Chinese Injection Tools

I came across a Chinese site earlier today:

Apart from the snazzy Neo picture, it's also harbouring an MS SQL injection tool. I love stumbling across sites like this, because there's no easy way to tell if the site is legitimate, if it's a penetration test tool, something designed to be malicious or they just have a thing for Neo and hacking.


Setting aside the issues of "this tool can be used for evil, as well as good" I thought it might be interesting to take a look at what it does. After a while, I found a Flash demonstration of the program going through its paces, but frankly had no idea what was going on. After checking with a colleague, I think I have a pretty reasonable play by play account of what's happening. I could be horribly wrong, of course.

Warning: lots of Chinese text coming your way.

Let's kick things off with a look at the program itself:

I think the word I'm looking for here is "impenetrable". This next shot is an image of someone attempting to get the name of the database via asking it through http. Unfortunately for them, it doesn't work. Drama!

At this point, they fire up the program. The next picture is our wily hacker trying to find out what kind of database the target is running:

He quickly discovers the target is running a Microsoft MSSQL server:

In the next image, he's digging around in the site to find out various bits and pieces of information he can use to his advantage:

Finally, here's a shot of our persistent offender creating an .asp page on the target server:

As you can imagine, uploading files directly onto the server is not a particularly good thing to have happen.

At this point, our bumpy ride into the wilds of Chinese injection tools ends abruptly, due to the Flash animation refusing to play past the above screenshot. I'm still trying to find out if the program was created by a legit security outfit for penetration testing or if it's Black Hats all the way.

Fun while it lasted, though....

Additional Research: Chris Mannon, Sr. Threat Engineer

