sqlmap
sqlmap copied to clipboard
DBA password brute-force support on PgSQL/MSSQL
- MSSQL: OPENROWSET
- PgSQL: dblink()
Combine with CVE-2012-2122 (http://seclists.org/oss-sec/2012/q2/493) for MySQL
Example for MsSQL: http://labs.portcullis.co.uk/download/Revelli-OwaspDay2-Rome.pdf (slides 21 & 22)
http://www.secforce.com/blog/2013/01/stacked-based-mssql-blind-injection-bypass-methodology/