wisemonkeys logo
FeedNotificationProfileManage Forms
FeedNotificationSearchSign in
wisemonkeys logo

Blogs

SQL Injection practice on DVWA

profile
Taha Chatriwala
Nov 04, 2017
0 Likes
0 Discussions
1990 Reads

Please read this article first : How to setup DVWA using XAMPP on a windows 

 
Once you are done with the setup, follow the below steps to try SQL Injection on your DVWA !!! DVWA ( damn vulnerable web application) is one the readymade web application environment used for testing several attacks. It is purely used for educational purposes. We will be showing here how we can perform SQL injection using dvwa.
SQL injection is one of the very old method of system penetrations. It means firing an SQL query in the database and making a database burp out information you desire. Structured query language being well structured has its own flaws which can be exploited. Using certain keywords as mentioned below breaks the query into a set of instructions which can even bypass the password fields. For an instance writing 1'=1-- in the username field after typing username will bypass the password. This means whether password matches or not still give an access. These flaws are obviously no more there as with increasing security there are patches inbuilt in programming now. Still as a developer you can keep in mind while creating date input fields that your need to mention enough conditional checks so that before data is sent over the server it has already been filtered. Go ahead and enjoy the stunts. Not to forget that these are only for educational purpose. Do not ever try it on actual server with any bad intention. As it might lead you behind the bars. Happy learning..!!  

Step 1: Visit the DVWA login page

URL :- " localhost/dvwa/login.php "and login using the username : "admin" and password : "password"   How To Setup DVWA Using XAMPP on Windows  

Step 2 : You will get to this Homepage

  Blind Sql Injection Using DVWA  

Step 3 : Go to security setting option in left and set security level low.

  Blind Sql Injection Using DVWA  

Step 4 : Click on SQL injection option in left.

  Blind Sql Injection Using DVWA  

Step 5 : Write "1" in text box and click on submit.

  Blind Sql Injection Using DVWA  

Step 6 : Write "a' or ''='" in text box and click on submit.

  Blind Sql Injection Using DVWA  

Step 7 : Write "1=1" in text box and click on submit.

  Blind Sql Injection Using DVWA  

Step 8 : Write "1*" in text box and click on submit.

  Blind Sql Injection Using DVWA  

Comments ()


Sign in

Read Next

Python as a tool for data analysis

Blog banner

Exploring Human Factors in Cyber Forensics Investigations.

Blog banner

Malicious softwares

Blog banner

Denial-of-Service and Distributed Denial-of-Service Attack Techniques

Blog banner

INTRODUCTION

Blog banner

Concurrency:Deadlock and Starvation

Blog banner

Microsoft Word

Blog banner

computer security

Blog banner

History of ITIL

Blog banner

Starvation

Blog banner

Risk factors in service transistion

Blog banner

Networking 101: How to Build Meaningful Connections in College

Blog banner

Top 5 Places To Stay And Visit In Berlin, Germany

Blog banner

Virtual memory in os

Blog banner

Man is free by the birth .

Blog banner

File management

Blog banner

The Power of Forensic Watermarking in the Fight Against Content Piracy

Blog banner

"Geographic Information Systems (GIS) and its Applications in Urban Planning"

Blog banner

EVOLUTION OF THE MIRCOPROCESSOR

Blog banner

MySQL

Blog banner

IT service level agreement

Blog banner

KEAP MANAGEMENT SYSTEM

Blog banner

"Audit" In Data Science

Blog banner

Deadlocks

Blog banner

Types of Hackers.

Blog banner

Deadlock and Starvation

Blog banner

Facebook marketing

Blog banner

10 Signs your Computer has Virus

Blog banner

12 Principles of Animation

Blog banner

Evolution of Operating Sytems

Blog banner

Human Error: The weakest link in Cybersecurity

Blog banner

An Overview of Virtual Machines

Blog banner

Disk cache

Blog banner

An Approach To Spyware Detection And Removal

Blog banner

CYBER SECURITY CHALLENGES

Blog banner

Why Kanye West (Now Ye) is the GOAT: A Legacy Beyond Music

Blog banner

Student Grade Calculator in LISP

Blog banner

Ethical Hacking

Blog banner

SQL Injection Techniques

Blog banner

IT GOVERNANCE

Blog banner

Cache memory

Blog banner

Game Theory in Blockchain

Blog banner