Wednesday, July 15, 2009

mssql-hax0r v0.9 – Multi-purpose MS-SQL injection script


Multi-purpose SQL injection script for advanced Microsoft SQL Server exploitation. Three modes of operation are currently available: info (Information Gathering), dump (Record Dump), and brute (Brute Force).

CHANGELOG (v1.0):

  • french language support added (courtesy of )
  • small fix to better handle cookies (for post-auth injections)
  • replaced i=`expr $i + 1` with i=$(($i + 1)) to avoid some fork()s

TODO (v1.0):

  • fix italian language support (test platform needed)
  • info mode: add logins target (master..sysxlogins) [name,dbname,password]
  • brute mode: automatic login grabbing feature?
  • info mode: add sys target (xtype=’S')?
  • info mode: implement better types/keys dumping
  • add a command execution mode via master..xp_cmdshell?
  • add a privileged testing mode for post-auth vulnerabilities
Read More: Here

0 comments:

Post a Comment

Advertisement

Affiliates




Vote For Us

Users Online

Follow US


 

DISCLAIMER

None of the files shown here are hosted or transmitted by this server. The links are provided solely by this site's users. The administrator of this site (7Files) cannot be held responsible for what its users post, or any other actions of its users. You may not use this site to distribute or download any material when you do not have the legal rights to do so. It is your own responsibility to adhere to these terms.