Hacker News new | past | comments | ask | show | jobs | submit login
SQL Injection Tools For Database Pwnage (darkreading.com)
65 points by gkesten on April 12, 2012 | hide | past | favorite | 9 comments



Safe yourself the click (or worded differently, don't give pageviews to this junk).

It is a 10 page slide show. Original title is "Slide Show: 10 SQL Injection Tools For Database Pwnage". There are not even links to the tools.

Here is the print view, all 10 slides in one page: http://www.darkreading.com/taxonomy/index/printarticle/id/23...


I found the sourceforge project page for "the mole" http://sourceforge.net/projects/themole/


I know a site which has sql queries inside its URLs. As this sounds scary to me and I would like to notify the site owners of their potential threat, can I use any of those tools to demonstrate what could possibly happen to them without actually causing any damage?


NO.

If you use any of these tools for that purpose, whether you cause damage or not, you open yourself up to all kinds of liability (legal and civil).

I would recommend sending them an email saying you think there is a security problem, with a good explanation, and make sure to note that you have not tried to exploit it.


If you and the site are located in the United States, it is illegal.


Is it illegal to posses these tools btw?

I know some jurisdictions treat hacking tools the same as burglary tools, which is really dumb if you're just trying to test your own system's security.


No.


We are located in Europe, but I guess I wont try to push my boundaries.


Lots of countries criminalise black hat hacking.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: