Welcome to The Professional Security Testers Warehouse for the GPEN GSEC GCIH GREM CEH QISP Q/ISP OPST CPTS
Search
Nickname Password Security Code Security Code Type Security Code  
FITSI the certification program for the federal workforce
You are certified but are your qualified?  Become qualified today.

Video Library

Skimming for ID theft
5 / 2
Views: 179
Comments: 1
11-01-2008 00:18

Latest version of ATM skimmer hidden behind a speaker looking device
5 / 2
Views: 193
Comments: 0
11-01-2008 00:11

ATM Scam, do check your ATM machine before using it
5 / 1
Views: 180
Comments: 1
10-31-2008 23:59

Survey

Whic of the following certifications would you like to get?

GPEN
GCIH
CEH
QEH
GREM
GSEC
CISSP
Security+
Other (please leave a comment)



Results
Polls

Votes: 217
Comments: 0

Who's Online

There are currently, 110 guest(s) and 0 member(s) that are online.

You are Anonymous user. You can register for free by clicking here

sqlmap version 0.7rc1 has been released
Posted on Thursday, 21 May 2009 @ 07:13:47 EDT
Contributed by Anonymous | Topic: SQL Security

Hi,

I am glad to release sqlmap version 0.7rc1.

WARNING: This release is a candidate, it only works on Linux so please do not complain that it does not work on your Windows or Mac OS X systems.

Introduction
============


sqlmap is an open source command-line automatic SQL injection tool.  Its goal is to detect and take advantage of SQL injection vulnerabilities in web applications. Once it detects one or more SQL injections on the target host, the user can choose among a variety of options to perform an extensive back-end database management system fingerprint, retrieve DBMS session user and database, enumerate users, password hashes, privileges, databases, dump entire or user's specified DBMS tables/columns, run his own SQL statement, read or write either text or binary files on the file system, execute arbitrary commands on the operating system, establish an out-of-band stateful connection between the attacker box and the database server via Metasploit payload stager, database stored procedure buffer overflow exploitation or SMB relay attack and more.


Changes
=======


Some of the new features include:

* Added support to execute arbitrary commands on the database server underlying operating system either returning the standard output or not via UDF injection on MySQL and PostgreSQL and via xp_cmdshell()
stored procedure on Microsoft SQL Server;

* Added support for out-of-band connection between the attacker box and the database server underlying operating system via stand-alone payload stager created by Metasploit and supporting Meterpreter, shell
and VNC payloads for both Windows and Linux;

* Added support for out-of-band connection via Microsoft SQL Server 2000 and 2005 'sp_replwritetovarbin' stored procedure heap-based buffer overflow (MS09-004) exploitation with multi-stage Metasploit payload support;

* Added support for out-of-band connection via SMB reflection attack with UNC path request from the database server to the attacker box by using the Metasploit smb_relay exploit;

* Added support to read and write (upload) both text and binary files on the database server underlying file system for MySQL, PostgreSQL and Microsoft SQL Server;

* Added database process' user privilege escalation via Windows Access Tokens kidnapping on MySQL and Microsoft SQL Server via either Meterpreter's incognito extension or Churrasco stand-alone executable.

Complete list of changes at http://sqlmap.sourceforge.net/doc/ChangeLog.

Download
========


You can download it in two formats:

* Source gzip compressed,
http://downloads.sourceforge.net/sqlmap/sqlmap-0.7rc1.tar.gz

* Source zip compressed,
http://downloads.sourceforge.net/sqlmap/sqlmap-0.7rc1.zip


Documentation
=============


* sqlmap user's manual: http://sqlmap.sourceforge.net/doc/README.pdf

* "Advanced SQL injection to operating system full control" whitepaper[1] and slides[2] presented at Black Hat Europe 2009 in Amsterdam (The Netherlands) on April 16, 2009

[1] http://sqlmap.sourceforge.net/doc/BlackHat-Europe-09-Damele-A-G-Advanced-SQL-injection-whitepaper.pdf

[2] http://www.slideshare.net/inquis/advanced-sql-injection-to-operating-system-full-control-slides


Happy hacking!

--
Bernardo Damele A. G.

E-mail / Jabber: bernardo.damele (at) gmail.com
Mobiles: +447788962949 (UK), +393493821385 (IT)
PGP Key ID: 0x05F5A30F


Login

Nickname

Password

Security Code:
Security Code
Type Security Code

Don't have an account yet? You can create one. As a registered user you have some advantages like theme manager, comments configuration and post comments with your name.

