Feature and bug list

131 views
Skip to first unread message

ron...@ymail.com

unread,
Aug 2, 2012, 10:45:04 AM8/2/12
to jsql-in...@googlegroups.com
I tried to build the jSQL tool as easy to use as possible, based on a script and algorithm I have coded previously on a CLI PHP. Java should be a good solution to build together a GUI application and an automatic CLI program, with portability, network coding and thread support. I have tried other big tools like sqlmap or havij but sometimes they give me results I couldn't get, like 'why did you run blind, I know normal injection should works on this page?!' or 'why couldn't you inject that, I know it's working in my browser?!'. You should either expect bugs and problems with GUI and algorithm, you can email them to me or post them here.
Also the source code is on git: https://github.com/ron190/jSQL-Injection

skdra...@gmail.com

unread,
Aug 7, 2012, 3:12:31 AM8/7/12
to jsql-in...@googlegroups.com
hi.i download it but i can't open any thing . How can i run it ? thank you

ron...@ymail.com

unread,
Aug 7, 2012, 6:16:03 AM8/7/12
to jsql-in...@googlegroups.com, skdra...@gmail.com
When you have downloaded et installed Java at java.com, you can normally open java application with a double click on the .jar file. If you can't run the .jar, check first that java is installed with command java -version, then try command java -jar [Jar file Name] in the same directory as the .jar.

If you have a compression tool like Winzip, or Winrar that opens itself when you double click the .jar, you can try to right click on .jar, then Open with... and search the file javaw.exe, in a path like C:\Program Files\Java\jre7\bin\javaw.exe

alv....@gmail.com

unread,
Aug 19, 2012, 2:34:13 AM8/19/12
to jsql-in...@googlegroups.com, skdra...@gmail.com
Your java app JSQL INJECTION is nice and consume less system resources, i have been comparing there quality is other similar program, like HAVIJ 1.16 ,SAFE3QLI,SQLMAP, AND PANGOLINA, yours is simple and easy to use beside is faster in pulling data and less system resource,

What i will be expecting in nest version is 1.2

TIME BASE INJECTION
MULTI THREAD
ABILITY TO BYPASS WAF
BYPASS ILLIGAL UNION
BYPASS MOD SECURITY
ALSO INCLUDE MORE PLATFORM LIKE MSSQL & CFM

alv....@gmail.com

unread,
Aug 19, 2012, 6:59:26 AM8/19/12
to jsql-in...@googlegroups.com
Which of the program is the latest one?

MYSQL INJECTION V1.0 DATED JULY
OR
JSQL INJECTION V0.0 DATED ON AUGUST

ron...@ymail.com

unread,
Aug 19, 2012, 3:14:23 PM8/19/12
to jsql-in...@googlegroups.com
Thank you for your report, I'm glad that the tool works properly, actually reply like yours is important for me to know if there are any problems, or to know if some assumptions are corrects, for example I thought the tool should be fast or efficient in some ways, but nothing is better than someone else confirms it. Also your expectations for the future versions are refering to some features I have already thought of, and maybe they will be included in a future release. Actually I'm working on giving the user the ability to interrupt the process of injection, and that implies some reworking of the application's guts and adding threads' play. Like, you start a connection and you see requests are taking forever to complete, you should be able to stop the connection without closing the window. Also there will always be GUI work to make the tool as painless for the eye and as easy to use as possible, now you can view the next version of the GUI in the screenshot attached. The version of the tool is always numbered in ascending direction, you should stick to the version number to know what is the newest program (i.e I keep it clear until the end: between jsql-injection-v0.0.jar and jsql-injection-v0.1.jar, jsql-injection-v0.1.jar is newer :)
screenshot_gui_v0.2.png

alv....@gmail.com

unread,
Aug 21, 2012, 4:34:18 AM8/21/12
to jsql-in...@googlegroups.com
From the picture of the next version, i dont really see much chnage as you mention, the ability to stop the program without clossing the program, sometime the program stay forever, maybe you should had multi thread and include all the featurs like havij if possible, one great thing about your app is that it does not take system resources, example when i run havij, i my pc make a lot of noise and the power it take, means i can not run other program sametime.

Good luck with your project

Reply all
Reply to author
Forward
0 new messages