CHANGING SECURITY TO LOW Mechanize::Page Links Discovered: ******************************************** http://localhost/DVWA/. http://localhost/DVWA/instructions.php http://localhost/DVWA/setup.php http://localhost/DVWA/vulnerabilities/brute/ http://localhost/DVWA/vulnerabilities/exec/ http://localhost/DVWA/vulnerabilities/csrf/ http://localhost/DVWA/vulnerabilities/fi/.?page=include.php http://localhost/DVWA/vulnerabilities/upload/ http://localhost/DVWA/vulnerabilities/captcha/ http://localhost/DVWA/vulnerabilities/sqli/ http://localhost/DVWA/vulnerabilities/sqli_blind/ http://localhost/DVWA/vulnerabilities/xss_r/ http://localhost/DVWA/vulnerabilities/xss_s/ http://localhost/DVWA/security.php http://localhost/DVWA/phpinfo.php http://localhost/DVWA/about.php http://localhost/DVWA/login.php Pages Successfully Guessed: ******************************************** http://localhost/DVWA/about.php http://localhost/DVWA/login.php Parsed URLs (from guessed pages and discovered links): ******************************************** ["http://localhost/DVWA/."] ["http://localhost/DVWA/instructions.php"] ["http://localhost/DVWA/setup.php"] ["http://localhost/DVWA/vulnerabilities/brute/"] ["http://localhost/DVWA/vulnerabilities/exec/"] ["http://localhost/DVWA/vulnerabilities/csrf/"] ["http://localhost/DVWA/vulnerabilities/fi/.", "page=include.php"] ["http://localhost/DVWA/vulnerabilities/upload/"] ["http://localhost/DVWA/vulnerabilities/captcha/"] ["http://localhost/DVWA/vulnerabilities/sqli/"] ["http://localhost/DVWA/vulnerabilities/sqli_blind/"] ["http://localhost/DVWA/vulnerabilities/xss_r/"] ["http://localhost/DVWA/vulnerabilities/xss_s/"] ["http://localhost/DVWA/security.php"] ["http://localhost/DVWA/phpinfo.php"] ["http://localhost/DVWA/about.php"] ["http://localhost/DVWA/login.php"] ["http://localhost/DVWA/about.php"] ["http://localhost/DVWA/login.php"] ************************************************ PAGE: Setup :: Damn Vulnerable Web Application (DVWA) v1.9 ************************************************ FORM INPUTS: ********************************************* * Name * Value * ********************************************* ********************************************* *user_token*60e06ac7adf5ceb58dff089c2dd5f28d* ********************************************* ************************************************ PAGE: Vulnerability: Brute Force :: Damn Vulnerable Web Application (DVWA) v1.9 ************************************************ FORM INPUTS: **************** * Name *Value* **************** **************** *username* * *password* * **************** ************************************************ PAGE: Vulnerability: Command Injection :: Damn Vulnerable Web Application (DVWA) v1.9 ************************************************ FORM INPUTS: ********** *Name*Value* ********** ********** *ip* * ********** ************************************************ PAGE: Vulnerability: Cross Site Request Forgery (CSRF) :: Damn Vulnerable Web Application (DVWA) v1.9 ************************************************ FORM INPUTS: ********************* * Name *Value* ********************* ********************* *password_new * * *password_conf* * ********************* ************************************************ PAGE: Vulnerability: File Upload :: Damn Vulnerable Web Application (DVWA) v1.9 ************************************************ FORM INPUTS: ************************************************ PAGE: Vulnerability: Insecure CAPTCHA :: Damn Vulnerable Web Application (DVWA) v1.9 ************************************************ FORM INPUTS: ******************************************** * Name * Value * ******************************************** ******************************************** * step * 1 * * password_new * * * password_conf * * *recaptcha_response_field *manual_challenge* *recaptcha_challenge_field* * ******************************************** ************************************************ PAGE: Vulnerability: SQL Injection :: Damn Vulnerable Web Application (DVWA) v1.9 ************************************************ FORM INPUTS: ********** *Name*Value* ********** ********** *id* * ********** ************************************************ PAGE: Vulnerability: SQL Injection (Blind) :: Damn Vulnerable Web Application (DVWA) v1.9 ************************************************ FORM INPUTS: ********** *Name*Value* ********** ********** *id* * ********** ************************************************ PAGE: Vulnerability: Reflected Cross Site Scripting (XSS) :: Damn Vulnerable Web Application (DVWA) v1.9 ************************************************ FORM INPUTS: ************ *Name*Value* ************ ************ *name* * ************ ************************************************ PAGE: Vulnerability: Stored Cross Site Scripting (XSS) :: Damn Vulnerable Web Application (DVWA) v1.9 ************************************************ FORM INPUTS: ****************** * Name *Value* ****************** ****************** * txtName * * *mtxMessage* * ****************** ************************************************ PAGE: DVWA Security :: Damn Vulnerable Web Application (DVWA) v1.9 ************************************************ FORM INPUTS: ********************************************* * Name * Value * ********************************************* ********************************************* *user_token*8ba8dec7f5c63609af42807be0d95b8e* * security * low * ********************************************* ************************************************ PAGE: Login :: Damn Vulnerable Web Application (DVWA) v1.9 ************************************************ FORM INPUTS: ********************************************* * Name * Value * ********************************************* ********************************************* * username * * * password * * *user_token*7d5e771e549cac642b702d28a4efbd05* ********************************************* ************************************************ PAGE: Login :: Damn Vulnerable Web Application (DVWA) v1.9 ************************************************ FORM INPUTS: ********************************************* * Name * Value * ********************************************* ********************************************* * username * * * password * * *user_token*efcfd50ddaf4ccbd0702f4fc094e7df3* ********************************************* Cookies: ********************************************************* PHPSESSID=mto9mlep0ida20vv2lbvoac0v0 security=low *********************************************************