• Home
  • About
  • Archives
  • Icon Gallery
Subscribe: Posts | Comments | E-mail
  • 'Net Culture
  • Downloads
  • Music
  • PHP/mySQL
  • Teh Funneh
  • Tools
  • Video
  • Web Dev

Snipe.Net

Posted on July 1, 2008 - by snipe

Identify and Fix SQL Injection Vulnerabilities in Web Applications

Featured PHP/mySQL Web Dev Windows Downloads
Identify and Fix SQL Injection Vulnerabilities in Web Applications

Scrawlr is a free software for scanning SQL injection vulnerabilities on your web applications, developed by HP Web Security Research Group in coordination with Microsoft Security Response Center.

Scrawlr crawls a website while simultaneously analyzing the parameters of each individual web page for SQL Injection vulnerabilities.

After the scanning process, if it can find vulnerabilities, it will display your database table names as a proof of the possible SQL injection vulnerabilities.

From the HP Scrawlr website:

Technical details for Scrawlr

  • Identify Verbose SQL Injection vulnerabilities in URL parameters
  • Can be configured to use a Proxy to access the web site
  • Will identify the type of SQL server in use
  • Will extract table names (verbose only) to guarantee no false positives

Scrawlr does have some limitations versus our professional solutions and our fully functional SQL Injector tool

  • Will only crawls up to 1500 pages
  • Does not support sites requiring authentication
  • Does not perform Blind SQL injection
  • Cannot retrieve database contents
  • Does not support JavaScript or flash parsing
  • Will not test forms for SQL Injection (POST Parameters)

There are some limitations, as noted in the above bulleted list, however this is certainly a good start to help web developers find and correct vulnerabilities in their applications. Download Scrawlr now - Windows Only.

Share and Enjoy:
  • Digg
  • del.icio.us
  • Facebook
  • Google
  • E-mail this story to a friend!
  • Furl
  • Ma.gnolia
  • Pownce
  • Reddit
  • Technorati
  • TwitThis

Related Posts

  • Generate lists of banned words for forums and other applications...

  • 1 Star2 Stars3 Stars4 Stars5 Stars (1 votes, average: 4 out of 5)
    Loading ... Loading ...
    This entry was posted on Tuesday, July 1st, 2008 at 11:15 am and is filed under Featured, PHP/mySQL, Web Dev, Windows Downloads. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

    0 Comments

    We'd love to hear yours!



    Leave a Comment

    Here's your chance to speak.

    1. Name (required)

      Mail (required)

      Website

      Message

    Subscribe without commenting

    • Categories

    • What I'm Doing...

      • was stoked about her progress until the US armory server locked her out again. http://apps.facebook.com/wow_toons/ 3 hrs ago
      • is still unsure how she feels about people telling her to increase her personal brand. Marketing people... sheesh... 3 hrs ago
      • is making the WoW Armory and Facebook her bitch while on the bus. The powah! 6 hrs ago
      • More updates...
    • Random Thing You Probably Didn't Know About Me

      • I used to eat instant iced tea mix right out of the container
    • Make With the Clicky!

    • Flickr Photos

    • AJAX/Web 2.0

      • AJAXDaddy
      • Noupe
    • CSS

      • Blueprint CSS
      • Noupe
    • Geek Humor

      • Bash.Org
      • Daily WTF
      • Diesel Sweeties
      • FailBlog
      • Penny Arcade
      • xkcd
    • Graphics

      • Adobe Kuler
      • Iconspedia
      • Photoshop Express
      • Smashing Magazine
    • Life Tools

      • LifeHacker
    • Misc

      • 419 Eater
      • Cellphone PSA Cards
      • Glarkware
      • TehAwesome
      • What’s That Bug?
    • Music

      • Hipster, Please!
      • Jonathan Coulton
      • MC Frontalot
      • MC Lars
      • Optimus Rhyme
    • PHP/mySQL

      • PHPBuilder
      • Zend
    © 2008 Snipe.Net - Bitterness never tasted so sweet
    The Papercut theme by WooThemes - Premium Wordpress Themes