For now check out Version 0.7.. Named searches and Data searches via external config files are now functioning properly as well as other bugs fixed along the way... Drop this in a BT5 VM and make sure you have your DB python stuff installed per the help docs and you should be good to go. If you are looking to use oracle you are going to have to install all the oracle nonsense from oracle or use a BT4r2 vm which has most of the needed drivers minus cxoracle which will need to be installed.
http://consolecowboys.org/pillager/pillage_0.7.zip
Ficti0n$ python pillager.py
[---] The Database Pillager (DBPillage) [---]
[---] CcLabs Release [---]
[---] Authors: Ficti0n, [---]
[---] Contributors: Steponequit [---]
[---] Version: 0.7 [---]
[---] Find Me On Twitter: ficti0n [---]
[---] Homepage: http://console-cowboys.blogspot.com [---]
Release Notes:
--Fixed bugs and optimized code
--Added Docstrings
--Fixed Named and Data searches from config files
About:
The Database Pillager is a multiplatform database tool for searching and browsing common
database platforms encountered while penetration testing. DBPillage can be used to search
for PCI/HIPAA data automatically or use DBPillage to browse databases,display data.
and search for specified tables/data instances.
DBpillage was designed as a post exploitation pillaging tool with a goal of targeted
extraction of data without the use of database platform specific GUI based tools that
are difficult to use and make my job harder.
Supported Platforms:
--------------------
-Oracle
-MSSQL
-MYSQL
-PostGreSQL
Usage Examples:
************************************************************************
For Mysql Postgres and MsSQL pillaging:
---------------------------------------
python dbPillage -a [address] -d [dbType] -u [username] -p [password]
For Oracle pillaging you need a SID connection string:
------------------------------------------------------
python dbPillage-a [address]/[sid] -d [dbType] -u [username] -p [password]
Grab some hashes and Hipaa specific:(Default is PCI)
------------------------------------
python dbPillage -a [address] -d [dbType] -u [username] -p [password] --hashes -s hipaa
Drop into a SQL CMDShell:
-------------------------
python dbpillage.py -a [address] -d [dbType] -u [username] -p [password] -q
Config file specified searches:
-------------------------------
Search for data Items from inputFiles/data.txt:
python dbpillage.py -a [address] -d [dbType] -u [username] -p [password] -D
Search for specific table names from inputFiles/tables.txt:
python dbpillage.py -a [address] -d [dbType] -u [username] -p [password] -N
Switch Options:
---------------------
-# --hashes = grab database password hashes
-l --limit = limit the amount of rows that are searched or when displaying data (options = any number)
-s --searchType = Type of data search you want to perform (options:pci, hipaa, all)(PCI default)
-u --user = Database servers username
-p --pass = Password for the database server
-a --address = Ipaddress of the database server
-d --database = The database type you are pillageing (options: mssql,mysql,oracle,postgres)
-r --report = report format (HTML, XML, screen(default))
-N --nameSearch = Search via inputFiles/tables.txt
-D --dataSearch = Targeted data searches per inputFiles/data.txt
-q --queryShell = Drop into a SQL CMDshell in mysql or mssql
Prerequisites:
-------------
python v2 (Tested on Python 2.5.2 BT4 R2 and BT5 R3 - Oracle stuff on BT4r2 only unless you install the drivers from oracle)
cx_oracle (cx-oracle.sourceforge.net)
psycopg2 (initd.org/psycopg/download/)
MySQLdb (should be on BT by default)
pymssql (should be on BT by default)
Related posts
- Hacker Techniques Tools And Incident Handling
- Best Hacking Tools 2019
- Pentest Tools Open Source
- Hacking App
- Hacking Tools Software
- Hacking Tools Windows 10
- Hack Tools For Windows
- Hack Tool Apk No Root
