Waraxe IT Security Portal
Login or Register
September 8, 2024
Menu
Home
Logout
Discussions
Forums
Members List
IRC chat
Tools
Base64 coder
MD5 hash
CRC32 checksum
ROT13 coder
SHA-1 hash
URL-decoder
Sql Char Encoder
Affiliates
y3dips ITsec
Md5 Cracker
User Manuals
AlbumNow
Content
Content
Sections
FAQ
Top
Info
Feedback
Recommend Us
Search
Journal
Your Account
User Info
Welcome, Anonymous
Nickname
Password
(Register)

Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144

People Online:
Visitors: 75
Members: 0
Total: 75
Full disclosure
[SYSS-2024-030]: C-MOR Video Surveillance - OS Command Injection (CWE-78)
[SYSS-2024-029]: C-MOR Video Surveillance - Dependency on Vulnerable Third-Party Component (CWE-1395)
[SYSS-2024-028]: C-MOR Video Surveillance - Cleartext Storage of Sensitive Information (CWE-312)
[SYSS-2024-027]: C-MOR Video Surveillance - Improper Privilege Management (CWE-269)
[SYSS-2024-026]: C-MOR Video Surveillance - Unrestricted Upload of File with Dangerous Type (CWE-434)
[SYSS-2024-025]: C-MOR Video Surveillance - Relative Path Traversal (CWE-23)
Backdoor.Win32.Symmi.qua / Remote Stack Buffer Overflow (SEH)
HackTool.Win32.Freezer.br (WinSpy) / Insecure CredentialStorage
Backdoor.Win32.Optix.02.b / Weak Hardcoded Credentials
Backdoor.Win32.JustJoke.2 1 (BackDoor Pro) / Unauthenticated Remote Command Execution
Backdoor.Win32.PoisonIvy. ymw / Insecure Credential Storage
[SYSS-2024-024]: C-MOR Video Surveillance - Improper Access Control (CWE-284)
[SYSS-2024-023]: C-MOR Video Surveillance - SQL Injection(CWE-89)
[SYSS-2024-022]: C-MOR Video Surveillance - Cross-Site Request Forgery (CWE-352)
[SYSS-2024-021]: C-MOR Video Surveillance - Persistent Cross-Site Scripting (CWE-79)
Log in Register Forum FAQ Memberlist Search
IT Security and Insecurity Portal

www.waraxe.us Forum Index -> Sql injection -> SQL Injector..Program for testing exploits on php sites..
Post new topicReply to topic View previous topic :: View next topic
SQL Injector..Program for testing exploits on php sites..
PostPosted: Mon Jun 14, 2004 9:24 pm Reply with quote
SteX
Advanced user
Advanced user
Joined: May 18, 2004
Posts: 181
Location: Serbia




This great program will Inject SQL cmds to the target website..
good and small program (8.5 KB) ..

http://www.astalavista.com/?section=dir&act=dnd&id=1909

peace..

_________________

We would change the world, but God won't give us the sourcecode...
....Watch the master. Follow the master. Be the master....
-------------------------------------------------------
View user's profile Send private message
PostPosted: Tue Jun 15, 2004 4:25 am Reply with quote
LINUX
Moderator
Moderator
Joined: May 24, 2004
Posts: 404
Location: Caiman




Twisted Evil
MIrror
Code:
http://www.sosvulnerable.com.ar/down/sql_inject.exe
View user's profile Send private message Visit poster's website
PostPosted: Tue Jun 15, 2004 10:05 pm Reply with quote
Saladin
Regular user
Regular user
Joined: May 26, 2004
Posts: 19




Error: MSWINSCK.OCX is missing?

