[ Search :

The Mole automatic SQL Injection exploitation tool

The Mole

The Mole is an automatic SQL Injection exploitation tool. Only by providing a vulnerable URL and a valid string on the site it can detect the injection and exploit it, either by using the union technique or a boolean query based technique.
Features

·  Support for injections using Mysql, SQL Server, Postgres and Oracle databases.


·  Command line interface. Different commands trigger different actions.


·  Auto-completion for commands, command arguments and database, table and columns names.


·  Support for filters, in order to bypass certain IPS/IDS rules using generic filters, and the possibility of creating new ones easily.


·  Exploits SQL Injections through GET/POST/Cookie parameters.


·  Developed in python 3.


·  Exploits SQL Injections that return binary data.


·  Powerful command interpreter to simplify its usage.


Download

  • Windows 32bit executable: themole-0.3-win32.zip
  • Tarball-gzipped format: themole-0.3-lin-src.tar.gz
  • Zip format: themole-0.3-win-src.zip
  • Debian(sid)/Ubuntu(11.04+) package: themole_0.3-1_all.deb
  • 0 comments:

    Post a Comment