> For the complete documentation index, see [llms.txt](https://cas-cyber.gitbook.io/cas-cybersecurity/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cas-cyber.gitbook.io/cas-cybersecurity/web-application-security/dvwa/dvwa-exercises-1.md).

# DVWA Exercises 1

### 01. Bruteforce Attack 1

Login with admin / admin

In burp click on forward until you see the post request. Hit **Ctrl + i** to send it to the Intruder tab

<div align="left"><img src="https://3977837039-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MfT0VPyK6X13Egd9pzy%2F-MhjYGcI9EpQ9DesSmHp%2F-MhjpsMnKTEVrHXITofg%2Fburp04.png?alt=media&amp;token=466a415d-8677-4eab-a355-64df71359c7c" alt=""></div>

Goto Intruder, choose Cluster bomb as Attack type. Clear all variables and add the value of username and the value of password. For both we want to provide a wordlist.&#x20;

![](https://3977837039-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MfT0VPyK6X13Egd9pzy%2F-MhjYGcI9EpQ9DesSmHp%2F-MhjrQoT2_xUZ-sW83hl%2Fburp05.png?alt=media\&token=8a2ccf5e-d553-4b59-b1df-56265fa1255e)

Generate passwordlist:

> gunzip /usr/share/wordlist/rockyou.txt.gz
>
> head -20 rockyou.txt >passwords.txt

![Generating a small password list](https://3977837039-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MfT0VPyK6X13Egd9pzy%2F-MhjYGcI9EpQ9DesSmHp%2F-MhjulYhcfYRHY0MrXsN%2Fpassword_list.png?alt=media\&token=86bcc8e3-6783-475c-89d0-5ea30a772e99)

For payload 1 I'll add 4 usernames

<div align="left"><img src="https://3977837039-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MfT0VPyK6X13Egd9pzy%2F-MhjYGcI9EpQ9DesSmHp%2F-MhjveQg0_XvgQPnezdw%2Fburp06.png?alt=media&amp;token=9d12bc39-e6f1-49b7-a8d8-c8518ef154b1" alt=""></div>

For payload 2 I'll load the password list

<div align="left"><img src="https://3977837039-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MfT0VPyK6X13Egd9pzy%2F-MhjYGcI9EpQ9DesSmHp%2F-MhjwOKPZjYKQ7ovI2cj%2Fburp07.png?alt=media&amp;token=73cc35de-f144-4bfe-92b7-811dec7bfe03" alt=""></div>

Start the attack and check Response header

<div align="left"><img src="https://3977837039-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MfT0VPyK6X13Egd9pzy%2F-MhjYGcI9EpQ9DesSmHp%2F-MhjzdO2Tl4FyVpfDuCf%2Fburp08.png?alt=media&amp;token=9964c7b7-3e3c-4da6-a3a1-f12297250526" alt="failed logins will stand on login.php"></div>

<div align="left"><img src="https://3977837039-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MfT0VPyK6X13Egd9pzy%2F-MhjYGcI9EpQ9DesSmHp%2F-Mhk-Qh8G9_rSj7fXgzB%2Fburp09.png?alt=media&amp;token=a20db014-92c2-420f-99d6-0e370e18654d" alt=""></div>

### 02. Bruteforce Attack 2

Let's login with admin / password and solve the bruteforce exercise

<div align="left"><img src="https://3977837039-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MfT0VPyK6X13Egd9pzy%2F-Mhk-mT1ea-yidelb7Kv%2F-Mhk3-2KSIDAs8cLt2oy%2Fdvwa02.png?alt=media&amp;token=84259d0b-3597-483e-a1aa-54320d0eed22" alt=""></div>

submit wrong credentials admin / test and fire up the intruder modul

<div align="left"><img src="https://3977837039-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MfT0VPyK6X13Egd9pzy%2F-Mhk-mT1ea-yidelb7Kv%2F-Mhk3XwYVS20UHAgrCMw%2Fburp10.png?alt=media&amp;token=12214aa1-8478-48b2-80fa-4d4a39338949" alt=""></div>

![](https://3977837039-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MfT0VPyK6X13Egd9pzy%2F-Mhk-mT1ea-yidelb7Kv%2F-Mhk4Q8AMq0iA_yc-gBy%2Fburp11.png?alt=media\&token=4c3138c0-2a2a-4799-b2de-9906e3324e16)

Set the payload and start the attack

<div align="left"><img src="https://3977837039-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MfT0VPyK6X13Egd9pzy%2F-Mhk-mT1ea-yidelb7Kv%2F-Mhk50kV9o4woL2Achh5%2Fburp12.png?alt=media&amp;token=2734aeea-fd10-429b-850f-db9dac834838" alt=""></div>

Check content length

<div align="left"><img src="https://3977837039-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MfT0VPyK6X13Egd9pzy%2F-Mhk-mT1ea-yidelb7Kv%2F-Mhk6P-wOrxlkjG_zffK%2Fburp13.png?alt=media&amp;token=3732b1bf-ccfa-4b3d-b1c9-e3a80845df95" alt=""></div>
