Penetration Testing mailing list archives
Re: Checking for SQL Injection
From: p4ssion <p4ssion () gmail com>
Date: Sat, 13 Sep 2008 17:28:46 -0700
Check the https://sourceforge.net/projects/gamja This scanner will be helpful for finding weak web source, also it will be simply check the xss & sql injection possibility. It's not the tool for sql injection attack but it will be find weak point at web service Nowaday I was developed enhanced GAMJA scanner a few month ago. someday will be submit to sourceforge. Thanks On Fri, Sep 12, 2008 at 2:49 PM, Jorge L. Vazquez <jlvazquez825 () gmail com> wrote:
Glenn Wilkinson wrote:And if you like Nikto, you should def check out Wikto :) www.sensepost.com/research/wikto/ david lodge wrote:You can try one of them: W3AF, Nikto, Accunetix. W3AF and Nikto are FREE but Accunetix is not!One note here - Nikto isn't a SQL Injection testing tool - it scans web servers for known vulnerabilities; not the content of said servers. dave (current maintainer of Nikto)------------------------------------------------------------------------ This list is sponsored by: Cenzic Top 5 Common Mistakes in Securing Web Applications Get 45 Min Video and PPT Slides www.cenzic.com/landing/securityfocus/hackinar ------------------------------------------------------------------------what he's trying to say is that nikto won't check the web application for vuln, but the web server itself ------------------------------------------------------------------------ This list is sponsored by: Cenzic Top 5 Common Mistakes in Securing Web Applications Get 45 Min Video and PPT Slides www.cenzic.com/landing/securityfocus/hackinar ------------------------------------------------------------------------
-- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ p4ssionable Security explorer ! p4ssion E-mail: p4ssion () gmail com , ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ------------------------------------------------------------------------ This list is sponsored by: Cenzic Top 5 Common Mistakes in Securing Web Applications Get 45 Min Video and PPT Slides www.cenzic.com/landing/securityfocus/hackinar ------------------------------------------------------------------------
Current thread:
- Checking for SQL Injection GT GERONIMO, Frederick Joseph B. (Sep 02)
- Re: Checking for SQL Injection Serg B (Sep 03)
- RE: Checking for SQL Injection Basha, Arif (Sep 03)
- Re: Checking for SQL Injection Bruno Guerreiro Diniz (Sep 03)
- Re: Checking for SQL Injection david lodge (Sep 10)
- Re: Checking for SQL Injection Glenn Wilkinson (Sep 12)
- Re: Checking for SQL Injection Jorge L. Vazquez (Sep 13)
- Re: Checking for SQL Injection p4ssion (Sep 14)
- RE: Checking for SQL Injection Basha, Arif (Sep 03)
- Re: Checking for SQL Injection Serg B (Sep 03)
- Re: Checking for SQL Injection natron (Sep 03)
- Re: Checking for SQL Injection kevin horvath (Sep 03)