Full Disclosure mailing list archives

Re: FatCat Auto SQLl Injector


From: Julius Kivimäki <julius.kivimaki () gmail com>
Date: Sat, 28 Jan 2012 10:49:36 +0200

How does this compete with already existing tools?

2012/1/28 sandeep k <sandeepk.l337 () gmail com>


This is an automatic SQL Injection tool called as FatCat, Use of FatCat
for testing your web application and exploit your application more deeper.
FatCat Features that help you to extract the Database information, Table
information, and Column information from web application.
Only If it is vulnerable to Mysql SQL Injection Vulnerability.

The user friendly GUI of FatCat and automatically detect the sql
vulnerability and start exploiting vulnerability.

*Features*

1)Normal SQL Injection
2) Double Query SQL Injection

*In Next Version*

1) WAF bypass
2) Cookie Header passing
3) Load File
3) Generating XSS from SQL

*Requirement*

1) PHP Verison 5.3.0
2) Enable file_get_function

*Print Screen *

Click image for larger version Name: fatcat.jpg Views: 6 Size: 15.4 KB ID:
180

*Download*

http://code.google.com/p/fatcat-sql-injector/downloads/list

*Video*

http://dl.dropbox.com/u/18007092/FatCat.swf


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Current thread: