RE: Vulnerability scanner for SQL injection, HTML injection- free or commercial ?

From: Cesar (cesarc56_at_yahoo.com)
Date: 09/24/03

  • Next message: Philipp, Roland: "RE: Blocking and allowing ActiveX"
    Date: Tue, 23 Sep 2003 16:21:12 -0700 (PDT)
    To: focus-ms@securityfocus.com
    
    

    Also check out AppDetective for Web Applications:
    http://www.appsecinc.com/products/appdetective/webapps/

    Cesar.
    --- "Harbar, Spencer" <spencer.harbar@dns.co.uk>
    wrote:
    >
    > Check out ScanDo from www.kavado.com, WebInspect
    > from
    > www.spidynamics.com and AppScan from www.sanctum.com
    >
    > hth
    > Spence
    >
    >
    > -----Original Message-----
    > From: Milind Nanal [mailto:milindyn@rolta.com]
    > Sent: 19 September 2003 06:31
    > To: focus-ms@securityfocus.com
    > Subject: Vulnerability scanner for SQL injection,
    > HTML injection- free
    > or commercial ?
    >
    > Hi,
    >
    > Can anyone please tell me information about any
    > vulnerability scanner
    > (free or trial version of commercial scanner) which
    > can scan SQL
    > injection , HTML injection of IIS web server running
    > with MS sql 2000 as
    > a backend database.
    >
    > I get many document on the internet which tell me
    > few default techniques
    > of SQL injection & trying out those to carry out SQL
    > injection test. I
    > am looking out for ready made scanner which has a
    > set of inbuilt
    > commands to carry out SQL , HTML injection attack &
    > give a report ,
    > recommendations to solve the problem.
    >
    > Quick response is appreciated
    >
    > Regards,
    >
    > Milind
    >
    >
    ------------------------------------------------------------------------
    > ---
    >
    ------------------------------------------------------------------------
    > ---
    >
    >
    >
    >
    >
    >
    ---------------------------------------------------------------------------------------------
    > This e-mail was checked and validated by the dns
    > email content management service.
    >
    > For information on how to improve email management
    > for your organisation, please contact
    > sales@dns.co.uk
    >
    ---------------------------------------------------------------------------------------------
    >
    >
    >
    >
    >
    >
    ---------------------------------------------------------------------------
    >
    ---------------------------------------------------------------------------
    >

    __________________________________
    Do you Yahoo!?
    Yahoo! SiteBuilder - Free, easy-to-use web site design software
    http://sitebuilder.yahoo.com

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: Philipp, Roland: "RE: Blocking and allowing ActiveX"

    Relevant Pages

    • Official release of SQL Power Injector 1.2
      ... One of the major improvements is an innovative way to optimize and accelerate the dichotomy in the Blind SQL injection, saving time/number of requests up to 25%. ... Also another great time saver is a new Firefox plugin that will launch SQL Power Injector with all the information of the current webpage with its session context. ... No more time wasted to copy paste the session cookies after you logged... ...
      (Bugtraq)
    • Official release of SQL Power Injector 1.2
      ... One of the major improvements is an innovative way to optimize and accelerate the dichotomy in the Blind SQL injection, saving time/number of requests up to 25%. ... Also another great time saver is a new Firefox plugin that will launch SQL Power Injector with all the information of the current webpage with its session context. ... No more time wasted to copy paste the session cookies after you logged... ...
      (Pen-Test)
    • Official release of SQL Power Injector 1.2
      ... One of the major improvements is an innovative way to optimize and accelerate the dichotomy in the Blind SQL injection, saving time/number of requests up to 25%. ... Also another great time saver is a new Firefox plugin that will launch SQL Power Injector with all the information of the current webpage with its session context. ... No more time wasted to copy paste the session cookies after you logged... ...
      (Security-Basics)
    • Official release of SQL Power Injector 1.1
      ... I have the pleasure to announce that a new version of SQL Power Injector is now officially available on my web site: ... For now it is SQL Server, Oracle and MySQL compliant, but it is possible to use it with any existing DBMS when using the inline injection (Normal ... Response of the SQL injection in a customized browser ...
      (Pen-Test)
    • [Full-disclosure] OTRS 1.x/2.x Multiple Security Issues
      ... OTRS, the Open Source Ticket Request System, is a trouble ... ranging from cross site scripting to SQL injection. ... A malicious user may be able to conduct blind SQL code ... an attacker may be able to exploit this issue. ...
      (Full-Disclosure)