OWASP Vulnerable Web Application Project https://github.com/hummingbirdscyber
Go to file
2018-11-30 02:24:18 +03:00
CommandExecution Update CommandExec-2.php 2018-11-29 17:01:05 +03:00
FileInclusion Rename main.html to fileinc.html 2018-11-30 01:22:05 +03:00
FileUpload Delete hummingbirds.txt 2018-11-30 04:57:13 +06:00
Resources Add files via upload 2018-11-29 16:48:58 +03:00
SQL Update sqlmainpage.html 2018-11-30 02:56:08 +06:00
XSS Create xssmainpage.html 2018-11-30 01:08:31 +03:00
homepage.html Creating index.php 2018-11-30 02:24:18 +03:00
README.md Update README.md 2018-11-30 05:13:43 +06:00
setup.php Bug fixes! 2018-11-30 02:22:46 +03:00

VulnWeb

VulnWeb

Installation Guide

If you want to run this tool, first of all you need to download web server solution like "xampp"- you can download xampp from https://www.apachefriends.org/tr/download.html. After your intallation; For windows you need to copy the files into the xampp/htdocs folder.

For Mac Os you need to install mampp and copy the files into the mampp/htdocs folder. https://www.mamp.info/en/downloads/

For linux after download our files first you need to open apache server and copy the files to /var/www/html

Other Configurations: The php.ini file should be altered. You can find the location of your php.ini file under the folder which php is installed.

  • allow_url_include = on - Allows for Remote File Inclusion
  • allow_url_fopen = on - Allows for Remote File Inclusion
  • safe_mode = off - (If PHP <= v5.4) Allows for SQL Injection
  • magic_quotes_gpc = off - (If PHP <= v5.4) Allows for SQL Injection

Installation

After all these configurations, firstly, open Xampp Control Panel and start Apache,MySQL. Your MySQL credentials have to be default.[username:root <-> password:""] Then open up our setup.php file in the VulnWeb directory. Follow the directions and create database. If you messed up with database, you can reset the database. If database is ready, you can go to homepage and start hacking.