🎯 BetterSQL - Profesyonel SQL Injection Test Aracı
📋 İçerik
- Giriş
- Nedir BetterSQL?
- Temel Özellikler
- Kurulum
- Kullanım
- Enjeksiyon Türleri
- Veritabanı Desteği
- WAF Bypass
- Lisans
🔍 Giriş
BetterSQL, SQLMap'tan esinlenerek geliştirilmiş, modern, zeki ve güçlü bir SQL Injection test aracıdır.
Sadece bir link girersiniz - gerisi tamamen otomatiktir.
🎨 Nedir BetterSQL?
BetterSQL, penetration test uzmanları ve güvenlik araştırmacıları için tasarlanmış, aşağıdaki özelliklerle donatılmış yeni nesil bir araçtır:
✨ Harika Özellikleri
- ✅ Tamamen Otomatik - Hiçbir parametre ayarlamaya gerek yok
- ✅ Dinamik Payload Generator - Her hedef için canlı olarak payload üreir
- ✅ WAF Learning System - WAF'ın reddetme nedenleri öğrenilir ve uyarlanır
- ✅ AI Strategy Engine - Yapay zeka destekli karar sistemi (Zither Mode)
- ✅ 2FA Bypass - İki faktörlü kimlik doğrulama engelleme
- ✅ Checkpoint System - Kesintiye dayanıklı session save/restore
- ✅ OOB Exfiltration - DNS/HTTP Out-of-Band veri çekim
🚀 Temel Özellikler
1. SQL Injection Türleri
Klasik Teknikler
- ✓ UNION-based Injection - Sonuç Döndürücü
- ✓ Error-based Injection - Hata Temelli
- ✓ Boolean-based Blind - Boolean Tabanlı
- ✓ Time-based Blind - Zaman Tabanlı
- ✓ Stacked Queries - Yığınlı Sorgular
Modern Teknikler
- ✓ NoSQL Injection - MongoDB, CouchDB, Redis
- ✓ GraphQL Injection - GraphQL Resolver Leakage
- ✓ LDAP Injection - Dizin Servisi
- ✓ XPath Injection - XML Sorgulama
- ✓ XSLT Injection - XML Dönüşüm
API & Modern Uygulamalar
- ✓ JWT Token Bypass - JSON Web Token
- ✓ OData Injection - Microsoft OData
- ✓ SPARQL Injection - Semantic Web
- ✓ HQL Injection - Hibernate
- ✓ Out-of-Band (OOB) - DNS/HTTP Exfiltration
2. Veritabanı Desteği
| Veritabanı | Destek | OOB | 2FA |
|---|---|---|---|
| MySQL | ✅ | ✅ | ✅ |
| PostgreSQL | ✅ | ✅ | ✅ |
| MSSQL | ✅ | ✅ | ✅ |
| Oracle | ✅ | ✅ | ✅ |
| SQLite | ✅ | ⚠️ | ✅ |
| MongoDB | ✅ | ✅ | ✅ |
| Firebird | ✅ | ✅ | ✅ |
| Sybase | ✅ | ✅ | ✅ |
| Vertica | ✅ | ✅ | ✅ |
| Snowflake | ✅ | ✅ | ✅ |
3. WAF Bypass & Evasion
Desteklenen WAF'lar:
- 🛡️ Cloudflare - Comment enjeksiyonu, karakter kodlama
- 🛡️ Akamai - Polyglot payloads, null byte
- 🛡️ AWS WAF - Unicode encoding, space replacement
- 🛡️ Azure WAF - Multibyte karakterler, encoding chains
- 🛡️ F5 BIG-IP - Advanced evasion, request morphing
- 🛡️ Google Cloud WAF - Dynamic mutation
- 🛡️ ModSecurity - Pattern bypass, nested comments
Bypass Stratejileri:
- Karakter Kodlama (Hex, Unicode, Base64)
- Yorum Enjeksiyonu (
/**/,--,#) - Space Değiştirme (
+,%20,/**/) - Case Variation (Büyük/Küçük Harf)
- Null Byte Enjeksiyonu
- Polyglot Payloads
- Dinamik Mutasyon
4. Akıllı Sistem (Zither Mode)
Hedef sistem zor olduğunda, Zither Mode otomatik olarak:
🤖 Hedef analiz eder
🧠 En uygun stratejiyi belirler
⚡ Dinamik payload üretir
🔄 Başarısızlıktan öğrenir
🎯 Tam otomatik exploit eder
📥 Kurulum
# PyPI'den kur
python -m pip install --upgrade BetterSQLi
# Başlat
bettersql -u "http://hedef.com/page.php?id=1"
Kaynak kodundan çalıştırmak için:
git clone https://github.com/ThT0AltayHR/BetterSQL.git
cd BetterSQL
python BetterSQL.py -u "http://hedef.com/page.php?id=1"