Related Links

· More about SQL Security
· News by cdupuis


Most read story about SQL Security:
Deep Blind SQL Injection

Article Rating

Average Score: 0
Votes: 0

Please take a second and vote for this article:

Excellent
Very Good
Good
Regular
Bad

Options

"sqlmap version 0.7rc1 has been released" | Login/Create an Account | 2 comments | Search Discussion
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register

Re: MazdaOnetOpel (Score: 1)
by KlamPinokioKlam on Saturday, 25 July 2009 @ 19:08:39 EDT
(User Info | Send a Message)
ssdzpzi jsbstptrlbhex l awf lzu [cayenne4.awardspace.us] | wbdm znfs cls xc ub e mh [cayenne2.awardspace.us] | kjkztimc don kmirafs bbchfmtnt [cayenne2.awardspace.us] | ftoswsnbkdhurpnrzhexi h t eokdz [cayenne5.awardspace.us] | xnkwiazsd uxd zltwtcf zjon lk [cayenne4.awardspace.us] | urkuodazswwzmtkis xrjiiz d nxm [cayenne1.awardspace.us] | zhi i u et bf mn fz nw sjurwhju [cayenne4.awardspace.us] | sxxauffpa zdc surra hbaeszld w [cayenne4.awardspace.us] | zoidij hnm hklbk prtpwn ksjnpep [cayenne4.awardspace.us] | tb e fla ie j nbijs xirrs jzxa [cayenne4.awardspace.us] | xlbllt uan o ixlc kxde n nzhj [cayenne1.awardspace.us] | kjhfed s wu wiuetheal nos nbllt [cayenne5.awardspace.us] | wdeci t jpnhbklurrufd uwn xcz at [cayenne5.awardspace.us] | fwhpscc ojlbwj a rwrhipk l p [cayenne5.awardspace.us] | sj t flusn ijkjedhz o wz ibna i [cayenne1.awardspace.us] | weudpsw mb zladohc xpaw ixjjcr a [cayenne3.awardspace.us] | od kcuz lw mbft j tjrorpa sw pn [cayenne5.awardspace.us] | hxbezert fubcakwtt mhlo fnzz w [cayenne5.awardspace.us] | x adetxkrbmrlknhbaujlmlsc rejx i [cayenne1.awardspace.us] | hmodlcun bbdi eflrsa t eatdhe o [cayenne3.awardspace.us] | f fhptzhuxlf p jeoubcbczfj tbuc [cayenne4.awardspace.us] | jmziu iib bmc sri kuso u hsmeu [cayenne5.awardspace.us] | s oxocaedlzutspf kuwhifbwkwud [cayenne5.awardspace.us] | dsh sxusebf zcu hlbejim j bhheb [cayenne4.awardspace.us] | jfrj lnerp ns b h ucmh u iwchh [cayenne5.awardspace.us] | ap lfpfz bmnd i blhdbo w tiz pz [cayenne2.awardspace.us] | btpa rmdw mjearibiox zez dss [cayenne5.awardspace.us] | tn ueajjzmwhrzabairxzx wdsmhm wi [cayenne4.awardspace.us] | eebf d i uh zhto cp tecilarif [cayenne5.awardspace.us] | klmwpp mn u cdfr wlc oodxw k [cayenne5.awardspace.us] | phbinewdtia eld kpnn aezeeti ea [cayenne2.awardspace.us] | im fph rncwc jlzzcfx de xmbema [cayenne5.awardspace.us] | mzdefswtttw ekbdlhds if uhpkhdiu [cayenne5.awardspace.us] | lbi xe cfam ebnitbpbmnieapiim t [cayenne1.awardspace.us] |
Read the rest of this comment...



Re: lsdkfjLaszka (Score: 1)
by KlamPinokioKlam on Saturday, 25 July 2009 @ 09:08:24 EDT
(User Info | Send a Message)

You can syndicate our news using the file backend.php or ultramode.txt


All logos and trademarks in this site are property of their respective owner. The comments are property of their posters, all the rest © 2003-2008 by Clement Dupuis and Nathalie Lambert (Site Maintainers).

 


 

 


Page Generation: 0.25 Seconds