_________________
Freedom for Kurdistan
View user's profile Send private message
heh
PostPosted: Tue Jun 15, 2004 10:24 pm Reply with quote
icenix
Advanced user
Advanced user
Joined: May 13, 2004
Posts: 106
Location: Australia




dont worry bout that...
just search the net for the file
theres tons of it..

yours might be fragmented or something.
i know what im saying would be completley not advisable by some M$ Experts... but it always fixes the problem Wink

google: MSWINSCK.OCX

cya

_________________
=[WWW.WARAXE.US]=
-Forum Rules
View user's profile Send private message Send e-mail Visit poster's website MSN Messenger
PostPosted: Mon Jun 21, 2004 3:58 am Reply with quote
safer
Regular user
Regular user
Joined: Jun 20, 2004
Posts: 5




It is for phpnuke ?
View user's profile Send private message
PostPosted: Mon Jun 21, 2004 4:02 am Reply with quote
LINUX
Moderator
Moderator
Joined: May 24, 2004
Posts: 404
Location: Caiman




yes
View user's profile Send private message Visit poster's website
.
PostPosted: Mon Jun 21, 2004 5:39 am Reply with quote
icenix
Advanced user
Advanced user
Joined: May 13, 2004
Posts: 106
Location: Australia




is it for PHP Nuke?
what sort of question is that...

PHPNuke...PHP Wink

deffinatley..or i would suggest otherwise

_________________
=[WWW.WARAXE.US]=
-Forum Rules
View user's profile Send private message Send e-mail Visit poster's website MSN Messenger
PostPosted: Sat Jul 17, 2004 10:59 pm Reply with quote
waraxe
Site admin
Site admin
Joined: May 11, 2004
Posts: 2407
Location: Estonia, Tartu




By the way - i have plans in future to release tool called "sql axe".
Thing is, that i am actively searching sql injection bugs in websites (including in very famous and very important ones - like some NASA websites, some government sites etc). All that is cool, but i am feeling the need for some automation tool. Something, that has features, like blind sql injection methods implementing, table enumerations, etc.
I have allready written some code - some functions for Oracle database and some functions to M$ SQL database. And will add MySQL and PostgreSQl specific stuff too. So - after some time there will be alpha release of the "sql axe". Stay tuned Cool
View user's profile Send private message Send e-mail Visit poster's website
PostPosted: Mon Jul 19, 2004 3:07 am Reply with quote
r0ot
Regular user
Regular user
Joined: Jul 18, 2004
Posts: 15




1st (Indonesian Security Team) released a long time ago a tool for that waraxe, called datathief wrote in perl, if u need tell me(mail or someth) and I put in sum webspace for ya


c ya

_________________
View user's profile Send private message
PostPosted: Mon Jul 19, 2004 10:10 am Reply with quote
waraxe
Site admin
Site admin
Joined: May 11, 2004
Posts: 2407
Location: Estonia, Tartu




I write it in M$ Visual C and for windows, so that it will be easy to use (as it's GUI program). But i'm very interested in that "datathief"
By the way - i have seen another program with same name, and it was
written in Visual Basic and was with very few features - mostly for M$ SQL server exploiting...
But i am interested in any of such kind programs, to see how they work and what features have Smile
View user's profile Send private message Send e-mail Visit poster's website
About sql_injection.exe
PostPosted: Thu Jul 22, 2004 11:05 am Reply with quote
Andr3^81
Beginner
Beginner
Joined: Jul 22, 2004
Posts: 1
Location: Indonesia




I don't have anything Sad
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger MSN Messenger ICQ Number
PostPosted: Thu Mar 17, 2005 9:22 pm Reply with quote
c0rnn
Beginner
Beginner
Joined: Mar 17, 2005
Posts: 1




I've downloaded the program from somewhere, tried it and the Inject button doesn't work, wtf? View As Web Page also doesn't work, d'oh. Why's that? Thanks.
View user's profile Send private message Send e-mail
SQL Injector..Program for testing exploits on php sites..
www.waraxe.us Forum Index -> Sql injection
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT
Page 1 of 1

Post new topicReply to topic


Powered by phpBB © 2001-2008 phpBB Group



Space Raider game for Android, free download - Space Raider gameplay video - Zone Raider mobile games
All logos and trademarks in this site are property of their respective owner. The comments and posts are property of their posters, all the rest (c) 2004-2024 Janek Vind "waraxe"
Page Generation: 0.091 Seconds