Website Hacking

Welcome, to website hacking & exploitation, the following links will provide tutorials on website hacking at different security levels using bWAPP

Getting Started

Before we begin website hacking, you need to set up a hacking lab.

bWAPP is used in these demonstrations but there are lots more.

Here are a list of vulnerable website virtual boxes.

Let the hacking begin!!


Broken Authentication: Username Enumeration

Broken Authentication: Brute forcing Passwords


Low Security

OS Command Injection

Unrestricted File-Upload

SQL Injection

CSRF (Cross Site Request Forgery)

Bypassing Administrative Portals

Medium Security

OS Command Injection

Unrestricted File-Upload

Bypassing Administrative Portals

High Security

Unrestricted File-Upload

