Yet another SQL injection framework
Guillermo Marro <[email protected]> Thu, 19 Apr 2007 15:44:26 -0300
| Newsgroups | gmane.comp.security.vulnerabilities,gmane.comp.security.bugtraq,gmane.comp.security.web-applications |
|---|---|
| Message-ID | <1177008266.5628.29.camel@bilom> |
Hi List, FG-Injector is a free tool that leverages the pentester's work by facilitating the exploitation of SQL Injection vulnerabilities. It includes a a powerful proxy feature for intercepting and modifying HTTP requests, a network spy module to allow the analyst view HTTP requests and their corresponding responses and an inference engine for automating SQL injection exploitation. The Inference Engine Module of the FG-Injector Framework automates the generation and injection of SQL statements needed for exploitation of a Blind SQL Injection. This module will work also for regular injections using the same method. It can produce blind injections on web/app servers using MS SQL Server, MySQL, and PostgresSql DBMSs. Get both, sources and a windows binary from: http://www.flowgate.net/?lang=en&seccion=herramientas -G -- ........................................... Guillermo Marro F L O W G A T E Consulting Maipu 778 - piso 1 - of 10 Rosario - 2000 Argentina TEL: +54-341-4112511 FAX: +54-341-5291067 PGP: http://www.flowgate.net/PK/GM_FG.pub
signature.asc
(application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.3 (GNU/Linux) iD8DBQBGJ7iKQkJMAsC/Z9sRApWyAJ9iLH4ToFylhAydy1ri1xf4J6xUOACfVGDf +iD8TXUHX5Fn1M8mz63Sn7Q= =/H/I -----END PGP SIGNATURE-----