Penetration Testing mailing list archives

Scanning for SQL Injection


From: "Ron Johnson - Adhost" <ron () adhost com>
Date: Thu, 28 Jun 2007 13:06:35 -0700

Hi. I need to scan about 350+ sites from three different web servers that all connect to one MS SQL server for SQL 
injection. Any ideas on how to make this not take a long long time?
 
I like the Priamos tool but you can only scan one site at a time, and you can't load a list of any sort, etc.
 
Any input is appreciated

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Swap Out your SPI or Watchfire app sec solution for
Cenzic's robust, accurate risk assessment and management
solution FREE - limited Time Offer

http://www.cenzic.com/wf-spi
------------------------------------------------------------------------


Current thread: