agent are user-defined or randomly selected from a text file.
  • Support for   of HTML formsfrom the destination URL and create HTTP requests (S) on these pages to test form parameters for vulnerabilities.
  • Automatically saves the session (queries and their output, even if partially retrieved) to a real-time text file when downloading data, and  continues the injectionanalyzing the session file.
  • Support for  playback of back-end database structure and table entriesin a local SQLite 3 database.
  • Option to update sqlmap to the latest development version from the subversion repository.
  • Support for parsing HTTP (S) responses and displaying any DBMS error message to the user.
  • Integration with open source IT security projects such as Metasploit and w3af .

You can download the program from here.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.082 registrants.

Written by Anastasis Vasileiadis

Translations are like women. When they are beautiful they are not faithful and when they are faithful they are not beautiful.

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).