diff --git a/lib/techniques/union/use.py b/lib/techniques/union/use.py index a76e338e9..f9acda624 100644 --- a/lib/techniques/union/use.py +++ b/lib/techniques/union/use.py @@ -353,6 +353,7 @@ def unionUse(expression, unpack=True, dump=False): kb.suppressResumeInfo = False if not value: + expression = re.sub("\s*ORDER BY\s+[\w,]+", "", expression, re.I) # full inband doesn't play well with ORDER BY value = __oneShotUnionUse(expression, unpack) duration = calculateDeltaSeconds(start)