Directory-traversal and file-inclusion

Let's begin by testing to see whether we can get the web application to jump up one directory.

We'll be in the DVWA app again. Log in and navigate to the File Inclusion page from the menu on the left:

In the address bar in the browser, you should see <IP Address>/dvwa/vulnerabilities/fi/?page=include.php. Let's change include.php to index.php and see what happens:

Nothing happens, suggesting that there ...

Get Kali Linux 2018: Assuring Security by Penetration Testing - Fourth Edition now with O’Reilly online learning.

O’Reilly members experience live online training, plus books, videos, and digital content from 200+ publishers.