Web development , php , ajax , symfony, framework, zend
In: web resources
20 Mar 2010SQL injection is a security exploit in which an attacker injects SQL parameters into a Web form, allowing him or her to send database queries and ultimately gain access. SQL injection is not a direct database problem but rather an application issue that indirectly affects your database systems. There are several web application vulnerability scanners to see if any input filtering or other SQL injection-specific holes exist.
SQLFury is the worlds first free online SQL Injection scanner. It is a developer tool written for the Adobe AIR runtime, this application performs SQL injection scans of a target website to identify any SQL injection vulnerabilities. SQLFury utilises blind or inband SQL injection techniques to identify vulnerable targets. If vulnerabilities are found options will be given to extract information from the database using the compromised parameter.
SQLFury works by appending your own SQL statements to a parameter which is not correctly sanitised on the server. Given a parameter with SQL injection vulnerablities SQLFury can extract, Database version, Current database user, database name, table names, columns names and entire columns.
Here are some key features of “SQLFury”:
Database Support:
• MySQL
• PostgreSQL
• Oracle
• Microsoft SQL Server
Extract from database:
• Database version.
• Current database user.
• All database users.
• Database name.
• All database names.
• All table names.
• All columns names.
• Entire columns.

Get SQLFury and test it to see for yourself just how useful it can be for you.
Brought To You By

Do you want to advertise here? Click to get more info…
This blog delivers stylish and dynamic news for designers and web-developers on all subjects of design, ranging from: CSS, Ajax, Javascript, web design, graphics, typography, advertising & much more. Our goal is to help you communicate effectively on the web with an engaging website or functional interface.
2 Responses to Is Your Site Free From SQL Injection?
Sly_Old_Mole
March 21st, 2010 at 11:42 am
no, not really. What version of windows is it?
henrie
May 14th, 2010 at 2:26 am
avg 8.5 is de new version ..i thnk…but it showz out of date some timez..nevermind dat….just activate deauto update option..derz no need 2 wry…