sqlninja News
Brought to you by:
icesurfer,
nicoleidecker
Sqlninja is a small penetration testing tool for the exploitation of SQL Injection vulnerabilities on a web application that uses Microsoft SQL Server.
Its main goal is to provide a remote shell on the vulnerable DB server, even in a very hostile environment (i.e.: paranoid firewall settings).
This new release provides the ability of tunneling the shell output into DNS requests, bypassing firewalls with paranoid rules.
It is still an alpha version and there are lots of bugs to be found and fixed, so go ahead and play with it!