DSSS – Damn Small SQLi Scanner

DSSS (Damn Small SQLi Scanner) is a fully functional SQL injection vulnerability scanner (supporting GET and POST parameters) written in under 100 lines of code.

As of optional settings it supports HTTP proxy together with HTTP header values User-AgentReferer and Cookie.

Also Read – SQLMap : Automatic SQL Injection & Database Takeover Tool

Requirements

Python version 2.6.x or 2.7.x is required for running this program.

Sample Runs

$ python dsss.py -h
Damn Small SQLi Scanner (DSSS) < 100 LoC (Lines of Code) #v0.2o
by: Miroslav Stampar (@stamparm)

Usage: dsss.py [options]

Options:

–version show program’s version number and exit
-h, –help show this help message and exit
-u URL, –url=URL Target URL (e.g. “http://www.target.com/page.php?id=1”)
–data=DATA POST data (e.g. “query=test”)
–cookie=COOKIE HTTP Cookie header value
–user-agent=UA HTTP User-Agent header value
–referer=REFERER HTTP Referer header value
–proxy=PROXY HTTP proxy address (e.g. “http://127.0.0.1:8080”)

$ python dsss.py -u “http://testphp.vulnweb.com/artists.php?artist=1”
Damn Small SQLi Scanner (DSSS) < 100 LoC (Lines of Code) #v0.2o
by: Miroslav Stampar (@stamparm)

*scanning GET parameter ‘artist’
(i) GET parameter ‘artist’ could be error SQLi vulnerable (MySQL)
(i) GET parameter ‘artist’ appears to be blind SQLi vulnerable (e.g.: ‘http://t
estphp.vulnweb.com/artists.php?artist=1%20AND%2061%3E60′)
scan results: possible vulnerabilities found

R K

Recent Posts

cp Command: Copy Files and Directories in Linux

The cp command, short for "copy," is the main Linux utility for duplicating files and directories. Whether…

5 days ago

Image OSINT

Introduction In digital investigations, images often hold more information than meets the eye. With the…

5 days ago

cat Command: Read and Combine File Contents in Linux

The cat command short for concatenate, It is a fast and versatile tool for viewing and merging…

6 days ago

Port In Networking

What is a Port? A port in networking acts like a gateway that directs data…

6 days ago

ls Command: List Directory Contents in Linux

The ls command is fundamental for anyone working with Linux. It’s used to display the files and…

6 days ago

pwd Command: Find Your Location in Linux

The pwd (Print Working Directory) command is essential for navigating the Linux filesystem. It instantly shows your…

6 days ago