Brute Force - DVWA

The goal is to brute force an HTTP login page.

August 17, 2022 · 3 min · 510 words · Aftab Sama

Command Injection - DVWA

Perform command injection using the ping functionality.

August 17, 2022 · 1 min · 64 words · Aftab Sama

Cross Site Request Forgery (CSRF) - DVWA

Changing the victim’s password using CSRF.

August 17, 2022 · 2 min · 331 words · Aftab Sama

File Inclusion - DVWA

Read the /etc/passwd file using File Inclusion vulnerability.

August 17, 2022 · 1 min · 55 words · Aftab Sama

File Upload - DVWA

Exploit the file upload vulnerability to achieve Remote Code Execution (RCE).

August 17, 2022 · 1 min · 193 words · Aftab Sama

SQL Injection - DVWA

Use an SQL injection attack to retrieve the admin password.

August 17, 2022 · 1 min · 97 words · Aftab Sama

SQL Injection (Blind) - DVWA

Perform a blind SQL injection attack to retrieve the database version.

August 17, 2022 · 2 min · 354 words · Aftab Sama

Weak Session IDs - DVWA

Identify the cookie session ID pattern.

August 17, 2022 · 1 min · 47 words · Aftab Sama

DOM Based Cross Site Scripting (XSS) - DVWA

Trigger an alert pop-up with cookie values using DOM-based XSS.

August 17, 2022 · 1 min · 100 words · Aftab Sama

Reflected Cross Site Scripting (XSS) - DVWA

Trigger an alert pop-up with cookie values using Reflected XSS.

August 17, 2022 · 1 min · 54 words · Aftab Sama