Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 57 guests and 1 member online
 
Free Business and Tech Magazines and eBooks

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow Recommendation for an SQL fuzzer?
EH-Net
May 24, 2013, 04:06:05 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Recommendation for an SQL fuzzer?  (Read 6373 times)
0 Members and 1 Guest are viewing this topic.
H1t M0nk3y
Hero Member
*****
Offline Offline

Posts: 865



View Profile
« on: August 16, 2010, 08:36:39 AM »

Hi,

I am looking for a fuzzer to find SQL Injection vulnerabilities. I have used a few, but I am wondering which one you use?
Logged

OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
Ketchup
Hero Member
*****
Offline Offline

Posts: 1021



View Profile
« Reply #1 on: August 16, 2010, 01:51:49 PM »

WebScarab has a neat fuzzing capability, as most of proxy tools.   W3AF can also do this.  I use SQLMap primarily for automated SQL Inject testing.  I find it to be very flexible and somewhat accurate. 
Logged

~~~~~~~~~~~~~~
Ketchup
H1t M0nk3y
Hero Member
*****
Offline Offline

Posts: 865



View Profile
« Reply #2 on: August 16, 2010, 02:14:46 PM »

Thanks Ketchup.

I have been using WebScarab and SQLMap so far and I was wondering if they were good. I guess they are!
Logged

OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
ajohnson
Recruiters
Hero Member
*
Offline Offline

Posts: 1060


aka dynamik


View Profile WWW
« Reply #3 on: August 16, 2010, 02:54:24 PM »

I don't have a lot of experience with these tools. They need to be used with care as some checks may drop databases or cause other damage, correct?
Logged

WIP: GCFA | www.infosiege.net | @infosiege

The day you stop learning is the day you start becoming obsolete.
Ketchup
Hero Member
*****
Offline Offline

Posts: 1021



View Profile
« Reply #4 on: August 16, 2010, 04:25:34 PM »

That depends on your input entirely.   WebScarab works from a text file template of SQL commands and such.  SQLMap has quite a few payloads, including some MSF webshells.   
Logged

~~~~~~~~~~~~~~
Ketchup
H1t M0nk3y
Hero Member
*****
Offline Offline

Posts: 865



View Profile
« Reply #5 on: August 16, 2010, 05:22:30 PM »

WebScarab as a fuzzer:
http://www.owasp.org/index.php/Fuzzing_with_WebScarab
http://travisaltman.com/webscarab-tutorial-part-3-fuzzing/

And there is plenty of document for SQLMap...
Logged

OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
H1t M0nk3y
Hero Member
*****
Offline Offline

Posts: 865



View Profile
« Reply #6 on: August 17, 2010, 10:31:50 AM »

Would anyone know about a good SQL Injection dictionary? I found an OK one, but I am looking for MySQL, MSSQL and Oracle specific ones...

Also for XSS and XSRF!

Good ones are hard to find...
Logged

OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
H1t M0nk3y
Hero Member
*****
Offline Offline

Posts: 865



View Profile
« Reply #7 on: August 17, 2010, 10:40:22 AM »

As an update, I finally found Injection dictionaries/wordlists at http://www.edge-security.com/wfuzz.php

The source directory of the WFuzz application contains several dictionaries.
Logged

OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
sil
Hero Member
*****
Offline Offline

Posts: 549



View Profile WWW
« Reply #8 on: August 17, 2010, 01:28:06 PM »

sqlninja, sqlmap, pangolin, webscarab, paros and drum roll... curl Wink

curl + your own list + your own values.

I was sent an email from my FW admin yesterday: (Chicken Little style... sky is...) "OMG Someone in Brazil is trying SQL injection attacks..." To which I replied: "Alright, so? Any 200's in the logs?" - 200's being what I thought was obvious - HTTP 200's (a-okay). Needless to say, deer + headlights. Maybe my question was wrong. I should have said, did you check the webserver logs. After explaining what 200's I was looking for, I just said send me the logs, I'll take care of it.

Anyhow, point of that rambling is... Timing. Timing is everything. I like to play around with honeypots, IDS', IPS' which means, the odds of someone coming in the front door with a tool (especially with off the shelf variables) is low. When performing ANYTHING web related, the point of view a pentester from my perspective should be: "timing is everything" where - if possible - keep the attack timing so slow you'll be so low key and blend in because you'll be lost in the sauce. Also hping + curl + decoy hosts does wonders to further get you lost in the sauce.

On the other hand, we have the defensive side to this. Personally I love all of these scanners and the users behind them ESPECIALLY if the end point is a *nix box. Simply because most scanners are so damn noisy, it's easy to whip up a shell script, tail the last few lines of access_log, awk out the connection, sort it, find out if N connection tried to connect to say more than 20 pages in less than a minute, if so, block em Wink Think about it... It literally is close to impossible to plop open 30 pages in ONE minute. I don't care what your ctrl+click skills are.

Logged

ajohnson
Recruiters
Hero Member
*
Offline Offline

Posts: 1060


aka dynamik


View Profile WWW
« Reply #9 on: August 17, 2010, 03:26:03 PM »

Think about it... It literally is close to impossible to plop open 30 pages in ONE minute. I don't care what your ctrl+click skills are.

Not a fan of Fire Gestures? Wink

Ctrl + Right Click + Drag = Selected links in new tabs. Great for forums, Digg, etc.
Logged

WIP: GCFA | www.infosiege.net | @infosiege

The day you stop learning is the day you start becoming obsolete.
sil
Hero Member
*****
Offline Offline

Posts: 549



View Profile WWW
« Reply #10 on: August 17, 2010, 03:55:38 PM »

Think about it... It literally is close to impossible to plop open 30 pages in ONE minute. I don't care what your ctrl+click skills are.

Not a fan of Fire Gestures? Wink

Ctrl + Right Click + Drag = Selected links in new tabs. Great for forums, Digg, etc.

Heh... That reminds me. I was trying to explain to explain this VoIP honeypot I made to someone in government. The goal, figure out what toll-fraudsters are doing, how they're doing it, what they're using, etc... (www.infiltrated.net/arkeos-w-mysql.txt) So I whipped up a quick and dirty shell script to dump data from my honeypot PBX's into a MySQL DB

Code:
mysql> select * from bruteforcers ;
+------------------------------------------+------------+------------+------------+-----------+----------------+----------+
| hostid                                   | start_date | start_time | stop_date  | stop_time | attacker       | attempts |
+------------------------------------------+------------+------------+------------+-----------+----------------+----------+
| e3d8862a1f1457b8722646dbec79d0f4b7e1b2ab | 2010-07-17 | 20:26:08   | 2010-07-17 | 20:44:26  | 220.241.37.123 | 35787    |
+------------------------------------------+------------+------------+------------+-----------+----------------+----------+

So while explaining it, I was asked...

GovWrker: "How do you know they weren't legit attempts..."

ArrogantMe: Oh I don't know... 35,787 attempts in 18 minutes 18 seconds... I can see where they re-attempt connections manually 32x a second. A little bit of meth here, some crackrocks there... Maybe you have yourself a drug problem, not a vishing one"
Logged

hayabusa
Hero Member
*****
Offline Offline

Posts: 1633



View Profile
« Reply #11 on: August 17, 2010, 04:09:54 PM »

ArrogantMe: Oh I don't know... 35,787 attempts in 18 minutes 18 seconds... I can see where they re-attempt connections manually 32x a second. A little bit of meth here, some crackrocks there... Maybe you have yourself a drug problem, not a vishing one"

Hahahaha...!!!  Grin
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.089 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.