Penetration Testing mailing list archives

Re: Database pen-testing tools


From: "iko tampan" <tampan () gmail com>
Date: Mon, 28 May 2007 21:25:20 +0700

see some free tools at :
http://www.security-hacks.com/2007/05/18/top-15-free-sql-injection-scanners

:)

---
iko94.blogspot.com

----- Original Message -----
From: "Erin Carroll" <amoeba () amoebazone com>
To: <pen-test () securityfocus com>
Sent: Saturday, May 19, 2007 2:22 AM
Subject: Database pen-testing tools


List members,

Does anyone have some suggestions or experience with database-specific
pen-testing tools that you would recommend? I am by no stretch of the
imagination a DBA (I run at the first sign of the words "Relational
Database") so tools that don't require a large amount of DBA-ish
background
to use to their full potential would be of particular interest.

The database testing market seems to be growing rapidly now and some
recommendations of tools to look at would be useful. I've played around
with
NGSSquirrel, AppSec, have experience with some Oracle-specific tools of
course...and ran into a new player in the market (Securno) at InfoSec
Europe. Just wondering what other players are out there that are effective
or you've played with.


--
Erin Carroll
Moderator
SecurityFocus pen-test list
"Do Not Taunt Happy-Fun Ball"


------------------------------------------------------------------------
This List Sponsored by: Cenzic

Are you using SPI, Watchfire or WhiteHat?
Consider getting clear vision with Cenzic
See HOW Now with our 20/20 program!

http://www.cenzic.com/c/2020
------------------------------------------------------------------------



------------------------------------------------------------------------
This List Sponsored by: Cenzic

Are you using SPI, Watchfire or WhiteHat?
Consider getting clear vision with Cenzic
See HOW Now with our 20/20 program!

http://www.cenzic.com/c/2020
------------------------------------------------------------------------


Current thread: