shack2/SuperSQLInjectionV1
超级SQL注入工具(SSQLInjection)是一款基于HTTP协议自组包的SQL注入工具,采用C#开发,直接操作TCP会话来进行HTTP交互,支持出现在HTTP协议任意位置的SQL注入,支持各种类型的SQL注入,支持HTTPS模式注入;支持以盲注、错误显示、Union注入等方式来获取数据;支持Access/MySQL/SQLServer/Oracle/PostgreSQL/DB2/SQLite/Informix等数据库;支持手动灵活的进行SQL注入绕过,可自定义进行字符替换等绕过注入防护。本工具为渗透测试人员、信息安全工程师等掌握SQL注入技能的人员设计,需要使用人员对SQL注入有一定了解。 observed · 2026-08-28
Health v2 · maintenance only
23/100
- Activity 0
- Release rhythm 8
- Longevity 100
Flags: no_license
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 3452
- days_rel: n/a
- days_push: 2002
- n_releases_24m: 0
Adoption not part of the score
1266 stars · 282 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
SuperSQLInjection (SSQLInjection) is a C#-based GUI SQL injection tool that builds raw HTTP requests over TCP sessions, supporting injection points anywhere in the HTTP protocol including HTTPS. It extracts data via blind, error-based, and Union injection against Access, MySQL, SQLServer, Oracle, PostgreSQL, DB2, SQLite, and Informix, with flexible manual bypass options.
Use cases
- detect and exploit SQL injection vulnerabilities in web applications
- extract data from a database via blind SQL injection
- bypass WAF or injection filters with custom character replacement
- test injection points in HTTP headers, cookies, and body parameters
- dump data from MySQL, Oracle, SQLServer, PostgreSQL and other databases during a pentest
When to choose
- you are a penetration tester who understands SQL injection and wants fine-grained manual control over payloads and bypasses
- you need to exploit injection points in arbitrary parts of HTTP requests, including HTTPS
- you need to extract multibyte-encoded (e.g. Chinese) data under blind injection where other tools fail
When to avoid
- you want a fully automated scanner with minimal SQL injection knowledge
- you need a maintained tool with an active project and license - the homepage domain is for sale and the last release was 2021
- you are on Linux/macOS without a Windows/.NET runtime, since it is a Windows C# GUI application
Facets
application · maturity maintenance
security penetration-testing http-client database security penetration-testing databases web-development windows dotnet sql-injection sqli gui-tool waf-bypass csharp desktop
2 sources
- readme: https://github.com/shack2/SuperSQLInjectionV1 · fetched 2026-08-28 · 4d07097b721b
- homepage: http://www.shack2.org · fetched 2026-08-29 · ea018ce4aeb9
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| shack2/SuperSQLInjectionV1 | main | 23 |
For agents
markdown · JSON · MCP: product_card(name="shack2/SuperSQLInjectionV1")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem