Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Commit 2c86022

Browse files
committed
added test cases for --sql-query and improved tests for --search -C
1 parent f8267ec commit 2c86022

1 file changed

Lines changed: 125 additions & 0 deletions

File tree

xml/livetests.xml

Lines changed: 125 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -527,8 +527,133 @@
527527
<item value="r'Database: mysql.+Table: plugin.+1 column.+name.+char\(64\)'"/>
528528
</parse>
529529
</case>
530+
<case name="MySQL boolean-based multi-threaded search enumeration - column given tables">
531+
<switches>
532+
<url value="http://debiandev/sqlmap/mysql/get_int.php?id=1"/>
533+
<threads value="4"/>
534+
<tech value="B"/>
535+
<search value="True"/>
536+
<tbl value="users,plugin"/>
537+
<col value="name"/>
538+
<answers value="do you want to dump=N"/>
539+
</switches>
540+
<parse>
541+
<item value="r'Database: testdb.+Table: users.+2 columns.+name.+surname'"/>
542+
<item value="r'Database: mysql.+Table: plugin.+1 column.+name'"/>
543+
</parse>
544+
</case>
545+
<case name="MySQL error-based multi-threaded search enumeration - column given tables">
546+
<switches>
547+
<url value="http://debiandev/sqlmap/mysql/get_int.php?id=1"/>
548+
<threads value="4"/>
549+
<tech value="E"/>
550+
<search value="True"/>
551+
<tbl value="users,plugin"/>
552+
<col value="name"/>
553+
<answers value="do you want to dump=N"/>
554+
</switches>
555+
<parse>
556+
<item value="r'Database: testdb.+Table: users.+2 columns.+name.+varchar\(500\).+surname.+varchar\(1000\)'"/>
557+
<item value="r'Database: mysql.+Table: plugin.+1 column.+name.+char\(64\)'"/>
558+
</parse>
559+
</case>
560+
<case name="MySQL UNION query multi-threaded search enumeration - column given tables">
561+
<switches>
562+
<url value="http://debiandev/sqlmap/mysql/get_int.php?id=1"/>
563+
<threads value="4"/>
564+
<tech value="U"/>
565+
<search value="True"/>
566+
<tbl value="users,plugin"/>
567+
<col value="name"/>
568+
<answers value="do you want to dump=N"/>
569+
</switches>
570+
<parse>
571+
<item value="r'Database: testdb.+Table: users.+2 columns.+name.+varchar\(500\).+surname.+varchar\(1000\)'"/>
572+
<item value="r'Database: mysql.+Table: plugin.+1 column.+name.+char\(64\)'"/>
573+
</parse>
574+
</case>
575+
<case name="MySQL boolean-based multi-threaded search enumeration - column given databases and table">
576+
<switches>
577+
<url value="http://debiandev/sqlmap/mysql/get_int.php?id=1"/>
578+
<threads value="4"/>
579+
<tech value="B"/>
580+
<search value="True"/>
581+
<db value="mysql,testdb"/>
582+
<tbl value="users"/>
583+
<col value="name"/>
584+
<answers value="do you want to dump=N"/>
585+
</switches>
586+
<parse>
587+
<item value="r'Database: testdb.+Table: users.+2 columns.+name.+surname'"/>
588+
</parse>
589+
</case>
590+
<case name="MySQL error-based multi-threaded search enumeration - column given databases and table">
591+
<switches>
592+
<url value="http://debiandev/sqlmap/mysql/get_int.php?id=1"/>
593+
<threads value="4"/>
594+
<tech value="E"/>
595+
<search value="True"/>
596+
<db value="mysql,testdb"/>
597+
<tbl value="users"/>
598+
<col value="name"/>
599+
<answers value="do you want to dump=N"/>
600+
</switches>
601+
<parse>
602+
<item value="r'Database: testdb.+Table: users.+2 columns.+name.+varchar\(500\).+surname.+varchar\(1000\)'"/>
603+
</parse>
604+
</case>
605+
<case name="MySQL UNION query multi-threaded search enumeration - column given databases and table">
606+
<switches>
607+
<url value="http://debiandev/sqlmap/mysql/get_int.php?id=1"/>
608+
<threads value="4"/>
609+
<tech value="U"/>
610+
<search value="True"/>
611+
<db value="mysql,testdb"/>
612+
<tbl value="users"/>
613+
<col value="name"/>
614+
<answers value="do you want to dump=N"/>
615+
</switches>
616+
<parse>
617+
<item value="r'Database: testdb.+Table: users.+2 columns.+name.+varchar\(500\).+surname.+varchar\(1000\)'"/>
618+
</parse>
619+
</case>
530620
<!-- End of search enumeration switches -->
531621

622+
<!-- User's provided statement enumeration switches -->
623+
<case name="MySQL boolean-based multi-threaded custom SQL query enumeration">
624+
<switches>
625+
<url value="http://debiandev/sqlmap/mysql/get_int.php?id=1"/>
626+
<threads value="4"/>
627+
<tech value="B"/>
628+
<query value="SELECT * FROM users LIMIT 0, 2"/>
629+
</switches>
630+
<parse>
631+
<item value="r'SELECT \* FROM users LIMIT 0, 2 \[2\].+1, luther, blissett.+2, fluffy, bunny'"/>
632+
</parse>
633+
</case>
634+
<case name="MySQL error-based multi-threaded custom SQL query enumeration">
635+
<switches>
636+
<url value="http://debiandev/sqlmap/mysql/get_int.php?id=1"/>
637+
<threads value="4"/>
638+
<tech value="E"/>
639+
<query value="SELECT * FROM users LIMIT 0, 2"/>
640+
</switches>
641+
<parse>
642+
<item value="r'SELECT \* FROM users LIMIT 0, 2 \[2\].+1, luther, blissett.+2, fluffy, bunny'"/>
643+
</parse>
644+
</case>
645+
<case name="MySQL UNION query multi-threaded custom SQL query enumeration">
646+
<switches>
647+
<url value="http://debiandev/sqlmap/mysql/get_int.php?id=1"/>
648+
<threads value="4"/>
649+
<tech value="U"/>
650+
<query value="SELECT * FROM users LIMIT 0, 2"/>
651+
</switches>
652+
<parse>
653+
<item value="r'SELECT \* FROM users LIMIT 0, 2 \[2\].+1, luther, blissett.+2, fluffy, bunny'"/>
654+
</parse>
655+
</case>
656+
<!-- End of user's provided statement enumeration switches -->
532657

533658
<!-- Old test cases -->
534659
<case name="MySQL (--technique=E --is-dba --banner --current-user --current-db --dbs --tables -D testdb -T users --columns --dump)">

0 commit comments

Comments
 (0)