For now check out Version 0.7.. Named searches and Data searches via external config files are now functioning properly as well as other bugs fixed along the way... Drop this in a BT5 VM and make sure you have your DB python stuff installed per the help docs and you should be good to go. If you are looking to use oracle you are going to have to install all the oracle nonsense from oracle or use a BT4r2 vm which has most of the needed drivers minus cxoracle which will need to be installed.
http://consolecowboys.org/pillager/pillage_0.7.zip
Ficti0n$ python pillager.py
[---] The Database Pillager (DBPillage) [---]
[---] CcLabs Release [---]
[---] Authors: Ficti0n, [---]
[---] Contributors: Steponequit [---]
[---] Version: 0.7 [---]
[---] Find Me On Twitter: ficti0n [---]
[---] Homepage: http://console-cowboys.blogspot.com [---]
Release Notes:
--Fixed bugs and optimized code
--Added Docstrings
--Fixed Named and Data searches from config files
About:
The Database Pillager is a multiplatform database tool for searching and browsing common
database platforms encountered while penetration testing. DBPillage can be used to search
for PCI/HIPAA data automatically or use DBPillage to browse databases,display data.
and search for specified tables/data instances.
DBpillage was designed as a post exploitation pillaging tool with a goal of targeted
extraction of data without the use of database platform specific GUI based tools that
are difficult to use and make my job harder.
Supported Platforms:
--------------------
-Oracle
-MSSQL
-MYSQL
-PostGreSQL
Usage Examples:
************************************************************************
For Mysql Postgres and MsSQL pillaging:
---------------------------------------
python dbPillage -a [address] -d [dbType] -u [username] -p [password]
For Oracle pillaging you need a SID connection string:
------------------------------------------------------
python dbPillage-a [address]/[sid] -d [dbType] -u [username] -p [password]
Grab some hashes and Hipaa specific:(Default is PCI)
------------------------------------
python dbPillage -a [address] -d [dbType] -u [username] -p [password] --hashes -s hipaa
Drop into a SQL CMDShell:
-------------------------
python dbpillage.py -a [address] -d [dbType] -u [username] -p [password] -q
Config file specified searches:
-------------------------------
Search for data Items from inputFiles/data.txt:
python dbpillage.py -a [address] -d [dbType] -u [username] -p [password] -D
Search for specific table names from inputFiles/tables.txt:
python dbpillage.py -a [address] -d [dbType] -u [username] -p [password] -N
Switch Options:
---------------------
-# --hashes = grab database password hashes
-l --limit = limit the amount of rows that are searched or when displaying data (options = any number)
-s --searchType = Type of data search you want to perform (options:pci, hipaa, all)(PCI default)
-u --user = Database servers username
-p --pass = Password for the database server
-a --address = Ipaddress of the database server
-d --database = The database type you are pillageing (options: mssql,mysql,oracle,postgres)
-r --report = report format (HTML, XML, screen(default))
-N --nameSearch = Search via inputFiles/tables.txt
-D --dataSearch = Targeted data searches per inputFiles/data.txt
-q --queryShell = Drop into a SQL CMDshell in mysql or mssql
Prerequisites:
-------------
python v2 (Tested on Python 2.5.2 BT4 R2 and BT5 R3 - Oracle stuff on BT4r2 only unless you install the drivers from oracle)
cx_oracle (cx-oracle.sourceforge.net)
psycopg2 (initd.org/psycopg/download/)
MySQLdb (should be on BT by default)
pymssql (should be on BT by default)
Related posts
