Question: Using Burp Suite and DVWA website: Change your security level to Medium. In the DVWA website, find a user name (NOT user id which is

Using Burp Suite and DVWA website:

Change your security level to Medium. In the DVWA website, find a user name (NOT user id which is a numeric value) list using SQL injection attack. The user name is not necessarily the same as users first name or last name. Using brute force attack through the Burp Suite tool, find a plain password for each user name. The password list (pass.txt) is given in the Canvas. Capture the screen that shows user name in the DVWA website using SQL injection and add to the report. Capture the screen that shows user name and corresponding password in the Burp Suite and add to the report. Add the screen shots after you successfully logged in with all the found user name and password in the DVWA website. Explain how you identified the passwords of the user from the Burp Suite tool.

Step by Step Solution

There are 3 Steps involved in it

1 Expert Approved Answer
Step: 1 Unlock blur-text-image
Question Has Been Solved by an Expert!

Get step-by-step solutions from verified subject matter experts

Step: 2 Unlock
Step: 3 Unlock

Students Have Also Explored These Related Databases Questions!