Sign inSign up

cytopia/dvwa

By cytopia

•Updated over 3 years ago

DVWA (Damn Vulnerable Web Application) with additional local priv escalation challenges

Image
21

100K+

cytopia/dvwa repository overview

⁠Dockerized DVWA

Install⁠ | Start⁠ | Stop⁠ | Usage⁠ | Features⁠ | Configuration⁠ | Capture the flag⁠ | Tools⁠ | FAQ⁠ | Sec Tools⁠ | License⁠

Tag build nightly License

Damn Vulnerable Web Application (DVWA) is a PHP/MySQL web application that is damn vulnerable. Its main goal is to be an aid for security professionals to test their skills and tools in a legal environment, help web developers better understand the processes of securing web applications and to aid both students & teachers to learn about web application security in a controlled class room environment.

https://github.com/digininja/DVWA⁠

DVWA⁠ has an official Docker image available at Dockerhub⁠, however by the time of writing this image did not receive any recent updates.

If you need an always up-to-date version or arm64 images, you can use the here provided Docker Compose setup. The image is built every night against the latest master branch of the DVWA⁠ and pushed to Dockehub⁠.

Additionally this Docker image comes with a few CTF challenges that require you to completely compromise the machine and reach root access. Read here⁠ for details.

Available Architectures: amd64, arm64

⁠:whale: Available Docker image versions

Docker

⁠Rolling releaess

The following Docker image tags are rolling releases and are built and updated every night.

nightly

Docker TagGit RefPHPAvailable Architectures
latestmasterlatestamd64, arm64
php-8.1master8.1amd64, arm64
php-8.0master8.0amd64, arm64
php-7.4master7.4amd64, arm64
php-7.3master7.3amd64, arm64
php-7.2master7.2amd64, arm64
php-7.1master7.1amd64, arm64
php-7.0master7.0amd64, arm64
php-5.6master5.6amd64, arm64

⁠:tada: Install

Clone repository from GitHub:

git clone https://github.com/cytopia/docker-dvwa

⁠:zap: Start

Inside the cloned repository (docker-dvwa/ directory):

make start

⁠:no_entry_sign: Stop

Inside the cloned repository (docker-dvwa/ directory):

make stop

⁠:computer: Usage

After running make start you can access DVWA in your browser via:

⁠:star: Features

⁠:wrench: Configuration

This setup allows you to configure a few settings via the .env file.

VariableDefaultSettings
PHP_VERSION8.1PHP version to run DVWA (5.6, 7.0, 7.1, 7.2, 7.3, 7.4, 8.0 or 8.1)
LISTEN_PORT8000Local port for the web server to listen on
RECAPTCHA_PRIV_KEYRequired to make the captcha module work. (See FAQ⁠ section below)
RECAPTCHA_PUB_KEYRequired to make the captcha module work. (See FAQ⁠ section below)
PHP_DISPLAY_ERRORS0Set to 1 to display PHP errors (if you want a really easy mode)

The following .env file variables are default settings and their values can also be changed from within the web interface:

VariableDefaultSettings
SECURITY_LEVELmediumAdjust the difficulty level for the challenges[1]
(low, medium, high or impossible)
PHPIDS_ENABLED0Set to 1 to enable PHP WAF/IDS[2] (off by default)
PHPIDS_VERBOSE0Set to 1 to display WAF/IDS reasons for blocked requests

[1] For the SECURITY_LEVEL changes to take effect, you will have to clear your cookies. Alternatively change it in the web interface.
[2] WAF (Web Application Firewall) / IDS (Intrusion Detection System)

⁠:pirate_flag: Capture the flag

Additionally to the default DVWA features, this flavour also contains a few flags that can be captured via various means (including local privilege escalation).

  • Flag 1: flag{b9bbcb33e11b80be759c4e844862482d}
  • Flag 2: flag{fc3fd58dcdad9ab23faca6e9a36e581c}
  • Flag 3: flag{eca7d1f3cf60a8b5344a49287b9076e4}

How to play?

  • :heavy_check_mark: You must gain access to the running Docker container through the web application.
  • :no_entry: You cannot use docker exec -it dvwa_web bash to gain access

Let me know on :bird: Twitter⁠ if you've solved them and how easy/difficult they were.

⁠:gear: Tools

The DVWA Docker image contains the following tools assisting you in solving the challenges and also allowing you to gain access via reverse shells.

  • bash
  • netcat
  • ping
  • sudo
  • telnet
  • python3

⁠:bulb: FAQ

Q: I want to proxy through BurpSuite⁠, but it does not work on localhost or 127.0.0.1.


Browsers ususally bypass localhost or 127.0.0.1 for proxy traffic. One solution is to add an alternative hostname to /etc/hosts and access the application through that.

/etc/hosts:

127.0.0.1  dvwa

Then use http://dvwa:8000⁠ in your browser.

Q: How can I run DVWA with a different PHP version?


The here provided Docker images are built against all common PHP versions and you can easily select your version of choice in the .env⁠ prior startup. To do so, just uncomment the version of choice and restart the Docker Compose stack:
.env

# PHP VERSION
# -----------
# Uncomment one of the PHP versions you want to use for DVWA
#PHP_VERSION=5.6
#PHP_VERSION=7.0
#PHP_VERSION=7.1
#PHP_VERSION=7.2
#PHP_VERSION=7.3
#PHP_VERSION=7.4
#PHP_VERSION=8.0
PHP_VERSION=8.1

Q: How can I reset the database and start fresh?


The database uses a Docker volume and you can simply remove it via:

# the command below will stop all running container,
# remove their state and delete the MySQL docker volume.
make reset

Q: How can I view Apache access or error log files?


Log files are piped to stderr from the Docker container and you can view them via:

make logs

Q: How can I get a shell on the web server container?


warning Note: Doing so is basically cheating, you are supposed to gain access to the machine via exploitation.

You can enter the running web server container as root via:

make enter

Q: How do I setup the reCAPTCHA key?


Go to https://www.google.com/recaptcha/admin⁠ and generate your captcha as shown below:

  • Ensure to choose reCAPTCHA v2
  • Ensure to add all domains you plan on using
  • Add SITE KEY to the RECAPTCHA_PUB_KEY variable in your .env file
  • Add SECRET KEY to the RECAPTCHA_PRIV_KEY variable in your .env file

Q: How can I access/view the MySQL database?


warning Note: Doing so is basically cheating, but if you really need to, you can do so.

This Docker image bundles Adminer⁠ (a PHP web interace similar to phpMyAdmin) and you can access it here: http://localhost:8000/adminer.php⁠

  • Server: dvwa_db
  • Username: root
  • Password: rootpass

Q: How can I build the Docker image locally?


To build or rebuild the Docker image against new updates in DVWA master branch⁠, simply do the following:

# This is builing the image for the default PHP version
make rebuild

# This is building the image with PHP 8.0
make rebuild PHP=8.0

⁠:rocket: Deployment

⁠AWS

Terraform

This repository ships a Terraform module⁠ to deploy DVWA on AWS.

cd aws/
cp terraform.tfvars-example terraform.tfvars

terraform init
terraform apply

For more information see Terraform module⁠.

⁠Kubernetes

Kubernetes

This repository ships Kubernetes resources⁠ to deploy DVWA on K8s or minikube.

cd k8s/
kubectl apply -f .

For more information see k8s⁠.

⁠:lock: cytopia⁠ sec tools

Below is a list of sec tools and docs I am maintaining, which might come in handy working on DVWA.

NameCategoryLanguageDescription
offsec⁠DocumentationMarkdownOffsec checklist, tools and examples
header-fuzz⁠EnumerationBashFuzz HTTP headers
smtp-user-enum⁠EnumerationPython 2+3SMTP users enumerator
urlbuster⁠EnumerationPython 2+3Mutable web directory fuzzer
pwncat⁠PivotingPython 2+3Cross-platform netcat on steroids
badchars⁠Reverse EngineeringPython 2+3Badchar generator
fuzza⁠Reverse EngineeringPython 2+3TCP fuzzing tool

⁠:page_facing_up: License

MIT License⁠

Copyright (c) 2021 cytopia⁠

Tag summary

Content type

Image

Digest

sha256:f9746ae39…

Size

171.4 MB

Last updated

over 3 years ago

docker pull cytopia/dvwa