Penetration Testing mailing list archives
Re: Checking for SQL Injection
From: "Jorge L. Vazquez" <jlvazquez825 () gmail com>
Date: Fri, 12 Sep 2008 17:49:16 -0400
Glenn Wilkinson wrote:
And if you like Nikto, you should def check out Wikto :) www.sensepost.com/research/wikto/ david lodge wrote:You can try one of them: W3AF, Nikto, Accunetix. W3AF and Nikto are FREE but Accunetix is not!One note here - Nikto isn't a SQL Injection testing tool - it scans web servers for known vulnerabilities; not the content of said servers. dave (current maintainer of Nikto)------------------------------------------------------------------------ This list is sponsored by: Cenzic Top 5 Common Mistakes in Securing Web Applications Get 45 Min Video and PPT Slides www.cenzic.com/landing/securityfocus/hackinar ------------------------------------------------------------------------
what he's trying to say is that nikto won't check the web application for vuln, but the web server itself ------------------------------------------------------------------------ This list is sponsored by: Cenzic Top 5 Common Mistakes in Securing Web Applications Get 45 Min Video and PPT Slides www.cenzic.com/landing/securityfocus/hackinar ------------------------------------------------------------------------
Current thread:
- Checking for SQL Injection GT GERONIMO, Frederick Joseph B. (Sep 02)
- Re: Checking for SQL Injection Serg B (Sep 03)
- RE: Checking for SQL Injection Basha, Arif (Sep 03)
- Re: Checking for SQL Injection Bruno Guerreiro Diniz (Sep 03)
- Re: Checking for SQL Injection david lodge (Sep 10)
- Re: Checking for SQL Injection Glenn Wilkinson (Sep 12)
- Re: Checking for SQL Injection Jorge L. Vazquez (Sep 13)
- Re: Checking for SQL Injection p4ssion (Sep 14)
- RE: Checking for SQL Injection Basha, Arif (Sep 03)
- Re: Checking for SQL Injection Serg B (Sep 03)
- Re: Checking for SQL Injection natron (Sep 03)
- Re: Checking for SQL Injection kevin horvath (Sep 03)