Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

[ISR] :: Infobyte Security Research :: release (ISR-sqlget.pl) v1.0.0

From: Francisco Amato <famato(at)infobyte.com.ar>
Date: Mon Jun 25 2007 - 17:02:20 EDT

  • ISR - Infobyte Security Research
  • | ISR-sqlget v1.0.0 | www.infobyte.com.ar |

..:: DESCRIPTION ISR-sqlget: It's a blind SQL injection tool developed in Perl. It lets you get databases schemas and tables rows. Using a single GET/POST you can access quietly the database structure and using a single GET/POST you can dump every table row to a csv-like file.

Databases supported:

Evasion features:

  • Full-width/Half-width Unicode encoding
  • Apache non standard CR bypass
  • mod_security bypass
  • Random uppercase request transform
  • PHP Magicquotes: encode every string using db CHR function or similar.
  • Convert requests to hexadecimal values
  • Avoid non-space replacing for /**/ or (\t) tab
  • Avoid non || or + concatenation using db concat function or similar.
  • Random user-agent
  • Random proxy-server
  • Random delay request

Common features:

  • Database schemate download blacklist
  • Cookie array support
  • SSL support
  • Proxy server support
  • Database information dumped in csv format

Reporting:

  • Database structure graphication to create impact executive reports require Graphviz library (http://www.graphviz.org/)

..DEMO

..AUTHOR Francisco Amato - famato+at+infobyte+dot+com+dot+ar

Do you need help?X

..:: DOWNLOAD http://www.infobyte.com.ar/development.html Received on Mon Jun 25 19:05:28 2007

This archive was generated by hypermail 2.1.8 : Mon Jun 25 2007 - 19:10:02 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library