- Hacking Tools Software
- Blackhat Hacker Tools
- Pentest Tools Bluekeep
- What Are Hacking Tools
- Hacking Tools For Windows
- Black Hat Hacker Tools
- Pentest Tools Subdomain
- Hacker Tools For Mac
- Pentest Tools Open Source
- Hacking Tools Windows
- Hack Tools Online
- What Is Hacking Tools
- Hacker Tools Online
- Kik Hack Tools
- Hack Website Online Tool
- Best Hacking Tools 2019
- Pentest Tools Find Subdomains
- Hacker
- Best Hacking Tools 2020
- Hack Tools For Windows
- Hack Tool Apk
- Black Hat Hacker Tools
- New Hacker Tools
- Android Hack Tools Github
- Nsa Hacker Tools
- Best Hacking Tools 2020
- Hack Tools Download
- Physical Pentest Tools
- Pentest Tools Nmap
- Hacking Tools And Software
- Hacking Tools Mac
- Black Hat Hacker Tools
- Hacking Tools For Kali Linux
- Pentest Tools Github
- Pentest Tools Review
- Hacking Tools For Windows 7
- Hacker Tool Kit
- Hackrf Tools
- Pentest Tools Alternative
- Pentest Tools Website
- How To Hack
- Easy Hack Tools
- Hack And Tools
- Best Pentesting Tools 2018
- Hacker Tools Hardware
- How To Install Pentest Tools In Ubuntu
- Hacking Tools Mac
- Nsa Hack Tools
- Pentest Tools Framework
- Tools For Hacker
- Pentest Tools Bluekeep
- Hacking Tools Github
- Usb Pentest Tools
- New Hack Tools
- Hack Tools Github
- Hacker Tools For Ios
- Hacking Tools For Games
- Pentest Tools List
- Pentest Tools Open Source
- Hacker Techniques Tools And Incident Handling
- Hacking Tools 2020
- Pentest Tools Website Vulnerability
- Hacking Tools Mac
- Growth Hacker Tools
- Hacker
- Hack Tools Online
- Hacker Tools Github
- Hacking Tools
- Hacking Tools For Beginners
- Hacker Tools Free
- Hack Tools For Mac
- Hacker Tools 2020
- Hacker Security Tools
- Free Pentest Tools For Windows
- Hacking Tools Github
- Hack Tools Download
- Blackhat Hacker Tools
- Hacker Tools For Windows
- Hack Tool Apk
- Hacker Tool Kit
- Hacker Security Tools
- Physical Pentest Tools
- Hacking Tools Windows 10
- What Is Hacking Tools
- Tools For Hacker
- How To Install Pentest Tools In Ubuntu
- Best Hacking Tools 2020
- What Are Hacking Tools
- Pentest Tools For Android
- New Hacker Tools
- Hacker Hardware Tools
- Hack Tool Apk No Root
- Hacking Tools 2019
- Hack Tools Mac
- Hacking Tools Hardware
- Pentest Recon Tools
- Game Hacking
- Hack Tool Apk
- Best Pentesting Tools 2018
- Hacking Tools Windows
- Hacking App
- Best Hacking Tools 2019
- Pentest Tools For Android
- How To Hack
- Hacking Tools Windows 10
- Hack Tools
- How To Hack
- Hacker Tools Linux
- Hack Tools For Windows
- Pentest Tools For Mac
- Best Pentesting Tools 2018
- Hacking Tools Download
- Android Hack Tools Github
- Hacking Apps
- Pentest Tools Framework
- Pentest Tools Android
- Hacker Tools For Ios
- Hack Tools Pc
- Pentest Tools Kali Linux
- Hack Rom Tools
- Hacking Tools 2019
- Pentest Tools Review
- Hack Tools Pc
- Pentest Tools Online
- Hacks And Tools
- Hack Tools Github
- Physical Pentest Tools
- Hack App
- Hacker Tools Github
- Hacking Tools And Software
- Hacking Tools For Windows
- How To Hack
- Hacking Tools For Beginners
- Pentest Tools For Windows
- Top Pentest Tools
- Hacker
- Hacker Tools 2019
- Hacker Tools Linux
- Hacker Search Tools
- Game Hacking
- Pentest Tools For Mac
- What Is Hacking Tools
- Pentest Tools Bluekeep
- Hacking Tools For Pc
- New Hack Tools
- Hacker Tool Kit
- Hacker Tools Free
- Hack Tools For Ubuntu
- Hackrf Tools
- Hack Tools
- Hacking Tools For Windows
- Hacking Tools For Mac
- Blackhat Hacker Tools
- Hacking Tools
- Black Hat Hacker Tools
- Hacking Tools For Beginners
- Hacking App
- What Are Hacking Tools
- Pentest Tools Framework
- Hacking Tools Hardware
No comments:
Post a Comment