By Calvin AzuriNT OBJECTives, a provider of accurate Web Application security solutions, has announced that its free NTO SQL Invader tool has been made available. The NTO SQL Invader tool has been designed to deliver pen testers and developers with advanced capabilities for faster exploitation and demonstration of SQL Injection vulnerabilities within Web applications.
Enterprise customers are aware of the risks presented by SQL Injection Vulnerabilities for critical and sensitive data, as it was the primary method used for attacking million of sites and was used for attacking high-profile web applications.
While SQL Injection has been well documented and in spite of the availability of a number of tools that can help in identifying vulnerabilities, it is actually rather difficult to gauge if vulnerabilities can be exploited. This is because SQL Injection testing tools currently in use are deployed from a command line and do not support an intuitive user interface.
The delay in identifying the exploitability of vulnerabilities can lead to delay in remedial efforts and can lead to differences between security and development teams. However, by leveraging the NTO SQL Invader tool, pen testers and developers will now be able to use a vulnerability to track down a list of records as well as user accounts and tables on the back-end database.
NTO SQL Invader operates as a stand-alone tool and can also be integrated with NTOSpider's reporting technology to enable pen testers and developers in identifying exploitability of vulnerabilities.
The free NTO SQL Invader tool from NT OBJECTives comes with a GUI interface which makes it easy for users to paste an injectable request identified by the DAST tool into NTO SQL Invader tool. The user then simply has to select “Start Detecting Injection” which prompts the tool to track down injectable parameter/input.
Additionally, a more comprehensive request can be fed directly into NTO SQL Invader from the BurpSuite or from the NTOSpider report. As soon as an injection is identified, a user can review the amount of information gathered via the GUI interface.
NTO SQL Invader also offers evidence necessary to establish the existence of vulnerabilities in a polished method which can be used in executive meetings and discussions pertaining to remedies. Even a screenshot or video can prove the existence of a vulnerability as the acquisition of data from the back-end database can be reviewed easily for the understanding of both technical and business viewers.
Data which is compiled from NTO SQL Invader can be easily saved into a CSV file which allows reports to be included as evidence in a presentation or POC.