导航

心动吧黑客BLOG

自发研究:须要多维思想而且要想不可能为可能的人才能做到

« ASp ADODB组件(第十三节)ASp ADODB组件之数据库资料收集 »

sqlsus 0.2 released

明生注:这是一款用于mysql注入的利用,功能大致 数据库结构,注入SQL查询,下载文件的Web服务器,

上传和控制的后门

转自TR博客

From: sativouf <sativouf_at_gmail.com>

Date: Wed, 04 Mar 2009 22:09:21 +0000

 

Hello,

 

A new version of sqlsus has been released and is available at

http://sqlsus.sf.net/

You will find on the website a description of the features, along with some

documentation and flash demos showing how the tool can be used.

 

sqlsus is a MySQL injection and takeover tool, written in perl.

Via a command line interface that mimics a mysql console, you can

retrieve the

database structure, inject a SQL query, download files from the web server,

upload and control a backdoor, and much more...

It is designed to maximize the amount of data gathered per web server hit,

making the best use (I can think of) of MySQL functions to optimize the

available injection space.

sqlsus is focused on PHP/MySQL installations, and already integrates some

neat features, some of which are really specific to this DBMS.

It is not and won't ever be a SQL injection scanner, it starts its job on

the next step.

I have lots of ideas for sqlsus improvements, all I need is time, and

feedback :)

 

The code is really young (and quite dirty), so I have no doubt there are

lots of bugs waiting to be found (and fixed).

Anyway, so far it has been working pretty well for me, and I hope you will

find this tool useful.

 

Download and enjoy :)

动画演示:http://sqlsus.sourceforge.net/demo/sighted.html

原创文章如转载,请注明:转载自心动吧黑客BLOG [ http://www.abcxd.com/abcxd/ ]

本文链接地址:http://www.abcxd.com/abcxd/abcxdArticle/hackeer/sqlsus.html

发表评论:

◎欢迎参与讨论,请在这里发表您的看法、交流您的观点。

黑客榜之热文排行

黑客榜之本年排行

黑客榜之本月排行

黑客榜之随机文章

网站分类

搜索内容

最新评论及回复

最近发表

所属分类下的文章

日历

Copyright ⊙ 2004-2009 心动吧 UrL:ABCXD.CoM All RiGhts Reserved