Fedora Linux Support Community & Resources Center

Go Back   FedoraForum.org > Fedora 17/18 > Security and Privacy
FedoraForum Search

Forgot Password? Join Us!

Security and Privacy Sadly, malware, spyware, hackers and privacy threats abound in today's world. Let's be paranoid and secure our penguins, and slam the doors on privacy exploits.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 11th June 2008, 07:15 AM
savage's Avatar
savage Offline
Registered User
 
Join Date: Jun 2005
Location: Mission Control
Posts: 1,229
Scanning for SQL injection vulns

I'm coding a new CMS for my site. While I am making every effort to make sure any user inputted data is escaped properly, I'd still like to remain paranoid and scan for vulnerabilities.

Anybody know of good software for doing this? What do the skiddies use when they go hunting online for vulnerable sites?
Reply With Quote
  #2  
Old 11th June 2008, 12:24 PM
pete_1967 Online
Clueless in a Cuckooland
 
Join Date: Mar 2006
Location: Here now, elsewhere tomorrow.
Posts: 3,922
sqlmap is one that is specifically designed to find them: http://sqlmap.sourceforge.net/

And BackTrack is an excellent distro for white hat cracking: http://www.remote-exploit.org/backtrack.html
__________________
A Drink is Not Just For Christmas - SaskyCom :thumb:


“Give a man a fish; you have fed him for today. Teach a man to fish; and you have fed him for a lifetime” so now go and...
RTFM FIRST: http://docs.fedoraproject.org/ & http://rute.2038bug.com/index.html.gz
Reply With Quote
  #3  
Old 11th June 2008, 07:23 PM
savage's Avatar
savage Offline
Registered User
 
Join Date: Jun 2005
Location: Mission Control
Posts: 1,229
Thanks, I'm playing with sqlmap now, it seems to be exactly what I wanted.

I'll take a look at that distro next weekend, it sounds interesting.
Reply With Quote
  #4  
Old 11th June 2008, 11:42 PM
techmum Offline
Registered User
 
Join Date: Dec 2005
Location: Western Australia
Posts: 267
Wow!

and sqlmap looks perfect for a project here as well

thanks for that link
Reply With Quote
  #5  
Old 12th June 2008, 01:01 PM
kevross_33 Offline
Registered User
 
Join Date: Jun 2008
Posts: 34
http://www.securitycompass.com/exploitme.shtml

Get sqlinject me, a firefox plugin from the security compas site, it opens a nice tool and lets you manually test individual or just launch a ton of sql injection attacks agains all forms on a given page.
Reply With Quote
  #6  
Old 14th June 2008, 04:34 PM
savage's Avatar
savage Offline
Registered User
 
Join Date: Jun 2005
Location: Mission Control
Posts: 1,229
Thanks, I've been playing with that two, both do the job I need, thanks again.
Reply With Quote
Reply

Tags
injection, scanning, sql, vulns

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
IPv6 packet injection Sanych Servers & Networking 0 21st April 2008 07:17 PM
Lan Scanning Help!!!! dreamerchawla Using Fedora 0 22nd March 2008 12:21 AM
WEP Packet Injection with prism2_usb and aircrack-ng tybalt Using Fedora 2 26th January 2007 11:16 AM
Multiple vulns in PHP 4/5 ats-tech Security and Privacy 1 21st December 2004 04:58 PM


Current GMT-time: 06:16 (Monday, 20-05-2013)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
logo

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat