sqlninja News
Brought to you by:
icesurfer,
nicoleidecker
Brand new release of sqlninja!
Sqlninja is a tool targeted to exploit SQL Injection vulnerabilities on a web application that uses Microsoft SQL Server as its back-end.
Its main goal is to provide a remote shell on the vulnerable DB server, even in a very hostile environment. It should be used by penetration testers to help and automate the process of taking over a DB Server when a SQL Injection vulnerability has been discovered.
This version features an extended fingerprint engine and a new incremental-style bruteforce flavor that uses the remote DB server resources to crack the 'sa' password.
Check out http://sqlninja.sf.net for more information and a flash demo of the tool in action.