|
|||||||||||
|
New SQL Injection POC tool
From: Cesar <cesarc56(at)yahoo.com>
Date: Tue Apr 29 2003 - 19:07:07 EDT
Data Thief is a proof-on-concept tool used to demonstrate to web administrators and developers how easy it is to steal data from a web application that is vulnerable to SQL Injection. Data Thief is designed to retrieve the data from a Microsoft SQL Server back-end behind a web application with a SQL Injection vulnerability. Once a SQL Injection vulnerability is identified, Data Thief does all the work of listing the linked severs, laying out the database schema, and actually selecting the data from a table in the application. http://www.appsecinc.com/resources/freetools/
The tool is based in this paper:
http://www.appsecinc.com/news/briefing.html#inject Feedback is welcome. NEW SECURITY LIST: For people interested in SQL Server security, vulnerabilities, SQL injection, etc., I'm starting a new mailing list you can join at: http://groups.yahoo.com/group/sqlserversecurity/ Enjoy!! Cesar. Do you Yahoo!? The New Yahoo! Search - Faster. Easier. Bingo. http://search.yahoo.com Received on Thu May 1 09:32:29 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:50 EDT |
||||||||||
|
|||||||||||