Damn Vulnerable Web Application

Damn Vulnerable Web Application

Damn Vulnerable Web Application

Dvwa bug hunting lab download

1: Download the XAMPP Server.

Website: https://www.apachefriends.org/download.html

Damn Vulnerable Web Application 1

2: Install the XAMPP Server.

3: Download the DVWA from GitHub.

Website: https://github.com/digininja/DVWA

Damn Vulnerable Web Application 2

4: Extract the DVWA-master folder (Downloaded from GitHub).

5: Copy the DVWA-master folder.

6: Open the XAMPP folder where you installed XAMPP.

7: Then open the htdocs folder in the XAMPP folder.

8: Paste the DVWA-master folder.

9: Rename the DVWA-master folder to dvwa.

Damn Vulnerable Web Application 3

10: Open the dvwa folder.

11: Open the config folder in the dvwa folder.

12: Rename the config.inc.php.dist  file to config.inc.php

Damn Vulnerable Web Application 4

13: Download Notepad++.

Website: https://notepad-plus-plus.org/downloads/

Damn Vulnerable Web Application 5

14: Open the config.inc.php file into the Notepad++.

Damn Vulnerable Web Application 6

15: Open the XAMPP.

16: Start the Apache and MySQL.

17: Open the MySQL Admin.

Damn Vulnerable Web Application 7

18: Go to the User accounts.

Link: http://localhost/phpmyadmin/index.php?route=/server/privileges&viewing_mode=server&lang=en

19: Open the Add new user account.

Damn Vulnerable Web Application 8

20: Set up the Username, Host name and Password.

Damn Vulnerable Web Application 9

21: Also, change the config.inc.php file password.

22: Save the config.inc.php file.

Damn Vulnerable Web Application 10

23: Restart the Apache and MySQL in the XAMPP Control Panel.

24: Open the DVWA.

Website: http://localhost/dvwa

25: Log in to the DVWA account.

Damn Vulnerable Web Application 11

26: Username and Password?

Username: dvwa

Password: dvwa

27: Create the Database.

Damn Vulnerable Web Application 12

28: Log in to the DVWA again.

Username: admin

Password: password

Damn Vulnerable Web Application 13

dvwa brute force

1: Open the XAMPP Control Panel.

2: Activate the Apache and MySQL.

DVWA brute force attack 1

3: Open the DVWA in the Firefox browser and connect with Burp Suite.

Link: http://localhost/dvwa/vulnerabilities/brute/

DVWA brute force attack 2

4:  On the Intercept and then send the Request.

DVWA brute force attack 3

5: Send the Request to the Intruder for the Brute force attack.

Shortcutkey: Ctrl + I

DVWA brute force attack 4

6: Clear the Payload Positions.

7: Select the password and Add$ it.

DVWA brute force attack 5

8: Go to the Payloads section.

9: Add the password lists or type the password manually.

DVWA brute force attack 6

10: Change the DVWA Security Level to Low.

DVWA brute force attack 7

11: Start the Bruce force attack.

12: Here is the Password.

DVWA brute force attack 8

DVWA File Upload

1: Open the XAMPP Control Panel.

2: Activate the Apache and MySQL.

DVWA File Upload 1

3: Change the DVWA Security to Level Low.

DVWA File Upload 2

4: Open the File Upload.

Link: http://localhost/dvwa/vulnerabilities/upload/

5: Download the Shell-backdoor-list zip file.

Website: https://github.com/backdoorhub/shell-backdoor-list

DVWA File Upload 3

6: If the Download is not working, turn off the Realtime protection.

DVWA File Upload 4

7: Extract the shell-backdoor-list-master folder.

8: Open the shell-backdoor-list-master folder.

9: Upload the p0wny-shell.php shell.

DVWA File Upload 5

10: The Shell has been uploaded.

DVWA File Upload 6

11: Copy the Uploaded Shell Address.

Address: hackable/uploads/p0wny-shell.php

12: Open the executable link.

Link: http://localhost/dvwa/hackable/uploads/p0wny-shell.php

DVWA File Upload 7

13: The system has been hacked, and now you can execute.

Kakar Security Edition 1

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top