Skip to main content

🎯 BetterSQL - Profesyonel SQL Injection Test Aracı

Logo


📋 İçerik


🔍 Giriş

BetterSQL, SQLMap'tan esinlenerek geliştirilmiş, modern, zeki ve güçlü bir SQL Injection test aracıdır.

Sadece bir link girersiniz - gerisi tamamen otomatiktir.

Separator


🎨 Nedir BetterSQL?

BetterSQL, penetration test uzmanları ve güvenlik araştırmacıları için tasarlanmış, aşağıdaki özelliklerle donatılmış yeni nesil bir araçtır:

Harika Özellikleri

  • Tamamen Otomatik - Hiçbir parametre ayarlamaya gerek yok
  • Dinamik Payload Generator - Her hedef için canlı olarak payload üreir
  • WAF Learning System - WAF'ın reddetme nedenleri öğrenilir ve uyarlanır
  • AI Strategy Engine - Yapay zeka destekli karar sistemi (Zither Mode)
  • 2FA Bypass - İki faktörlü kimlik doğrulama engelleme
  • Checkpoint System - Kesintiye dayanıklı session save/restore
  • OOB Exfiltration - DNS/HTTP Out-of-Band veri çekim

Blog


🚀 Temel Özellikler

1. SQL Injection Türleri

Separator

Klasik Teknikler

  • UNION-based Injection - Sonuç Döndürücü
  • Error-based Injection - Hata Temelli
  • Boolean-based Blind - Boolean Tabanlı
  • Time-based Blind - Zaman Tabanlı
  • Stacked Queries - Yığınlı Sorgular

Modern Teknikler

  • NoSQL Injection - MongoDB, CouchDB, Redis
  • GraphQL Injection - GraphQL Resolver Leakage
  • LDAP Injection - Dizin Servisi
  • XPath Injection - XML Sorgulama
  • XSLT Injection - XML Dönüşüm

API & Modern Uygulamalar

  • JWT Token Bypass - JSON Web Token
  • OData Injection - Microsoft OData
  • SPARQL Injection - Semantic Web
  • HQL Injection - Hibernate
  • Out-of-Band (OOB) - DNS/HTTP Exfiltration

2. Veritabanı Desteği

Veritabanı Destek OOB 2FA
MySQL
PostgreSQL
MSSQL
Oracle
SQLite ⚠️
MongoDB
Firebird
Sybase
Vertica
Snowflake

3. WAF Bypass & Evasion

Separator

Desteklenen WAF'lar:

  • 🛡️ Cloudflare - Comment enjeksiyonu, karakter kodlama
  • 🛡️ Akamai - Polyglot payloads, null byte
  • 🛡️ AWS WAF - Unicode encoding, space replacement
  • 🛡️ Azure WAF - Multibyte karakterler, encoding chains
  • 🛡️ F5 BIG-IP - Advanced evasion, request morphing
  • 🛡️ Google Cloud WAF - Dynamic mutation
  • 🛡️ ModSecurity - Pattern bypass, nested comments

Bypass Stratejileri:

  • Karakter Kodlama (Hex, Unicode, Base64)
  • Yorum Enjeksiyonu (/**/, --, #)
  • Space Değiştirme (+, %20, /**/)
  • Case Variation (Büyük/Küçük Harf)
  • Null Byte Enjeksiyonu
  • Polyglot Payloads
  • Dinamik Mutasyon

4. Akıllı Sistem (Zither Mode)

Hedef sistem zor olduğunda, Zither Mode otomatik olarak:

🤖 Hedef analiz eder
🧠 En uygun stratejiyi belirler
⚡ Dinamik payload üretir
🔄 Başarısızlıktan öğrenir
🎯 Tam otomatik exploit eder

