wisemonkeys logo
FeedNotificationProfileManage Forms
FeedNotificationSearchSign in
wisemonkeys logo

Blogs

SQL Injection practice on DVWA

profile
Taha Chatriwala
Nov 04, 2017
0 Likes
0 Discussions
1991 Reads

Please read this article first : How to setup DVWA using XAMPP on a windows 

 
Once you are done with the setup, follow the below steps to try SQL Injection on your DVWA !!! DVWA ( damn vulnerable web application) is one the readymade web application environment used for testing several attacks. It is purely used for educational purposes. We will be showing here how we can perform SQL injection using dvwa.
SQL injection is one of the very old method of system penetrations. It means firing an SQL query in the database and making a database burp out information you desire. Structured query language being well structured has its own flaws which can be exploited. Using certain keywords as mentioned below breaks the query into a set of instructions which can even bypass the password fields. For an instance writing 1'=1-- in the username field after typing username will bypass the password. This means whether password matches or not still give an access. These flaws are obviously no more there as with increasing security there are patches inbuilt in programming now. Still as a developer you can keep in mind while creating date input fields that your need to mention enough conditional checks so that before data is sent over the server it has already been filtered. Go ahead and enjoy the stunts. Not to forget that these are only for educational purpose. Do not ever try it on actual server with any bad intention. As it might lead you behind the bars. Happy learning..!!  

Step 1: Visit the DVWA login page

URL :- " localhost/dvwa/login.php "and login using the username : "admin" and password : "password"   How To Setup DVWA Using XAMPP on Windows  

Step 2 : You will get to this Homepage

  Blind Sql Injection Using DVWA  

Step 3 : Go to security setting option in left and set security level low.

  Blind Sql Injection Using DVWA  

Step 4 : Click on SQL injection option in left.

  Blind Sql Injection Using DVWA  

Step 5 : Write "1" in text box and click on submit.

  Blind Sql Injection Using DVWA  

Step 6 : Write "a' or ''='" in text box and click on submit.

  Blind Sql Injection Using DVWA  

Step 7 : Write "1=1" in text box and click on submit.

  Blind Sql Injection Using DVWA  

Step 8 : Write "1*" in text box and click on submit.

  Blind Sql Injection Using DVWA  

Comments ()


Sign in

Read Next

DISK SCHEDULING

Blog banner

Ethical Issues in Data Science and Role of Data Science in Smart Cities

Blog banner

JUSTICE FOR EVERY “BEZUBAAN ANIMAL”

Blog banner

Why Summer Break Is Important for Emotional and Cognitive Growth?

Blog banner

What Makes a School Safe, Supportive, and Student-Friendly

Blog banner

Some facts about Technology

Blog banner

Memory Management in Operating System

Blog banner

Computer security techniques

Blog banner

ARTICLE ON WRIKE CORPORATION

Blog banner

Linker

Blog banner

How to lose belly fat

Blog banner

Explain website hacking issues

Blog banner

Landslide Hazard

Blog banner

Memory management

Blog banner

Deadlock

Blog banner

Binary Search Tree (BST) in Data Structure

Blog banner

John Titor: The Time Traveler

Blog banner

How Puppet Shows and Role Play Teach Empathy to Preschoolers

Blog banner

Strengthening Active Directory Security

Blog banner

PPT methodology

Blog banner

From Airboat Tours to Fossil Hunting: The Ultimate Arcadia Travel Experience

Blog banner

Decoding the Weave — How to Identify Original Patola Art on a Fabric

Blog banner

Social Engineering Attacks

Blog banner

Install Ubuntu in Vmware

Blog banner

Email Privacy

Blog banner

MoSCoW METHOD IN DATA SCIENCE

Blog banner

Cyber Attacks -- Trends Patterns and Security Countermeasures

Blog banner

Types Of Interrupt

Blog banner

File system implementation

Blog banner

IOT- Internet Of Things

Blog banner

Four Stalls Every Vegetarian Needs To Eat At Outside Vile Parle Station

Blog banner

Top 3 Places To Stay In Vienna

Blog banner

Access management

Blog banner

Phishing

Blog banner

TRIGGERS IN DATABASE

Blog banner

Developments in Modern Operating Systems

Blog banner

Privacy LAWs in IT

Blog banner

Deadlocks in operating system

Blog banner

Types of Big Data

Blog banner

Indian Food

Blog banner

SECURITY RISKS OF REMOTE WORKING

Blog banner

RAID_142

Blog banner