Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

MySQL time-based blind - Parameter replace (bool*int) porblem #1175

Closed
aaxxtt opened this issue Feb 25, 2015 · 6 comments
Closed

MySQL time-based blind - Parameter replace (bool*int) porblem #1175

aaxxtt opened this issue Feb 25, 2015 · 6 comments

Comments

@aaxxtt
Copy link

aaxxtt commented Feb 25, 2015

hey to all
Please help me in my problem
The problem with this type that does not accept the exploitation
When used Temper result
unable to retrieve the number of databases
Is the problem of Sqlmb or exploitation?
thx to all

@aaxxtt aaxxtt changed the title MySQL time-based blind - Parameter replace (bool*int) MySQL time-based blind - Parameter replace (bool*int) porblem Feb 25, 2015
@stamparm
Copy link
Member

What does this mean?

@stamparm
Copy link
Member

It seems that MySQL time-based blind - Parameter replace (bool*int) is indeed an invalid payload. I am not sure how it came here in the first place

@stamparm
Copy link
Member

delayed: SELECT 1 FROM DUAL WHERE ((49>49)*SLEEP(5))
delayed: SELECT 1 FROM DUAL WHERE ((49>48)*SLEEP(5))

also

delayed: SELECT 1 FROM testdb.users WHERE id=((49>49)*SLEEP(5))
delayed: SELECT 1 FROM testdb.users WHERE id=((49>48)*SLEEP(5))

@stamparm
Copy link
Member

@aaxxtt thank you for your report. Replaced that payload with a valid one.

@aaxxtt
Copy link
Author

aaxxtt commented Feb 26, 2015

thx stamparm but when i edit the payload ,sqlmap dnt found MySQL time-based blind - Parameter replace (bool)
can u help me?to slove this problem?

@stamparm
Copy link
Member

that payload is throughly tested on our testing environment. maybe there is no "time-based" injection in the first place at your side?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants