Calendar
März 2009
M D M D F S S
« Feb   Apr »
 1
2345678
9101112131415
16171819202122
23242526272829
3031  

Web Application Testing with Pangolin (Video & Screenshot)

Here is another new video “Web Application Testing with Pangolin” (1024×768).

Similar to the previous video with Matrixay I am using a chinese tool called Pangolin to extract the structure and content of a database (tables, columns, data) via a SQL Injection vulnerability in one of my vulnerable test applications.

Pangolin is a free product but some of the versions of Pangolin on the web are coming with a backdoored libcurl.dll. This can be a dangerous side effect of using free tools in a company environment. You have been warned…

Sometimes it is difficult to find a download possibility of Pangolin because the main website www.nosec.org is currently under construction but if you search a little bit you will be able to find a copy (e.g. via rapidshare). More details concerning Pangolin is available here.

Pangolin Web SQL Injection Tool

Pangolin supports all kind of databases (Oracle, MSSQL, MySQL, Sybase, DB2, …).

More videos can be found in our video section.

2 Antworten auf “Web Application Testing with Pangolin (Video & Screenshot)”

  1. Alexander Kornbrust Oracle Security Blog » Blog Archive » SQL Injection Tool Pangolin 2.0 published sagt:

    […] 5 Mrz 2009: Web Application Testing with Pangolin (Video & Screenshot) […]

  2. Pangolin - The one of the best SQL Injection Tool - Tech Support Forums - TechIMO.com sagt:

    […] (Flash) Oracle Security Videos Web Application Testing with Pangolin (Video & Screenshot) Alexander Kornbrust Oracle Security Blog

Antwort schreiben

Sie müssen als angemeldet sein, um einen Kommentar schreiben zu können.