Legacy Knowledge Base
Published Jun. 30, 2025

SQL injection Sleepy user agent attack

Written By

Anishq Sharma

How To articles are not official guidelines or officially supported documentation. They are community-contributed content and may not always reflect the latest updates to Liferay DXP. We welcome your feedback to improve How To articles!

While we make every effort to ensure this Knowledge Base is accurate, it may not always reflect the most recent updates or official guidelines.We appreciate your understanding and encourage you to reach out with any feedback or concerns.

Legacy Article

You are viewing an article from our legacy "FastTrack" publication program, made available for informational purposes. Articles in this program were published without a requirement for independent editing or verification and are provided"as is" without guarantee.

Before using any information from this article, independently verify its suitability for your situation and project.

Issue

  • Liferay does not restrict a URL that has a 'sleepy user agent' query appended to it like:
    https://domain/page?1%2b(select*from(select(sleep(x)))a)%2b=1

Environment

  • Liferay DXP 7.4

Resolution

  • Sleepy user agent payload gets a page in sleep mode(inactive) for x seconds of time, which is not the observed behavior on the Liferay portal.
  • There would be the addition of an SQL query in the User-agent header of the page, which is also False in this case.
  • Hence, this vulnerability is not present on Liferay.

Additional Information

  • In order to check the User-agent header, the user can perform a network analysis of all the requests/responses on the website through Chrome's developer tool.
  • Unofficial Ref: The Sleepy User Agent
Did this article resolve your issue ?

Legacy Knowledge Base