This guide will help you Install web DVWA on Hyper V
What is DVWA
Damn Vulnerable Web App (DVWA) is a PHP/MySQL web application that is damn vulnerable. Its main goals are to be an aid for security professionals to test their skills and tools in a legal environment, help web developers better understand the processes of securing web applications and aid teachers/students to teach/learn web application security in a class room environment.
I’m going to install this on a HyperV host. Basically on my own computer with hyperv manager installed. Just like I did with the Juice Shop . If you did the juice shop installation on the Hyperv then you will notice the beginning is the same.
Download Ubuntu here Get Ubuntu Server | Download | Ubuntu
HyperV Installation
I presume you know how to install HyperV on your machine. If not then follow the guide written by Microsoft to activate HyperV on your machine Enable Hyper-V on Windows 10 | Microsoft Docs
Once done start the HyperV console
Create a virtual switch
Inside the console on the right side click on Virtual Switch Manager and create a new External Switch. Just call it external
data:image/s3,"s3://crabby-images/4ba3e/4ba3e824f4c0284d8d4ed6094d91d75d3affee10" alt="Howto Install web dvwa"
Connect it to the right NIC and press Ok
data:image/s3,"s3://crabby-images/c6ee2/c6ee2ae315e2ae4572a859ec8c25d3e7fbecef39" alt="Howto Install web dvwa"
I’m choosing for an external switch because My kali machine is on an other laptop. This way it is available for the entire network
Creating an VM
data:image/s3,"s3://crabby-images/8b51b/8b51bca9703daa8f201eb9e0869156c50d21cff6" alt="Howto Install web dvwa"
data:image/s3,"s3://crabby-images/27088/27088871c4cffb7d0ef813b80bf2b075e9bef4d1" alt="Howto Install web dvwa"
data:image/s3,"s3://crabby-images/1b507/1b50714f7433a75b5fd9a43cf595c8107dfb5075" alt="Howto Install web dvwa"
Make sure you turn on Dynamic memory. If it needs more and there is more it will take more
data:image/s3,"s3://crabby-images/7bc0b/7bc0bc45370a0ca325da656075146e73170593ea" alt="Howto Install web dvwa"
Select the network we just added
data:image/s3,"s3://crabby-images/77400/7740005780d94de8bc66fac0855f284cffa20ebd" alt="Howto Install web dvwa"
Click next
data:image/s3,"s3://crabby-images/d1d34/d1d343f84820cf8fa48f8b110f669ba52596a592" alt="Howto Install web dvwa"
Select the downloaded ISO and click next then finish. Make sure you have the server version
You now have a VM. Right click on it and select connect. Now press start and select UBUNTU to start the installation
Installing UBUNTU server
Start from CD if not already configured. Select server
data:image/s3,"s3://crabby-images/5819f/5819f44e52206d945fa914ecfc7f84832cccd728" alt="UBUNTU server installation"
Select the language
data:image/s3,"s3://crabby-images/4a3e5/4a3e585db69d0219119ecf7ba1231282b8047da3" alt="UBUNTU server installation"
Select Keyboard
data:image/s3,"s3://crabby-images/21434/214346eed6316c01491563e7b303572b27d34df1" alt="UBUNTU server installation"
Select IPv4 and then automatic if no network is found
data:image/s3,"s3://crabby-images/835d1/835d10ae3bdd04def492994441e08a43a6fab0f9" alt="UBUNTU server installation"
Configure mirror or accept the default
data:image/s3,"s3://crabby-images/6a287/6a287ec7f91ddda8bc13a8b9a8c8b39af0ad35b3" alt="UBUNTU server installation"
Update to the new installer ( Always update )
data:image/s3,"s3://crabby-images/54035/540350e30275a6367fe02b7f50e5e8b50a9db5bb" alt="UBUNTU server installation"
Accept defaults
data:image/s3,"s3://crabby-images/234bc/234bc05f8ff4da4bee14610a2ce2eef963a9a813" alt="UBUNTU server installation"
Fill in the information needed to continue
data:image/s3,"s3://crabby-images/f315d/f315d8e23a0ef4a67b1cad4465a871a9cbabaf4a" alt="UBUNTU server installation"
For ssh acces to the server you can select install openSSH server
data:image/s3,"s3://crabby-images/374a7/374a78f281016d5940d2314a1ea7c9e0c8cfb904" alt="UBUNTU server installation"
Do not select anything and move on to finish the installation
Installing web DVWA
Now for the fun part. Log in to the server
Update all with the following command
sudo apt-get update && sudo apt-get upgrade -y && sudo apt-get -y dist-upgrade && sudo apt-get autoremove -y
Once done we are going to install some depencies with the following command
sudo apt-get install php php-gd sudo apt-get install linux-azure
Configure MySQL
Install the mysql first with the follwoing command
sudo apt-get install mysql-server
sudo apt-get install php-mysql
Now top configure the MYSQL part
sudo mysql -u root
CREATE USER ‘dvwa’@’localhost’;
ALTER USER ‘dvwa’@’localhost’ IDENTIFIED BY ‘p@ssw0rd’;
CREATE DATABASE dvwa;
GRANT ALL PRIVILEGES ON . TO ‘dvwa’@’localhost’;
FLUSH PRIVILEGES;
exit
Download and install DVWA
cd ~ git clone https://github.com/digininja/DVWA.git sudo mv ./DVWA/ /var/www/dvwa/ sudo chmod 757 -R /var/www/dvwa/hackable/uploads sudo chmod 757 -R /var/www/config sudo chmod 757 /var/www/dvwa/external/phpids/0.6/lib/IDS/tmp/phpids_log.txt sudo cp /var/www/dvwa/config/config.inc.php.dist /var/www/dvwa/config/config.inc.php
Edit the config file t change the password
sudo nano /var/www/dvwa/config/config.inc.php
data:image/s3,"s3://crabby-images/98569/98569dadf7f8ff15edaa93b2aa2490aef044e3a2" alt="Install web DVWA"
Now for the apache part
sudo nano /etc/php/7.4/apache2/php.ini
data:image/s3,"s3://crabby-images/81764/8176409a665de2b40c64e40946e468c5c91190d9" alt="Install web DVWA"
TIP: You can search the file by hitting control+w
Now copy the apache2 default config
sudo cp /etc/apache2/site-available/000-default.conf /etc/apache2/site-available/dvwa.conf
If you get an error not existing then navigate to the directory and copy the default config
sudo cp 000-default.conf dvwa.conf
Now edit the dvwa.conf
nano dvwa.conf
Change the document root
sudo nano /etc/apache2/site-available/dvwa.conf
data:image/s3,"s3://crabby-images/af088/af0880b99e86c85ce87d36f47db81122a98f10fa" alt="Install web DVWA"
Now restart apache2
systemctl reload apache2
sudo service apache2 restart
Now navigate with a browser to the IP of the machine
http://MACHINE_IP/setup.php
data:image/s3,"s3://crabby-images/47bfe/47bfec795456c8083664256675fc88508c2b8810" alt="Install web DVWA"
There are still 2 issues open. Those we can fix but it is not necessary to complete. Let’s see if we can fix them anyway
First for the reCAPTCHA. We need to generated the keys and add them to the config
Navigate to reCAPTCHA (google.com) and generate a public and private key
data:image/s3,"s3://crabby-images/18879/18879441e1e6ec3e5a9302c8a4852b2524855781" alt="captcha for dvwa"
sudo nano /etc/apache2/site-available/dvwa.conf
Now add thos key in the config and save
Now for the last thing to do
sudo chmod 757 -R /var/www/dvwa/config
restart the apache
sudo service apache2 restart
refresh the page
data:image/s3,"s3://crabby-images/c8aaa/c8aaa9ef77f951cdead3460a99488eef0d871554" alt="Install web DVWA"
Now create a snapshot in Hyperv manager so you can always revert to this configuration
data:image/s3,"s3://crabby-images/bd84f/bd84fc349c5bb43c564146282deb4192cdebe3e6" alt="Checkpoint hyperv dvwa"
Have fun exploiting the DVWA. I will create some writeups when I get to it