For now check out Version 0.7.. Named searches and Data searches via external config files are now functioning properly as well as other bugs fixed along the way... Drop this in a BT5 VM and make sure you have your DB python stuff installed per the help docs and you should be good to go. If you are looking to use oracle you are going to have to install all the oracle nonsense from oracle or use a BT4r2 vm which has most of the needed drivers minus cxoracle which will need to be installed.
http://consolecowboys.org/pillager/pillage_0.7.zip
Ficti0n$ python pillager.py
[---] The Database Pillager (DBPillage) [---]
[---] CcLabs Release [---]
[---] Authors: Ficti0n, [---]
[---] Contributors: Steponequit [---]
[---] Version: 0.7 [---]
[---] Find Me On Twitter: ficti0n [---]
[---] Homepage: http://console-cowboys.blogspot.com [---]
Release Notes:
--Fixed bugs and optimized code
--Added Docstrings
--Fixed Named and Data searches from config files
About:
The Database Pillager is a multiplatform database tool for searching and browsing common
database platforms encountered while penetration testing. DBPillage can be used to search
for PCI/HIPAA data automatically or use DBPillage to browse databases,display data.
and search for specified tables/data instances.
DBpillage was designed as a post exploitation pillaging tool with a goal of targeted
extraction of data without the use of database platform specific GUI based tools that
are difficult to use and make my job harder.
Supported Platforms:
--------------------
-Oracle
-MSSQL
-MYSQL
-PostGreSQL
Usage Examples:
************************************************************************
For Mysql Postgres and MsSQL pillaging:
---------------------------------------
python dbPillage -a [address] -d [dbType] -u [username] -p [password]
For Oracle pillaging you need a SID connection string:
------------------------------------------------------
python dbPillage-a [address]/[sid] -d [dbType] -u [username] -p [password]
Grab some hashes and Hipaa specific:(Default is PCI)
------------------------------------
python dbPillage -a [address] -d [dbType] -u [username] -p [password] --hashes -s hipaa
Drop into a SQL CMDShell:
-------------------------
python dbpillage.py -a [address] -d [dbType] -u [username] -p [password] -q
Config file specified searches:
-------------------------------
Search for data Items from inputFiles/data.txt:
python dbpillage.py -a [address] -d [dbType] -u [username] -p [password] -D
Search for specific table names from inputFiles/tables.txt:
python dbpillage.py -a [address] -d [dbType] -u [username] -p [password] -N
Switch Options:
---------------------
-# --hashes = grab database password hashes
-l --limit = limit the amount of rows that are searched or when displaying data (options = any number)
-s --searchType = Type of data search you want to perform (options:pci, hipaa, all)(PCI default)
-u --user = Database servers username
-p --pass = Password for the database server
-a --address = Ipaddress of the database server
-d --database = The database type you are pillageing (options: mssql,mysql,oracle,postgres)
-r --report = report format (HTML, XML, screen(default))
-N --nameSearch = Search via inputFiles/tables.txt
-D --dataSearch = Targeted data searches per inputFiles/data.txt
-q --queryShell = Drop into a SQL CMDshell in mysql or mssql
Prerequisites:
-------------
python v2 (Tested on Python 2.5.2 BT4 R2 and BT5 R3 - Oracle stuff on BT4r2 only unless you install the drivers from oracle)
cx_oracle (cx-oracle.sourceforge.net)
psycopg2 (initd.org/psycopg/download/)
MySQLdb (should be on BT by default)
pymssql (should be on BT by default)
More information
- Pentest Tools For Mac
