<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>PHP User-Group Philippines &#187; web applications</title>
	<atom:link href="http://www.phpugph.com/blog/tag/web-applications/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.phpugph.com/blog</link>
	<description></description>
	<lastBuildDate>Wed, 23 Dec 2009 04:00:10 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Scrawlr: Crawls your website for SQL Injection</title>
		<link>http://www.phpugph.com/blog/2008/07/03/scrawlr-crawls-your-website-for-sql-injection/</link>
		<comments>http://www.phpugph.com/blog/2008/07/03/scrawlr-crawls-your-website-for-sql-injection/#comments</comments>
		<pubDate>Thu, 03 Jul 2008 03:16:34 +0000</pubDate>
		<dc:creator>aj</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[Beginner]]></category>
		<category><![CDATA[Intermediate]]></category>
		<category><![CDATA[Software Review]]></category>
		<category><![CDATA[database]]></category>
		<category><![CDATA[injection]]></category>
		<category><![CDATA[MySQL]]></category>
		<category><![CDATA[parameters]]></category>
		<category><![CDATA[sql]]></category>
		<category><![CDATA[web applications]]></category>

		<guid isPermaLink="false">http://www.phpugph.com/blog/?p=43</guid>
		<description><![CDATA[
Scrawlr, short for SQL Injector and Crawler will crawl your website and will analyze the parameters of each individual pages for SQL injection vulnerabilities. Very useful tool for small to medium sized websites. Free for the first 1,500 pages.
From HPs website:
Technical details for Scrawlr

Identify Verbose SQL Injection vulnerabilities in URL parameters
Can be configured to use [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2008/06/23/finding-sql-injection-with-scrawlr.aspx?jumpid=reg_R1002_USEN"><img src="https://download.spidynamics.com/Products/scrawlr/scrawler-screenshot.png" alt="" width="400" height="272" /></a></p>
<p><a href="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2008/06/23/finding-sql-injection-with-scrawlr.aspx?jumpid=reg_R1002_USEN">Scrawlr</a>, short for SQL Injector and Crawler will crawl your website and will analyze the parameters of each individual pages for SQL injection vulnerabilities. Very useful tool for small to medium sized websites. Free for the first 1,500 pages.</p>
<p>From HPs website:</p>
<blockquote><p><em>Technical details for Scrawlr</em></p>
<ul>
<li><em>Identify Verbose SQL Injection vulnerabilities in URL parameters</em></li>
<li><em>Can be configured to use a Proxy to access the web site</em></li>
<li><em>Will identify the type of SQL server in use</em></li>
<li><em>Will extract table names (verbose only) to guarantee no false positives</em></li>
</ul>
<p><em>Scrawlr does have some limitations versus our professional solutions and our fully functional SQL Injector tool<br />
</em></p>
<ul>
<li><em>Will only crawls up to 1500 pages</em></li>
<li><em>Does not support sites requiring authentication</em></li>
<li><em>Does not perform Blind SQL injection</em></li>
<li><em>Cannot retrieve database contents</em></li>
<li><em>Does not support JavaScript or flash parsing</em></li>
<li><em>Will not test forms for SQL Injection (POST Parameters)</em></li>
</ul>
</blockquote>
<p><a href="https://download.spidynamics.com/Products/scrawlr/">It&#8217;s worth trying out.</a></p>
<p>&#8211;aj</p>
<div id="facebook_like"><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.phpugph.com%2Fblog%2F2008%2F07%2F03%2Fscrawlr-crawls-your-website-for-sql-injection%2F&amp;layout=standard&amp;show-faces=true&amp;width=450&amp;action=like&amp;font=arial&amp;colorscheme=light" scrolling="no" frameborder="0" allowTransparency="true" style="border:none; overflow:hidden; width:450px; height:auto;"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.phpugph.com/blog/2008/07/03/scrawlr-crawls-your-website-for-sql-injection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
