DB AppSecurity announced MatriXay, a nifty tool for SQL injection attacks on existing Web databases that also runs through default passwords trying to break into the backend DB. Support for MSSQL, Access, MySQL, Oracle, DB2, Sybase, bruteforce password generation (if you have the CPU cycles).
