From 7ce49bcf0dbea669176679e57b92a7c69de8631a Mon Sep 17 00:00:00 2001 From: Bernardo Damele Date: Thu, 20 Jan 2011 21:42:55 +0000 Subject: [PATCH] Sorted boundaries so that the ones with parenthesis are tested first - it has to be like this! Adjusted comments accordingly to new UNION-specific tags. --- xml/payloads.xml | 87 ++++++++++++++++++++++++++++++------------------ 1 file changed, 55 insertions(+), 32 deletions(-) diff --git a/xml/payloads.xml b/xml/payloads.xml index 0d2633879..d62c8aad3 100644 --- a/xml/payloads.xml +++ b/xml/payloads.xml @@ -138,6 +138,14 @@ Tag: Sub-tag: Comment to append to the payload, before the suffix. + Sub-tag: + Character to use to bruteforce number of columns in UNION + query SQL injection tests. + + Sub-tag: + Range of columns to test for in UNION query SQL injection + tests. + Sub-tag: How to identify if the injected payload succeeded. @@ -201,6 +209,8 @@ Formats: + + @@ -219,15 +229,6 @@ Formats: - - 1 - 0 - 1,2,3 - 1 - - - - 3 1 @@ -237,15 +238,6 @@ Formats: - - 3 - 1 - 1,2 - 2 - ' - - - 4 1 @@ -255,6 +247,15 @@ Formats: + + 3 + 1 + 1,2 + 2 + ' + + + 5 1 @@ -295,11 +296,11 @@ Formats: 1 - 1 - 1,2 - 2 - ' - AND '[RANDSTR]'='[RANDSTR] + 0 + 1,2,3 + 1 + + @@ -330,12 +331,12 @@ Formats: - 2 + 1 1 1,2 - 3 + 2 ' - AND '[RANDSTR]' LIKE '[RANDSTR] + AND '[RANDSTR]'='[RANDSTR] @@ -369,9 +370,9 @@ Formats: 2 1 1,2 - 4 - " - AND "[RANDSTR]"="[RANDSTR] + 3 + ' + AND '[RANDSTR]' LIKE '[RANDSTR] @@ -402,12 +403,12 @@ Formats: - 3 + 2 1 1,2 - 5 + 4 " - AND "[RANDSTR]" LIKE "[RANDSTR] + AND "[RANDSTR]"="[RANDSTR] @@ -436,6 +437,15 @@ Formats: "))) AND ((("[RANDSTR]" LIKE "[RANDSTR] + + + 3 + 1 + 1,2 + 5 + " + AND "[RANDSTR]" LIKE "[RANDSTR] + @@ -633,6 +643,7 @@ Formats:
Microsoft SQL Server + Windows
@@ -746,6 +757,7 @@ Formats:
Microsoft SQL Server + Windows
@@ -827,6 +839,7 @@ Formats:
Microsoft SQL Server + Windows
@@ -846,6 +859,7 @@ Formats:
Microsoft SQL Server + Windows
@@ -1001,6 +1015,7 @@ Formats:
Microsoft SQL Server + Windows
@@ -1020,6 +1035,7 @@ Formats:
Microsoft SQL Server + Windows
@@ -1162,6 +1178,7 @@ Formats:
Microsoft SQL Server + Windows
@@ -1261,6 +1278,7 @@ Formats:
Microsoft SQL Server + Windows
@@ -1411,6 +1429,7 @@ Formats:
Microsoft SQL Server + Windows
@@ -1717,6 +1736,7 @@ Formats:
Microsoft SQL Server + Windows
@@ -1736,6 +1756,7 @@ Formats:
Microsoft SQL Server + Windows
@@ -1756,6 +1777,7 @@ Formats:
Microsoft SQL Server + Windows
@@ -2017,6 +2039,7 @@ Formats:
Microsoft SQL Server + Windows