- Hacking Tools Name
- Black Hat Hacker Tools
- Hack Apps
- Hackrf Tools
- Hacking Tools For Windows
- Wifi Hacker Tools For Windows
- Hacking Tools For Windows 7
- Hacking Tools For Kali Linux
- Hacker Tools Software
- Hacker Tools Github
- Hack Tools Download
- Game Hacking
- Pentest Tools Review
- Pentest Tools Open Source
- Best Hacking Tools 2020
- Hacker Tools For Windows
- Hack Tools Online
- Github Hacking Tools
- Hacking Tools Free Download
- Pentest Tools Review
- Hacker Tools For Windows
- Hack Tools For Windows
- Pentest Tools Download
- World No 1 Hacker Software
- Install Pentest Tools Ubuntu
- Pentest Tools Alternative
- Pentest Tools For Mac
- Nsa Hack Tools
- Hacking Tools For Beginners
- Hacking Tools Hardware
- Pentest Tools For Mac
- Hacking Tools For Games
- Best Pentesting Tools 2018
- Hacking Tools And Software
- Pentest Tools Free
- Hack Tools 2019
- Hack Tools Pc
- Pentest Tools Find Subdomains
- Hacking Tools Name
- Hacking Tools Github
- Hacker Tools Mac
- Free Pentest Tools For Windows
- Hacking Tools Download
- Pentest Tools Windows
- Pentest Tools Nmap
- Hacking App
- Hackrf Tools
- Pentest Reporting Tools
- Pentest Tools Kali Linux
- Hacker Tools Apk Download
- Best Pentesting Tools 2018
- Hacking Tools Github
- Pentest Tools List
- Blackhat Hacker Tools
- Hackers Toolbox
- Hacking Tools Windows 10
- Pentest Tools
- Hacking Tools Hardware
- Pentest Tools Kali Linux
- Hacking Tools Windows 10
- Bluetooth Hacking Tools Kali
- What Are Hacking Tools
- Hacking Tools Windows
- Hack Tools For Pc
- Pentest Tools For Windows
- Pentest Tools Tcp Port Scanner
- Hack Tools For Ubuntu
- Computer Hacker
- Hacker Tools Free
- Pentest Tools Linux
- Hacker Tools
- Termux Hacking Tools 2019
- Best Hacking Tools 2020
- Nsa Hacker Tools
- Install Pentest Tools Ubuntu
- Hacker Tools Apk Download
- Hack Tools For Pc
- Hacking App
- Pentest Tools For Android
- Hack Tool Apk No Root
- Hacking Tools Software
- Hacker Tools Free
- What Is Hacking Tools
- Best Hacking Tools 2020
- Hacking Tools Windows 10
- World No 1 Hacker Software
- Hacking Tools For Pc
- Hacker Tools Free Download
- Hak5 Tools
- Install Pentest Tools Ubuntu
- Install Pentest Tools Ubuntu
- Best Pentesting Tools 2018
- Pentest Tools List
- Hacker Tools For Ios
- Pentest Tools Subdomain
- Black Hat Hacker Tools
- Hacking Tools Kit
- Hack Tools 2019
- Pentest Tools Url Fuzzer
- Hack Tools For Mac
- What Are Hacking Tools
- Pentest Tools Free
- Tools For Hacker
- Best Hacking Tools 2020
- Hak5 Tools
- Tools Used For Hacking
- Bluetooth Hacking Tools Kali
- Hacker Hardware Tools
- What Is Hacking Tools
- New Hacker Tools
- How To Install Pentest Tools In Ubuntu
- Hacking Tools Windows
- Hacker Tools Apk
- Tools 4 Hack
- Hacker Security Tools
- Hacker Tools Software
- Hacking Tools Github
- Computer Hacker
- Hacking Tools For Windows Free Download
- Hack Rom Tools
- Hacker Tools Linux
- Hack Apps
- Pentest Tools Windows
- Pentest Tools For Ubuntu
- Hacking Tools Free Download
- Pentest Tools Website
- World No 1 Hacker Software
- Best Hacking Tools 2019
- Hack Tools 2019
- Hack Tools Online
- Pentest Tools Free
- Hacking Tools Online
- Hacker Tools
- Hacking Tools For Games
- Hack Tools Mac
- Pentest Automation Tools
- Hacker Tools
- Hacker Security Tools
- Github Hacking Tools
- Pentest Tools Windows
- Pentest Tools Port Scanner
- Kik Hack Tools
- Pentest Tools Url Fuzzer
- Pentest Tools Framework
- Pentest Tools Bluekeep
- Pentest Tools Website
- Pentest Tools Linux
- Pentest Box Tools Download
- Hackers Toolbox
- Pentest Tools Subdomain
- Best Hacking Tools 2020
- Pentest Tools
- Tools For Hacker
- Pentest Tools For Windows
- Hackers Toolbox
- Hack And Tools