- Hacker Tools Online
- Hacking Tools Github
- Hacking Tools Online
- Pentest Tools For Android
- Underground Hacker Sites
- Pentest Recon Tools
- Pentest Tools Linux
- Hacking Tools Usb
- Growth Hacker Tools
- Hacking Tools Windows
- Hacker Tools Hardware
- Hacker Tools Github
- Hack Website Online Tool
- Hacking Tools For Kali Linux
- Hacking Tools For Windows 7
- Hack Apps
- Hacker Tools Hardware
- Pentest Tools Apk
- Hacking Tools Hardware
- Pentest Tools Port Scanner
- Hacking Tools And Software
- Pentest Tools Website
- Hacker
- Hacking App
- Hack Tool Apk
- Pentest Tools Windows
- Pentest Tools Tcp Port Scanner
- Android Hack Tools Github
- Hacker Hardware Tools
- Hacker Tools Apk Download
- How To Install Pentest Tools In Ubuntu
- Hacking Tools Windows
- World No 1 Hacker Software
- New Hack Tools
- Pentest Tools Windows
- Hacking Tools For Windows 7
- Tools For Hacker
- World No 1 Hacker Software
- Pentest Tools Linux
- Hacking Tools And Software
- Nsa Hacker Tools
- Hack Rom Tools
- How To Install Pentest Tools In Ubuntu
- Hack Tools Download
- Hacker Tools Github
- Hacking Tools 2020
- Hackrf Tools
- Pentest Tools Android
- Hacker Techniques Tools And Incident Handling
- Hacking Tools For Windows Free Download
- Hacker Tools Linux
- Hacker Tools Online
- Hack Tools For Games
- Hackers Toolbox
- Hacking Tools Hardware
- Hacker Tools Software
- Hack Tools Pc
- Pentest Tools List
- Pentest Tools Apk
- Nsa Hacker Tools
- Hacker Tools Github
- Hacker Tools Hardware
- Pentest Tools Github
- Hack Tools
- Pentest Tools
- Pentest Tools Url Fuzzer
- Hacker Tools Software
- Pentest Tools Online
- Hacking Tools Software
- Game Hacking
- Best Hacking Tools 2019
- Pentest Tools Bluekeep
- Hack Tools For Games
- Pentest Tools Url Fuzzer
- Black Hat Hacker Tools
- Hacker Tools For Mac
- Hack Tool Apk
- Hacking Tools
- Hack Tools
- Hacks And Tools
- Pentest Tools Linux
- Hacking Tools 2020
- Pentest Tools Subdomain
- Pentest Tools Windows
- Pentest Tools Website Vulnerability
- Computer Hacker
- Hacking Tools Windows
- Pentest Tools Bluekeep
- Pentest Tools Framework
- Hacker Techniques Tools And Incident Handling
- Hack Tool Apk
- Top Pentest Tools
- Best Pentesting Tools 2018
- Hacking Tools Github
- Hacker Techniques Tools And Incident Handling
- Growth Hacker Tools
- Hacker Tools For Windows
- New Hacker Tools
- Hacking Tools Windows
- Hacker Tools List
- Hacker Search Tools
- Hacker Search Tools
- Pentest Tools Tcp Port Scanner
- Hack Tools Mac
- Pentest Tools Url Fuzzer
- Pentest Tools For Mac
- Wifi Hacker Tools For Windows
- Hacking Tools 2019
- Hacking Tools For Windows Free Download
- Pentest Tools Github
- Tools Used For Hacking
- Hacker Tools Software
- Hack Tools
- How To Hack
- Tools For Hacker
- Pentest Tools Linux
- Best Hacking Tools 2020
- Hacker Tools Github
- Hacker Tools 2020
- Physical Pentest Tools
- Hacker Tools 2020
- Hacking Tools Mac
- Hacker Hardware Tools
- Pentest Tools Github
- Hack Tools
- Pentest Reporting Tools
- Pentest Tools Find Subdomains
- Hacking Tools 2019
- Pentest Tools Subdomain
- Hacking Tools For Kali Linux
- New Hack Tools
- Hacking Tools Kit
- Hack Website Online Tool
- Pentest Tools List
- Hacking Tools Mac
- Hacking Tools Software
- Hack Website Online Tool
- Pentest Tools Review
- Hacking Tools
- Hacking Tools Github
- Pentest Tools For Ubuntu
- Hack Tools For Windows
- Github Hacking Tools
- Pentest Tools Online
- Best Hacking Tools 2020
- Hacking Tools Software
- Pentest Tools Find Subdomains
- Kik Hack Tools
- Hack And Tools
- Hacking Tools And Software
- Usb Pentest Tools
- Hacking Tools Software
- Hacker Tools Github
- Tools Used For Hacking
- Hacking Tools For Windows Free Download
- Pentest Tools Kali Linux
- Hacking Tools Kit
- Beginner Hacker Tools
- Hack Tools For Games
- Hacking Tools Download
- Beginner Hacker Tools
- Pentest Tools Url Fuzzer
No comments:
Post a Comment