From f06ff42c587098343096be606d549afc3c26a541 Mon Sep 17 00:00:00 2001 From: Miroslav Stampar Date: Fri, 3 Jun 2016 10:42:57 +0200 Subject: [PATCH] This never worked. Not sure who incorporated it (WAITFOR DELAY can't go to SELECT/CASE) --- lib/core/settings.py | 2 +- xml/payloads/05_time_blind.xml | 42 ---------------------------------- 2 files changed, 1 insertion(+), 43 deletions(-) diff --git a/lib/core/settings.py b/lib/core/settings.py index 68bf1a7bf..8fcf62cea 100644 --- a/lib/core/settings.py +++ b/lib/core/settings.py @@ -19,7 +19,7 @@ from lib.core.enums import OS from lib.core.revision import getRevisionNumber # sqlmap version (...) -VERSION = "1.0.6.17" +VERSION = "1.0.6.18" REVISION = getRevisionNumber() STABLE = VERSION.count('.') <= 2 VERSION_STRING = "sqlmap/%s#%s" % (VERSION, "stable" if STABLE else "dev") diff --git a/xml/payloads/05_time_blind.xml b/xml/payloads/05_time_blind.xml index 9aca8f99c..ca328c0be 100644 --- a/xml/payloads/05_time_blind.xml +++ b/xml/payloads/05_time_blind.xml @@ -1418,27 +1418,6 @@ - - Microsoft SQL Server/Sybase time-based blind - Parameter replace - 5 - 3 - 1 - 1,3,9 - 3 - (SELECT (CASE WHEN ([INFERENCE]) THEN WAITFOR DELAY '0:0:[SLEEPTIME]' ELSE [RANDNUM]*(SELECT [RANDNUM] UNION ALL SELECT [RANDNUM1]) END)) - - (SELECT (CASE WHEN ([RANDNUM]=[RANDNUM]) THEN WAITFOR DELAY '0:0:[SLEEPTIME]' ELSE [RANDNUM]*(SELECT [RANDNUM] UNION ALL SELECT [RANDNUM1]) END)) - - - - -
- Microsoft SQL Server - Sybase - Windows -
-
- Microsoft SQL Server/Sybase time-based blind - Parameter replace (heavy queries) 5 @@ -1718,27 +1697,6 @@ - - Microsoft SQL Server/Sybase time-based blind - ORDER BY clause - 5 - 3 - 1 - 2,3 - 1 - ,(SELECT (CASE WHEN ([INFERENCE]) THEN WAITFOR DELAY '0:0:[SLEEPTIME]' ELSE [RANDNUM]*(SELECT [RANDNUM] UNION ALL SELECT [RANDNUM1]) END)) - - ,(SELECT (CASE WHEN ([RANDNUM]=[RANDNUM]) THEN WAITFOR DELAY '0:0:[SLEEPTIME]' ELSE [RANDNUM]*(SELECT [RANDNUM] UNION ALL SELECT [RANDNUM1]) END)) - - - - -
- Microsoft SQL Server - Sybase - Windows -
-
- Microsoft SQL Server/Sybase time-based blind - ORDER BY clause (heavy query) 5