Skip to content

Mvrcoz/Web-Application-Attacks

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

9 Commits
 
 

Repository files navigation

Web Application Attacks

Objective: This project demonstrates hands-on experience in identifying and exploiting SQL Injection and Cross-Site Scripting (XSS) vulnerabilities using WebGoat and DVWA.

Tools Used

  • WebGoat: A deliberately insecure web application by OWASP for training on web vulnerabilities.
  • DVWA (Damn Vulnerable Web Application): A safe, legal environment to practice web security.

Key Concepts

  • SQL Injection: Used input like ' OR '1'='1'-- to dump database information.
  • XSS: Injected scripts to exploit the XSS vulnerability and capture session cookies.

Lab Overview

  1. SQL Injection: Tested using http://127.0.0.1/Webgoat/attack on the WebGoat platform.
  2. XSS Attack: Exploited to inject scripts that steal session IDs.

Learnings

  • SQL Injection and XSS vulnerabilities can compromise web application security.
  • Practical methods for identifying and mitigating these issues.

View the lab document

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors