00:00
83
More
See all Show me
12. Fast-Track SQLPwnage
3 years ago
The SQLPwnage tool is one of the most useful tools on Fast-Track, the tool essentially scans subnets looking for web servers, once found it automatically starts to crawl the site looking or post parameters (currently SQLPwnage does not support query string parameters). Once a list of post parameters have been identified, Fast-Track will either try blind SQL injection or error based SQL injection and attempt to automatically exploit the system for you. If successful, whatever payload you specified will be delivered to you, this could be meterpreter, reverse shell, bind shell, reverse vnc, and much more. SQLPwnage will automatically re-enable xp cmdshell if disabled, try to elevate permissions, and use the hex to binary bypass explained in the SQL bruter section to deliver our payloads.
This conversation is missing your voice. Take five seconds to join Vimeo or log in.

Advertisement

About this video

MOV
00:01:23
  • 1440x900, 9.31MB
  • Uploaded Sat February 14, 2009
  • Please join or log in to download

Statistics

Date Plays Comments
Totals 5,914 1 0
Feb 15th 0 0 0
Feb 14th 0 0 0
Feb 13th 0 0 0
Feb 12th 1 0 0
Feb 11th 0 0 0
Feb 10th 2 0 0
Feb 9th 0 0 0