Absinthe - Automated Blind SQL Injection

Absinthe was designed to automate the process of exploiting blind SQL
injection holes on Microsoft SQL Server. It currently supports SQL
Server, Oracle and Postgres.

LiLith : http forms scanner/injector

LiLith is an http scanner to perform web application audits. This tool
analyses webpages and looks for html <form> tags , which often refer to
dynamic pages that might be subject to sql injection or other flaws.

WIS (Web Injection Scanner)

C:\>wis http://www.someaspsite.com/

Web Injection Scanner (Protype 0.4)
by netXeyes, 2004.05.08 http://www.netXeyes.com security@vip.sina.com
กก

Scanning http://www.someaspsite.com/, Page: Unlimited
Patient, Please....

(001 + 000) Checking: /shownews.asp?newsid=204
SQL Injection Found: /shownews.asp?newsid=204


WED (Web Entry Detector)

enjoy wink.gif