Here I demonstrate how to exploit the Blind SQL Injection vulnerability in DVWA to obtain all user and passwords from the database.
Sorry, but the end of the video was cut off. Following the exploit, crack the MD5 hashes w/ JTR with the command:
john --format=raw-MD5 dvwa_hashes
See more content like this at http://securityjuggernaut.blogspot.com/ or follow me on Twitter: @antunesdennis
Link to this comment:
All Comments (0)