Softpedia
 

MAC CATEGORIES:



GLOBAL PAGES >>
NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
WEEK'S BEST
  • Apple Configurator 1.3
  • Adobe Premiere Pro CC 7.0
  • Adobe After Effects CC ...
  • Java for Mac OS X 2013-...
  • Adobe InDesign CC 9.0
  • Adobe Illustrator CC 17.0
  • Adobe Photoshop CC 14.0
  • Dropbox 2.2.4 / 2.3.15 ...
  • Parallels Desktop 8.0.1...
  • TweetDeck 3.0.2
  • Home > Mac > Developer Tools
     Report malware

    sqlifuzzer 0.6

    Download button

    Downloads: 91  Tell us about an update
    User Rating:
    Rated by:
    NOT RATED
    0 user(s)
    Developer:

    License / Price:

    Size / OS:

    Binary Format:

    Last Updated:

    Category:
    Toby Clarke | More programs
    GPL / FREE
    63 KB / Mac OS X
    -
    October 2nd, 2012, 17:07 UTC [view history]
    Home / Developer Tools

     Read user reviews (0)  Refer to a friend  Subscribe

    sqlifuzzer description

    A CLI based SQL injection web scanner

    sqlifuzzer is a free and open-source command line scanner that was designed to identify SQL injection vulnerabilities. It parses Burp logs to create a list of fuzzable requests, then fuzzes them.

    More specifically, sqlifuzzer is a wrapper for curl written in bash. sqlifuzzer is also a tool that can be used to remotely identify SQL (and XPath) injection vulnerabilities. It does this by sending a range of injection payloads and examining the responses for signs of 'injectability'. If a parameter is vulnerable, sqlifuzzer sends exploit payloads to extract data.

    Note that sqlifuzzer is beta, so don't use it in an environment that matters to you or anyone else. Also, do not use sqlifuzzer to scan hosts without the owner's permission.

    sqlifuzzer is cross-platform and it works on Mac OS X, Windows and Linux.

    Detailed instructions on how to install and use the sqlifuzzer utility on your Mac are available HERE.

    Here are some key features of "sqlifuzzer":

    · Payloads/tests for numeric, string, error and time-based SQL injection
    · Support for MSSQL, MYSQL and Oracle DBMS's
    A range of filter evasion options:
    ORDER BY and UNION SELECT tests on vulnerable parameters to:
    · Conditional tests to extract DBMS info when data extraction via UNION SELECT fails (i.e. no string type columns)
    · Time delay based tests to extract DBMS info when data extraction via conditional methods fails (i.e. fully blind scenarios)
    · Boolean response-based XPath injection testing and data extraction
    · Support for automated detection and testing of parameters in POST URIs and multipart forms
    Scan 'state' maintenance:
    · Optional exclusion of a customizable list of parameters from scanning scope
    · Tracking of parameters scanned and avoidance of re-scanning scanned parameters
    · HTML format output with links/buttons to send Proof of Concept SQL injection requests and links to response difference files and to extracted data

    What's New in This Release: [ read full changelog ]

    · Fixed a bug preventing time based exploitation from being triggered.

     Softpedia guarantees that sqlifuzzer 0.6 is 100% FREE, which means it does not contain any form of malware, including spyware, viruses, trojans and backdoors. [read more >]


    TAGS:

    SQL injection | web scanner | identify SQL vulnerability | SQL | injection | web

    Go to top

    WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

    SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM