SQL Server Injection
Great article and great tools:
http://searchsqlserver.techtarget.com/tip/0,289483,sid87_gci1159434,00.html#
SQL Server Security Hacks
Top 15 free SQL Injection Scanners
http://www.security-hacks.com/2007/05/18/top-15-free-sql-injection-scanners
HP WebInspect performs web application security testing
https://h10078.www1.hp.com/cda/hpms/display/main/hpms_content.jsp?zn=bto&cp=1-11-201-200%5e9570_4000_100__
Wikto: Web Server Assessment Tool
http://www.sensepost.com/research/wikto/
This is a modified version of 'bsqlbfv1.2-th.pl'. This perl script allows extraction of data from Blind SQL Injections. It accepts custom SQL queries as a command line parameter and it works for both integer and string based injections.
http://code.google.com/p/bsqlbf-v2/
Pangolin - Best Sql Injection Tool
http://www.lifedork.com/pangolin-best-sql-injection-tool.html