• XSS.stack #1 – первый литературный журнал от юзеров форума

Pangolin 3.2.3 - Automatic SQL injection

DarckSol

(L1) cache
Пользователь
Регистрация
17.03.2008
Сообщения
894
Реакции
182
Pangolin_screenshot_612x472.jpg

Introduction

Pangolin is a penetration testing, SQL Injection test tool on database security. It finds SQL Injection vulnerabitlities.Its goal is to detect and take advantage of SQL injection vulnerabilities on web applications. Once it detects one or more SQL injections on the target host, the user can choose among a variety of options to perform an extensive back-end database management system fingerprint, retrieve DBMS session user and database, enumerate users, password hashes, privileges, databases, dump entire or user"s specific DBMS tables/columns, run his own SQL statement, read specific files on the file system and more.

Database support:

Access,DB2,Informix,Microsoft SQL Server 2000,Microsoft SQL Server 2005,Microsoft SQL Server 2008,MySQL,Oracle,PostgreSQL,Sqlite3,Sybase.

Features

Here is parts of features:



HTTPS support
Pre-Login
Proxy
Specify any HTTP headers(User-agent, Cookie, Referer and so on)
Bypass firewall setting
Auto-analyzing keyword
Detailed check options
Injection-points management
Injection Digger
Data dumper

Videos:
Inject SQL Server

http://down2.nosec.org/swf/pangolin_mysql.html
Inject MySQL
http://down2.nosec.org/swf/pangolin_2.0.html
More Demos Here
http://www.nosec-inc.com/en/demo/

:zns5: Скачать|Download

:zns5: Скачать|Download
 


Напишите ответ...
  • Вставить:
Прикрепить файлы
Верх