From copycats and "localizers" of Russian web malware exploitation kits, to suppliers of original hacking tools, the Chinese IT underground has been closely following the emerging threats and the obvious insecurities on a large scale. They are either filling the niches left open by other international communities, or coming up with tools and setting new benchmarks for massive SQL injection attacks, like the case with this one:
”A professional web site vulnerability scanning, use of tools, SQL injection is a new generation of tools to help Web developers and site of the station quickly find vulnerabilities in order to be able to effectively prepare Security work. At the same time, the tool to Web developers to demonstrate the ways in which hackers are using these vulnerabilities, hackers, as well as through the loopholes to do things, can effectively raise the safety awareness of relevant personnel."
Nothing seems wrong with the marketing pitch at first glance, but going through the features, the "massive SQL injections through search engine reconnaissance," and automatic page rank verification which you can see in the attached screenshots, ruin the "security auditing" marketing pitch. The tool not only allows easy integration of potentially vulnerable sites obtained through search engines reconnaissance, but also, is prioritizing the results based on the probability for successful injection, next to the page rank of the domains in question. A simple demonstration offered by the company is also, directly enticing its users to "localize" the search engine reconnaissance, by filtering the search results for a particular country — in this case, they used French sites for one of the demos. Here are some excerpts from its CHANGE log which speak for themselves:
2008.7.15 release version 1.3
New powerful "automatic machine cycle" feature
Automatic machine cycle is to provide assistance to the advanced user manual into the use of a very powerful and flexible module, the main sites used for some special filtering into the hand, is almost a universal tool, you can achieve the following:
1. In support of GET / POST / COOKIES in a variety of ways, such as the injection.
2. Scan the key to the page (background, upload, WebShell, databases, backup files, etc.).
3. According to the dictionary to violence landing back-guess solution WebShell password and password (required to verify that the code can not guess solution).
4. Page language does not limit the types and databases (to provide specific statements into the database).
5. At the same time, support for the circulation of the two variables and two dictionaries, fast running and violent content of the database solution to guess a password.
It gets even more interesting in terms of the massive SQL injection attacks mentality which is pretty evident on all fronts:
The use of the three search engine sites scans to invade the side to complete
The best reverse domain name query engine, and quasi-wide
point into the types of improved detection order to improve the efficiency of detection.
solved from the database to read large amounts of data (on hundreds of thousands or millions of records), the half-way card program will die.
The public version of the tool has been in the wild for over a year, with a VIP version available to customers only.
By Dancho Danchev, Independent Security Consultant. Visit the blog maintained by Dancho Danchev here.
Related topics: Cyberattack, Cybercrime, Malware, Security
To post comments, please login or create an account.
DNSSponsored byNeustar | |
DNS SecuritySponsored byAfilias | |
MobileSponsored bydotMobi | |
Top-Level DomainsSponsored byMinds + Machines |