wisemonkeys logo
FeedNotificationProfileManage Forms
FeedNotificationSearchSign in
wisemonkeys logo

Blogs

SQL Injection practice on DVWA

profile
Taha Chatriwala
Nov 04, 2017
0 Likes
0 Discussions
1992 Reads

Please read this article first : How to setup DVWA using XAMPP on a windows 

 
Once you are done with the setup, follow the below steps to try SQL Injection on your DVWA !!! DVWA ( damn vulnerable web application) is one the readymade web application environment used for testing several attacks. It is purely used for educational purposes. We will be showing here how we can perform SQL injection using dvwa.
SQL injection is one of the very old method of system penetrations. It means firing an SQL query in the database and making a database burp out information you desire. Structured query language being well structured has its own flaws which can be exploited. Using certain keywords as mentioned below breaks the query into a set of instructions which can even bypass the password fields. For an instance writing 1'=1-- in the username field after typing username will bypass the password. This means whether password matches or not still give an access. These flaws are obviously no more there as with increasing security there are patches inbuilt in programming now. Still as a developer you can keep in mind while creating date input fields that your need to mention enough conditional checks so that before data is sent over the server it has already been filtered. Go ahead and enjoy the stunts. Not to forget that these are only for educational purpose. Do not ever try it on actual server with any bad intention. As it might lead you behind the bars. Happy learning..!!  

Step 1: Visit the DVWA login page

URL :- " localhost/dvwa/login.php "and login using the username : "admin" and password : "password"   How To Setup DVWA Using XAMPP on Windows  

Step 2 : You will get to this Homepage

  Blind Sql Injection Using DVWA  

Step 3 : Go to security setting option in left and set security level low.

  Blind Sql Injection Using DVWA  

Step 4 : Click on SQL injection option in left.

  Blind Sql Injection Using DVWA  

Step 5 : Write "1" in text box and click on submit.

  Blind Sql Injection Using DVWA  

Step 6 : Write "a' or ''='" in text box and click on submit.

  Blind Sql Injection Using DVWA  

Step 7 : Write "1=1" in text box and click on submit.

  Blind Sql Injection Using DVWA  

Step 8 : Write "1*" in text box and click on submit.

  Blind Sql Injection Using DVWA  

Comments ()


Sign in

Read Next

ZOHO

Blog banner

Deadlock and starvation

Blog banner

Impact of social media on the human life

Blog banner

TOGETHER WE CAN CONQUER #team

Blog banner

New Ransomware Encrypts Your Android And Then Changes PIN Lock

Blog banner

MIDDLE CLASS MELODIES!!

Blog banner

Know your Processors!

Blog banner

Data Storytelling: Turning Analysis into Business Action

Blog banner

Are Social Media Paid Campaigns Worth It?

Blog banner

Study of Backdoor and Trojan tools

Blog banner

Dekkers Algorithm

Blog banner

Mumbai famous street food

Blog banner

Information of meesho company

Blog banner

Understanding Business Layer in Data Science

Blog banner

Life

Blog banner

Number Guessing game --lisp

Blog banner

Threads

Blog banner

Virtual Machine

Blog banner

Video games

Blog banner

Memory management

Blog banner

FAMILY WHERE LIFE BEGINS....

Blog banner

Deadlocks

Blog banner

operating system

Blog banner

Multiprocessor and scheduling

Blog banner

Some web vulnerabilities

Blog banner

GOOGLE

Blog banner

Embaded operating system

Blog banner

Uniprocessor scheduling

Blog banner

Who decides your overthinking, anyway?

Blog banner

Game via listing method

Blog banner

Revolutionary AI Tool: ChatGPT

Blog banner

Tableau

Blog banner

What does the Australian summer have in store for your oral health?

Blog banner

The Right way of cooking

Blog banner

Street foods

Blog banner

The Role of Data Provenance and Lineage in Modern Data Science

Blog banner

Pooja Silver

Blog banner

Memory hierarchy

Blog banner

Virtual Memory

Blog banner

Data Exfiltration

Blog banner

Process State

Blog banner

Data Visualization

Blog banner