Eric Posted October 25, 2012 Report Posted October 25, 2012 An easy to use SQL injection tool for retrieving database informations from a distant server. You can discuss about jSQL Injection on the discussion group. jSQL Injection features: GET, POST, header, cookie methodsnormal, error based, blind, time based algorithmsautomatic best algorithms detectiondata retrieving progressionproxy settingevasionFor now supports MySQL. Running injection requires the distant server url and the name of the parameter to inject. If you know an injection should work but the jSQL tool doesn't access the database, you can inform me by email or use the discussion group. For a local test, you can use the following PHP source code with the URL http://127.0.0.1/simulate_get.php?lib= : mysql_connect("localhost", "root", "");mysql_select_db("my_own_database");$result = mysql_query("SELECT * FROM my_own_table where my_own_field = {$_GET['lib']}") # time basedor die( mysql_error() ); # error basedif(mysql_num_rows($result)!==0) echo" true "; # blindwhile ($row = mysql_fetch_array($result, MYSQL_NUM)) echo join(',',$row); # normaljsql-injection - jSQL Injection is a java tool for automatic database injection. - Google Project Hosting Quote