This project demonstrates practical web application security testing using Damn Vulnerable Web Application (DVWA) deployed on Ubuntu Server inside an isolated VMware laboratory.
The assessment focuses on understanding common OWASP Top 10 vulnerabilities in a controlled environment.
- Install DVWA
- Configure Apache, PHP and MariaDB
- Perform SQL Injection testing
- Demonstrate Command Injection
- Demonstrate Reflected XSS
- Demonstrate Stored XSS
- Demonstrate Local File Inclusion
- Demonstrate CSRF
- Demonstrate File Upload
- Demonstrate Brute Force
- Document findings
| Component | Details |
|---|---|
| Host OS | Windows 11 |
| Hypervisor | VMware Workstation 17 |
| Attacker | Kali Linux |
| Target | Ubuntu Server 24.04 LTS |
| Web Server | Apache2 |
| Database | MariaDB |
| Application | DVWA |
- SQL Injection
- Command Injection
- Reflected XSS
- Stored XSS
- Local File Inclusion
- CSRF
- File Upload
- Brute Force
- Kali Linux
- Ubuntu Server
- Apache2
- PHP
- MariaDB
- DVWA
- Firefox
- Web Application Security
- OWASP Top 10
- Linux Administration
- Apache Configuration
- Database Configuration
- Secure Documentation
- Vulnerability Validation
- Technical Reporting
This project provided hands-on experience with common web application vulnerabilities, secure deployment concepts, and mitigation strategies within an isolated lab environment.
All testing was performed exclusively against DVWA hosted inside a personal VMware laboratory for educational purposes.
Dheeraj S
Aspiring SOC Analyst | Cybersecurity Analyst