🎮 Kullanım
Basit Kullanım
# Tek satırda - hiç parametre gerek yok!
python BetterSQL.py -u "http://target.com/page.php?id=1"
İleri Kullanım
# Cookie ile
python BetterSQL.py -u "http://target.com/page.php?id=1" --cookie="PHPSESSID=xyz"
# Custom header ile
python BetterSQL.py -u "http://target.com/api/user" --header="Authorization: Bearer token"
# POST data ile
python BetterSQL.py -u "http://target.com/login" --data="username=admin&password=test"
# Zither Mode (AI)
python BetterSQL.py -u "http://target.com/page.php?id=1" --zither
📊 Log Formatı
[22:30:43](TR) [INFO] BetterSQL hazırlanıyor...
[22:30:45](TR) [SCAN] SQL Injection test başlıyor...
[22:30:46](TR) [UNION] UNION SELECT payload gönderiliyor...
[22:30:48](TR) [✓] Zafiyetli parametreler bulundu: id
[22:30:50](TR) [DATABASE] MySQL 8.0.23 tespit edildi
[22:30:52](TR) [DUMP] Tablo çekimi başlıyor...
... users (356 rows)
... products (1,024 rows)
... sessions (128 rows)
[22:35:12](TR) [✓] Dump tamamlandı! 1,508 kayıt çekildi.
🔐 Lisans
╔════════════════════════════════════════════════════════════════╗
║ BetterSQL - Uluslararası Koruma Lisansı (UKSL-2026) ║
║ ║
║ ⚠️ KOD DEĞİŞTİRİLEMEZ - Non-Modifiable License ║
║ ⚠️ EĞİTİM AMAÇLI - Educational Use Only ║
║ ⚠️ SAHIBININ İZNİ OLMADAN YAYILANAMAZ ║
║ ║
║ Bu araç YASAL penetration testing için tasarlanmıştır. ║
║ İzinsiz sistemlere erişim SUÇTUR. ║
║ ║
║ © 2026 BetterSQL Team ║
╚════════════════════════════════════════════════════════════════╝
📞 Destek
- 📧 Email: security@bettersql.dev
- 🐛 Bug Report: issues@bettersql.dev
- 📚 Dokümantasyon: https://docs.bettersql.dev
BetterSQL - Daha İyi Güvenlik Testi İçin 🚀
Release files for BetterSQLi 1.3.3
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| bettersqli-1.3.3.tar.gz | 8.3 MB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| bettersqli-1.3.3-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 16.6 MB
Release files / bettersqli-1.3.3.tar.gz
| Download URL | bettersqli-1.3.3.tar.gz |
|---|---|
| Size | 8.3 MB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
c9405c3344a097d56dc875deccf27cee8d4dc0127df4514ffbe9fbdefd7f7668
|
|
BLAKE2b-256 checksum How to use checksums |
adb79be4107c69c5994b35b77547ad3b1e213498ed7aff636ed491544326118f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.11
|
Release files / bettersqli-1.3.3-py3-none-any.whl
| Download URL | bettersqli-1.3.3-py3-none-any.whl |
|---|---|
| Size | 8.3 MB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
adbf82ee1a1685cd4231624c828dad356df4b4ab5f6cfcd3b91b25d308970b85
|
|
BLAKE2b-256 checksum How to use checksums |
550392b3b9b7342e3d593a4a28dc779004c926dac86c42a4dbfcf023a27c82f5
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.11
|