wisemonkeys logo
FeedNotificationProfileManage Forms
FeedNotificationSearchSign in
wisemonkeys logo

Blogs

SQL Injection practice on DVWA

profile
Taha Chatriwala
Nov 04, 2017
0 Likes
0 Discussions
1991 Reads

Please read this article first : How to setup DVWA using XAMPP on a windows 

 
Once you are done with the setup, follow the below steps to try SQL Injection on your DVWA !!! DVWA ( damn vulnerable web application) is one the readymade web application environment used for testing several attacks. It is purely used for educational purposes. We will be showing here how we can perform SQL injection using dvwa.
SQL injection is one of the very old method of system penetrations. It means firing an SQL query in the database and making a database burp out information you desire. Structured query language being well structured has its own flaws which can be exploited. Using certain keywords as mentioned below breaks the query into a set of instructions which can even bypass the password fields. For an instance writing 1'=1-- in the username field after typing username will bypass the password. This means whether password matches or not still give an access. These flaws are obviously no more there as with increasing security there are patches inbuilt in programming now. Still as a developer you can keep in mind while creating date input fields that your need to mention enough conditional checks so that before data is sent over the server it has already been filtered. Go ahead and enjoy the stunts. Not to forget that these are only for educational purpose. Do not ever try it on actual server with any bad intention. As it might lead you behind the bars. Happy learning..!!  

Step 1: Visit the DVWA login page

URL :- " localhost/dvwa/login.php "and login using the username : "admin" and password : "password"   How To Setup DVWA Using XAMPP on Windows  

Step 2 : You will get to this Homepage

  Blind Sql Injection Using DVWA  

Step 3 : Go to security setting option in left and set security level low.

  Blind Sql Injection Using DVWA  

Step 4 : Click on SQL injection option in left.

  Blind Sql Injection Using DVWA  

Step 5 : Write "1" in text box and click on submit.

  Blind Sql Injection Using DVWA  

Step 6 : Write "a' or ''='" in text box and click on submit.

  Blind Sql Injection Using DVWA  

Step 7 : Write "1=1" in text box and click on submit.

  Blind Sql Injection Using DVWA  

Step 8 : Write "1*" in text box and click on submit.

  Blind Sql Injection Using DVWA  

Comments ()


Sign in

Read Next

The Secure Software Development Life Cycle (SDLC)

Blog banner

Data Mining

Blog banner

Phishing

Blog banner

A-B-C of Networking: Part-3 (Topology [Bus & Star])

Blog banner

RACI model in IT services

Blog banner

MACHINE LEARNING

Blog banner

Goa Trip With Friends

Blog banner

Deadlock

Blog banner

Race Condition

Blog banner

Security and E-mail

Blog banner

Functions of operating system

Blog banner

Stories Woven in Silk: The Meaning Behind Patola Motifs

Blog banner

IT GOVERNANCE

Blog banner

Multiprocessor and Multicore Organization

Blog banner

Guidelines for a Low sodium Diet.

Blog banner

How I use google in my daily life

Blog banner

From Websites To Super Apps For Digital User Experience

Blog banner

Electronic data interchange

Blog banner

Operating System Objectives and Functions

Blog banner

10 Interesting facts you should know!!!

Blog banner

Memory Management

Blog banner

Modern Operating system

Blog banner

Thumb Sucking: When It’s Normal and When It Becomes a Dental Problem

Blog banner

Explain website hacking issues

Blog banner

How to use open SSL for web server - browser communication

Blog banner

Operating system

Blog banner

Cyber Forensics on IOT Devices

Blog banner

Decision Tree: A Diagram Model

Blog banner

BENIFITS OF YOGA

Blog banner

differentiate thinking humanly and rationally

Blog banner

VIRTUAL MACHINE

Blog banner

Should you be using a mouthwash? Know from the experts

Blog banner

Facebook marketing

Blog banner

Service Transition Process in ITSM

Blog banner

The Role of Summer Camps in Early Childhood Development

Blog banner

Man is free by the birth .

Blog banner

Deadlock

Blog banner

THREADS (assignment 1)

Blog banner

Data Science in Everyday Life (like a phone, shopping cart, or social media icons)

Blog banner

Smartsheet

Blog banner

Artificial Intelligence and I

Blog banner

Fault tolerance

Blog banner