[TOOL] BobCat - SQL Injection Exploitation Tool
- From: SecuriTeam <support@xxxxxxxxxxxxxx>
- Date: 5 Feb 2006 12:44:05 +0200
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
The SecuriTeam alerts list - Free, Accurate, Independent.
Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html
- - - - - - - - -
BobCat - SQL Injection Exploitation Tool
------------------------------------------------------------------------
SUMMARY
DETAILS
BobCat is a MS Windows based tool to aid a security consultant in taking
full advantage of SQL injection vulnerabilities. It is based on a tool
named " <http://www.securiteam.com/tools/5HP0W009PO.html> Data Thief" that
was published as PoC by appsecinc. BobCat can exploit SQL injection
bugs/opportunities in web applications, independent of language, but
dependent on MS SQL as the back end DB.
To download the tool:
<http://www.northern-monkee.co.uk/projects/bobcat/bin/BobCat_Alphav0.2.zip> http://www.northern-monkee.co.uk/projects/bobcat/bin/BobCat_Alphav0.2.zip
ADDITIONAL INFORMATION
The information has been provided by <mailto:dave@xxxxxxxxxxxxxxxxxxxxx>
Dave.
To keep updated with the tool visit the project's homepage at:
<http://www.northern-monkee.co.uk/projects/bobcat/bobcat.html>
http://www.northern-monkee.co.uk/projects/bobcat/bobcat.html
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@xxxxxxxxxxxxxx
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@xxxxxxxxxxxxxx
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Prev by Date: [NT] Winamp playlist Buffer Overflow
- Next by Date: [UNIX] IBM Tivoli Access Manager Directory Traversal
- Previous by thread: [NT] Winamp playlist Buffer Overflow
- Next by thread: [UNIX] IBM Tivoli Access Manager Directory Traversal
- Index(es):
Relevant Pages
- [UNIX] Protector System Multiple Vulnerabilities
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... Several classes of vulnerabilities
have been found in Protector. ... cross-site scripting and SQL injection attacks.
... (Securiteam) - [UNIX] PhotoPost PHP Pro Multiple Vulnerabilities
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... PhotoPost PHP Pro suffers
from multiple SQL injection, ... There are plenty of SQL injection vulnerabilities
in PhotoPost PHP Pro. ... (Securiteam) - [REVS] Advanced Topics on SQL Injection Protection
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... SQL injection is now one
of the most common attacks in the Internet. ... Static query statement - Development Phrase
... Some programmers may think escaping apostrophe with two apostrophes (and ...
(Securiteam) - [UNIX] PHPNuke Multiple Vulnerabilities in Search Module
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... cross-site scripting and
SQL injections located throughout the ... The vulnerability exists in the ... The
first SQL injection vulnerability is a non-critical one in the ... (Securiteam) - [UNIX] paFileDB SQL Injection
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... " <http://www.phparena.net/pafiledb.php>
paFileDB is designed to allow web ... The paFileDB product has been found to contain an SQL
Injection ... (Securiteam)