Kamis, 09 Februari 2012

dvwa with sqlmap

to run dvwa. turn on apache and mysql

-
/etc/init.d/apache2
- start mysql




1.
open browser - search type localhost/DVWA
(username : admin)
 (password : password)




2. Change the security to be low



3. open SQLInjection - try type 4 ' 1=1
if false or does not work and error, it will appear:




4. open SQLInjection - try type





5. open SQLInjection - try type 2



6. open SQLInjection - try type 2 ' and 1=1#




7. open SQLInjection - try type 1' and 1=0 order by #

8. open SQLInjection - try type 1 ' OR '1'='1' --';



9. open temper data


10. open SQLMap (Apps - Information Gathering - Database Analysis - MySQL Analysis - SQLMAP





11. open SQLMap (Apps - Information Gathering - Database Analysis - MySQL Analysis - SQLMAP






12. open SQLMap (Apps - Information Gathering - Database Analysis - MySQL Analysis - SQLMAP






13. open SQLMap (Apps - Information Gathering - Database Analysis - MySQL Analysis - SQLMAP







Tidak ada komentar:

Posting Komentar