Is Your Site Free From SQL Injection?

In: web resources

20 Mar 2010

SQL injection is a security exploit in which an attacker injects SQL parameters into a Web form, allowing him or her to send database queries and ultimately gain access. SQL injection is not a direct database problem but rather an application issue that indirectly affects your database systems. There are several web application vulnerability scanners to see if any input filtering or other SQL injection-specific holes exist.

SQLFury is the worlds first free online SQL Injection scanner. It is a developer tool written for the Adobe AIR runtime, this application performs SQL injection scans of a target website to identify any SQL injection vulnerabilities. SQLFury utilises blind or inband SQL injection techniques to identify vulnerable targets. If vulnerabilities are found options will be given to extract information from the database using the compromised parameter.

SQLFury

SQLFury works by appending your own SQL statements to a parameter which is not correctly sanitised on the server. Given a parameter with SQL injection vulnerablities SQLFury can extract, Database version, Current database user, database name, table names, columns names and entire columns.

SQLFury1

Here are some key features of “SQLFury”:

Database Support:
• MySQL
• PostgreSQL
• Oracle
• Microsoft SQL Server

Extract from database:
• Database version.
• Current database user.
• All database users.
• Database name.
• All database names.
• All table names.
• All columns names.
• Entire columns.

SQLFury2

Get SQLFury and test it to see for yourself just how useful it can be for you.

Brought To You By

Premier Survey
Do you want to advertise here? Click to get more info…

Go to Source

2 Responses to Is Your Site Free From SQL Injection?

Avatar

Sly_Old_Mole

March 21st, 2010 at 11:42 am

no, not really. What version of windows is it?

Avatar

henrie

May 14th, 2010 at 2:26 am

avg 8.5 is de new version ..i thnk…but it showz out of date some timez..nevermind dat….just activate deauto update option..derz no need 2 wry…

Comment Form

About this blog

This blog delivers stylish and dynamic news for designers and web-developers on all subjects of design, ranging from: CSS, Ajax, Javascript, web design, graphics, typography, advertising & much more. Our goal is to help you communicate effectively on the web with an engaging website or functional interface.