adamdecaf / vulnerabilities

Vulnerability teaching showcase
Other
12 stars 4 forks source link

Useless payloads for Postgres Time Based SQL Injections #2

Closed GoogleCodeExporter closed 9 years ago

GoogleCodeExporter commented 9 years ago
http://code.google.com/p/fuzzdb/source/browse/trunk/attack-payloads/sql-injectio
n/detect/GenericBlind.fuzz.txt?spec=svn138&r=138

The following payloads are totally useless, becase of return type for pg_sleep 
is void and this creates a Postgresql error.

1 or pg_sleep(__TIME__)--
" or pg_sleep(__TIME__)--
' or pg_sleep(__TIME__)--
1) or pg_sleep(__TIME__)--
") or pg_sleep(__TIME__)--
') or pg_sleep(__TIME__)--
1)) or pg_sleep(__TIME__)--
")) or pg_sleep(__TIME__)--
')) or pg_sleep(__TIME__)--

Original issue reported on code.google.com by mesuttimur@gmail.com on 22 Nov 2010 at 1:16