sQuo Posted March 11, 2013 Share Posted March 11, 2013 This is the hidden content, please Sign In or Sign Up This is the hidden content, please Sign In or Sign Up This is the hidden content, please Sign In or Sign Up jSQL Injection is a lightweight application used to find database information from a distant server. jSQL is free, open source and cross-platform (Windows, Linux, Mac OS X, Solaris). Version 0.3 features: GET, POST, header, cookie methods Normal, error based, blind, time based algorithms Automatic best algorithm selection Thread control (start/pause/resume/stop) Expose URL calls Simple evasion Data retrieving progression bar Proxy setting Distant file reading Webshell deposit Terminal for webshell commands Configuration backup Updates checking Supports MySQL Next work: + distant table writing [sqli] + distant file writing [sqli] + reverse tcp shell deposit [sqli] + right elevation [sqli] + speed increase (non encoding pass): 50% faster [sqli] + control all running tasks in a tab [gui] # speed test comparison with other injection tools [dev] # automatic code testing (JUnit) [dev] # wiki pages [site] Installation First, install java. Then download the latest jSQL executable and double click on the .jar file to open the main window (or you may type in a terminal: java -jar jsql-injection-v0.2.jar). Forum You can request features and discuss about algorithm, programming and functionality in the discussion group. Injection and local test Running injection requires from you the URL for a local or distant server, and the name of parameter to inject. For a local test, you can save the following PHP code as 'simulate_get.php' and move it to the root folder into your web server (e.g /www), then use http://127.0.0.1/simulate_get.php?lib= in jSQL, and finally click Connect to read the local database safely: This is the hidden content, please Sign In or Sign Up Link to comment Share on other sites More sharing options...
pablitoerpablo Posted March 22, 2013 Share Posted March 22, 2013 Re: jSQL Injection v0.3 - a java tool for automatic database injection. Tutorial para usarlo? Link to comment Share on other sites More sharing options...
sQuo Posted March 22, 2013 Author Share Posted March 22, 2013 Re: jSQL Injection v0.3 - a java tool for automatic database injection. Tutorial para usarlo? google?????????' Link to comment Share on other sites More sharing options...
ascerx Posted March 28, 2013 Share Posted March 28, 2013 Re: jSQL Injection v0.3 - a java tool for automatic database injection. Pues va mejor el havij, la verdad Link to comment Share on other sites More sharing options...
Recommended Posts