so i setup iis and asp support on my laptop, then setup a simple sql on asp with mdb as database then tested vulnerability on access based on cheat sheet online
msaccess does not provide info regarding tables and columns, no schema etc… i set the program to bruteforce tables when it detects an msaccess host,once it finds a table will then get the column count, then will use union to extract data.
-bruteforce tables
-bruteforce columns
-dump data / save and load
because msaccess does not support “limit” function and does not allow subquery with multiple returns, program uses field<>’data1′ and field2<>’data2′, not very stable but works
Try it out:
Download them all at:
http://rapidshare.com/files/287748108/reiluke_tools.zip
password: www.reiluke.i.ph
If computer of u error > “Application failed to initialize properly (0xc000135. Click OK to Terminate the Application”
please download: http://www.microsoft.com/downloads/details.aspx?FamilyId=333325FD-AE52-4E35-B531-508D977D32A6&displaylang=en
No comments:
Post a Comment