diff --git a/lib/controller/checks.py b/lib/controller/checks.py index 267a903f5..b36c2b3f5 100644 --- a/lib/controller/checks.py +++ b/lib/controller/checks.py @@ -501,6 +501,12 @@ def checkSqlInjection(place, parameter, value): # Return the injection object if injection.place is not None and injection.parameter is not None: + if not conf.dropSetCookie and PAYLOAD.TECHNIQUE.BOOLEAN in injection.data and injection.data[PAYLOAD.TECHNIQUE.BOOLEAN].vector.startswith('OR'): + warnMsg = "in cases like this (OR boolean) please consider usage " + warnMsg += "of switch --drop-set-cookie if you experience any " + warnMsg += "problems during data retrieval" + logger.warn(warnMsg) + injection = checkFalsePositives(injection) return injection else: