Directory-traversal and file-inclusion

Let's begin by testing to see whether we can get the web application to jump up one directory.

We'll be in the DVWA app again. Log in and navigate to the File Inclusion page from the menu on the left:

In the address bar in the browser, you should see <IP Address>/dvwa/vulnerabilities/fi/?page=include.php. Let's change include.php to index.php and see what happens:

Nothing happens, suggesting that there ...

Get Kali Linux 2018: Assuring Security by Penetration Testing - Fourth Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.