Date: 21 Feb 2025


SQL Injection

attachments/Pasted image 20250309111402.png

  1. click the edit virtual machine settings -> if you have 16 gb then give 2gb ram -> ok
    attachments/Pasted image 20250309111636.png
  1. start the machine and select i copied it
    attachments/Pasted image 20250309112317.png

shortcut keys :


  1. ifconfig in owasp to know your ip
    attachments/Pasted image 20250309112402.png

  2. open burp suite -> intercept off -> open browser -> then search in burp's browser your ip 192.168.31.128
    attachments/Pasted image 20250309112813.png

  3. then login through: admin , passwd : admin
    attachments/Pasted image 20250309112829.png

  4. then go to sql injection -> user id 1 -> submit
    attachments/Pasted image 20250309112847.png

  5. capture the request by seeing the tick ✅ of PARAMS (parameter) and do right click only on the marked GET/POST ips and do active scan
    attachments/Pasted image 20250309112903.png

  6. then go to Target -> then see the SQL injection and other vulnerabilities.
    attachments/Pasted image 20250309112917.png

  7. then go the website and put ' in the box and login
    attachments/Pasted image 20250309112935.png



../attachments/Screenshot 2025-02-21 101401.png

---****---