📥 Kurulum

# PyPI'den kur
python -m pip install --upgrade BetterSQLi

# Başlat
bettersql -u "http://hedef.com/page.php?id=1"

Kaynak kodundan çalıştırmak için:

git clone https://github.com/ThT0AltayHR/BetterSQL.git
cd BetterSQL
python BetterSQL.py -u "http://hedef.com/page.php?id=1"

🎮 Kullanım

Basit Kullanım

# Tek satırda - hiç parametre gerek yok!
python BetterSQL.py -u "http://target.com/page.php?id=1"

İleri Kullanım

# Cookie ile
python BetterSQL.py -u "http://target.com/page.php?id=1" --cookie="PHPSESSID=xyz"

# Custom header ile
python BetterSQL.py -u "http://target.com/api/user" --header="Authorization: Bearer token"

# POST data ile
python BetterSQL.py -u "http://target.com/login" --data="username=admin&password=test"

# Zither Mode (AI)
python BetterSQL.py -u "http://target.com/page.php?id=1" --zither

📊 Log Formatı

[22:30:43](TR) [INFO] BetterSQL hazırlanıyor...
[22:30:45](TR) [SCAN] SQL Injection test başlıyor...
[22:30:46](TR) [UNION] UNION SELECT payload gönderiliyor...
[22:30:48](TR) [✓] Zafiyetli parametreler bulundu: id
[22:30:50](TR) [DATABASE] MySQL 8.0.23 tespit edildi
[22:30:52](TR) [DUMP] Tablo çekimi başlıyor...
  ... users (356 rows)
  ... products (1,024 rows)
  ... sessions (128 rows)
[22:35:12](TR) [✓] Dump tamamlandı! 1,508 kayıt çekildi.

🔐 Lisans

╔════════════════════════════════════════════════════════════════╗
║  BetterSQL - Uluslararası Koruma Lisansı (UKSL-2026)         ║
║                                                                ║
║  ⚠️  KOD DEĞİŞTİRİLEMEZ - Non-Modifiable License             ║
║  ⚠️  EĞİTİM AMAÇLI - Educational Use Only                    ║
║  ⚠️  SAHIBININ İZNİ OLMADAN YAYILANAMAZ                       ║
║                                                                ║
║  Bu araç YASAL penetration testing için tasarlanmıştır.      ║
║  İzinsiz sistemlere erişim SUÇTUR.                           ║
║                                                                ║
║  © 2026 BetterSQL Team                                        ║
╚════════════════════════════════════════════════════════════════╝

📞 Destek


BetterSQL - Daha İyi Güvenlik Testi İçin 🚀

Release files for BetterSQLi 1.3.3

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for BetterSQLi 1.3.3
File Size Uploaded
bettersqli-1.3.3.tar.gz 8.3 MB Details

Built distribution (wheel)

Table of built distributions (wheels) for BetterSQLi 1.3.3
File Interpreter ABI Platform
bettersqli-1.3.3-py3-none-any.whl Python 3 none any Details

Total release size: 16.6 MB

Release files / bettersqli-1.3.3.tar.gz

Download URL bettersqli-1.3.3.tar.gz
Size 8.3 MB
Tags Source
SHA-256 checksum
How to use checksums
c9405c3344a097d56dc875deccf27cee8d4dc0127df4514ffbe9fbdefd7f7668
BLAKE2b-256 checksum
How to use checksums
adb79be4107c69c5994b35b77547ad3b1e213498ed7aff636ed491544326118f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.11

Release files / bettersqli-1.3.3-py3-none-any.whl

Download URL bettersqli-1.3.3-py3-none-any.whl
Size 8.3 MB
Tags Python 3
SHA-256 checksum
How to use checksums
adbf82ee1a1685cd4231624c828dad356df4b4ab5f6cfcd3b91b25d308970b85
BLAKE2b-256 checksum
How to use checksums
550392b3b9b7342e3d593a4a28dc779004c926dac86c42a4dbfcf023a27c82f5
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.11

Release history Release notifications | RSS feed

This release

1.3.3 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page