wisemonkeys logo
FeedNotificationProfileManage Forms
FeedNotificationSearchSign in
wisemonkeys logo

Blogs

SQL Injection practice on DVWA

profile
Taha Chatriwala
Nov 04, 2017
0 Likes
0 Discussions
1991 Reads

Please read this article first : How to setup DVWA using XAMPP on a windows 

 
Once you are done with the setup, follow the below steps to try SQL Injection on your DVWA !!! DVWA ( damn vulnerable web application) is one the readymade web application environment used for testing several attacks. It is purely used for educational purposes. We will be showing here how we can perform SQL injection using dvwa.
SQL injection is one of the very old method of system penetrations. It means firing an SQL query in the database and making a database burp out information you desire. Structured query language being well structured has its own flaws which can be exploited. Using certain keywords as mentioned below breaks the query into a set of instructions which can even bypass the password fields. For an instance writing 1'=1-- in the username field after typing username will bypass the password. This means whether password matches or not still give an access. These flaws are obviously no more there as with increasing security there are patches inbuilt in programming now. Still as a developer you can keep in mind while creating date input fields that your need to mention enough conditional checks so that before data is sent over the server it has already been filtered. Go ahead and enjoy the stunts. Not to forget that these are only for educational purpose. Do not ever try it on actual server with any bad intention. As it might lead you behind the bars. Happy learning..!!  

Step 1: Visit the DVWA login page

URL :- " localhost/dvwa/login.php "and login using the username : "admin" and password : "password"   How To Setup DVWA Using XAMPP on Windows  

Step 2 : You will get to this Homepage

  Blind Sql Injection Using DVWA  

Step 3 : Go to security setting option in left and set security level low.

  Blind Sql Injection Using DVWA  

Step 4 : Click on SQL injection option in left.

  Blind Sql Injection Using DVWA  

Step 5 : Write "1" in text box and click on submit.

  Blind Sql Injection Using DVWA  

Step 6 : Write "a' or ''='" in text box and click on submit.

  Blind Sql Injection Using DVWA  

Step 7 : Write "1=1" in text box and click on submit.

  Blind Sql Injection Using DVWA  

Step 8 : Write "1*" in text box and click on submit.

  Blind Sql Injection Using DVWA  

Comments ()


Sign in

Read Next

Why Consistency in Eating Habits Matters and How Meal Maharaj Makes It Easy

Blog banner

Deadlock

Blog banner

Indian Culture and Tradition

Blog banner

GIS Bharat Maps

Blog banner

Flipkart

Blog banner

Deadlock

Blog banner

Sniffing: A Cyber Security Threat

Blog banner

Data Science in Healthcare: Predicting Diseases

Blog banner

An Overview of Virtual Machines

Blog banner

A MODERN OPERATING SYSTEM

Blog banner

Super Garlicky Tomato Soup with Smashed White Beans

Blog banner

From Websites To Super Apps For Digital User Experience

Blog banner

The Role of Summer Camps in Early Childhood Development

Blog banner

Depression

Blog banner

Interrupts

Blog banner

Veg Mix Pickle

Blog banner

The Sunny Side of Instagram

Blog banner

10 Reasons to date your best friend

Blog banner

Search Marketing In 2026: From Keywords To Credibility And User Intent

Blog banner

Famous Indian dishes that where misunderstood to be Indian

Blog banner

Why Travellers from Miami & Orlando Are Visiting Arcadia for Weekend Getaways?

Blog banner

EdTech (Education Technology)

Blog banner

THE LEGAL ISSUES OF COMPUTER FORENSICS IN INDIA

Blog banner

MEMORY MANAGEMENT

Blog banner

Software Piracy & Online Data Protection in Digital World

Blog banner

Career v/s Job : Choose your passion

Blog banner

Philadelphia Experiment : Was it real?

Blog banner

Deadlock and Starvation in an Operating System

Blog banner

GIS

Blog banner

Modern operating system

Blog banner

Excel records

Blog banner

Cyber Security Control

Blog banner

A BLOG ON MYSQL

Blog banner

Animal’s have my heart

Blog banner

SMARTSHEET MANAGEMENT SYSTEM

Blog banner

Deadlock and Starvation

Blog banner

Shoulders

Blog banner

Apache Spark :- Powerful Data Processing Tool

Blog banner

Bharat Maps

Blog banner

MOBILE DEVICE FORENSIC

Blog banner

Disk Management

Blog banner

Linux

Blog banner