# Translation
ç®åç¿»è¯æ£å¨å®åï¼æåçç¿»è¯å·¥ä½å°±æ¯å大æ¼æ´ç说æï¼ä¿æä¸å¤©ä¸¤æ´ï¼ä¸æ´ä¸ç¯è¯´æç¿»è¯ã
ç¿»è¯ï¼@[Basyaact](https://github.com/Basyaact),@[inVains](https://github.com/inVains)
å
¨ç¯å¢å·²æ±åï¼ä¾ä¸å½ç¨æ·ä½¿ç¨ï¼å¦æä¾µæï¼è¯·èç³»é®ç®±ï¼[email protected]
READMEé¨åæ¥èªæºå¨ç¿»è¯ï¼è¯·ä»¥åæ为å[README.md](README_en.md)
ä¸æ¯æºå¨ç¿»è¯ï¼ä¸æ¯æºå¨ç¿»è¯ï¼ï¼
- - -
# DAMN VULNERABLE WEB APPLICATION
Damn Vulnerable Web Application (DVWA)(è¯æ³¨ï¼å¯ä»¥ç´è¯ä¸ºï¼"该æ»ç"ä¸å®å
¨Webåºç¨ç½ç«)ï¼æ¯ä¸ä¸ªç¼ç ç³ç³çãæåæ»å»ç PHP/MySQL Webåºç¨ç¨åºã å®ç主è¦ç®çæ¯å¸®å©å®å
¨ä¸ä¸äººåå¨åæ³çç¯å¢ä¸ï¼æµè¯ä»ä»¬çæè½åå·¥å
·ï¼å¸®å© Web å¼å人åæ´å¥½å°äºè§£å¦ä½å¢å¼º Web åºç¨ç¨åºçå®å
¨æ§ï¼å¹¶å¸®å©å¦çåæå¸å¨åæ§ç课å ç¯å¢ä¸ï¼äºè§£ Web åºç¨ç¨åºçå®å
¨ã
DVWAçå
·ä½ç®æ æ¯éè¿ç®åæäºççé¢ï¼æ¥**æ¼ç»ä¸äºæ常è§ç Web æ¼æ´**ï¼è¿äºæ¼æ´å
·æ**ä¸åçé¾åº¦çº§å«**ã 请注æï¼æ¤è½¯ä»¶**åå¨è¯´æåæªè¯´æçæ¼æ´**ã è¿æ¯æ
æçã æ们é¼å±æ¨å°è¯å¹¶åç°å°½å¯è½å¤çå®å
¨é®é¢ã
- - -
## è¦åï¼
DVWAååæåæ»å»ï¼ **ä¸è¦å°å
¶ä¸ä¼ å°æ¨çäºæå¡å¨çå
Œ
± html æ件夹æä»»ä½é¢å Internet çæå¡å¨**ï¼å 为å®ä»¬ä¼åå°å±å®³ã 建议使ç¨èææºï¼å¦[VirtualBox](https://www.virtualbox.org/) æ[VMware](https://www.vmware.com/)ï¼ï¼è®¾ç½®ä¸ºNATç»ç½æ¹å¼ãå¨å®¢æºï¼guest machineï¼ä¸ï¼æ¨å¯ä»¥ä¸è½½å¹¶å®è£
[XAMPP](https://www.apachefriends.org/en/xampp.html) ä½ä¸º Web æå¡å¨åæ°æ®åºã
### å
责声æ
æ们ä¸å¯¹ä»»ä½äººä½¿ç¨æ¤åºç¨ç¨åº (DVWA) çæ¹å¼è´è´£ã æ们已ç»æç¡®äºåºç¨ç¨åºçç®çï¼ä¸åºè¢«æ¶æ使ç¨ã æ们已ååºè¦å并éåæªæ½é²æ¢ç¨æ·å° DVWA å®è£
å°å®é
ç产è¿è¡ç Web æå¡å¨ä¸ã å¦ææ¨ç Web æå¡å¨å å®è£
DVWA èåå°æ害ï¼è¿ä¸æ¯æ们ç责任ï¼èæ¯ä¸ä¼ åå®è£
å®ç人ç责任ã
- - -
## 许å¯
该æ件æ¯Damn Vulnerable Web Application (DVWA) çä¸é¨åã
Damn Vulnerable Web Application (DVWA)æ¯èªç±è½¯ä»¶ï¼æ¨å¯ä»¥æ ¹æ®èªç±è½¯ä»¶åºéä¼åå¸ç GNU éç¨å
Œ
±è®¸å¯è¯ï¼è®¸å¯è¯ç第 3 çï¼æï¼ç±æ¨éæ©çï¼ä»»ä½æ´é«çæ¬ï¼éæ°ååå/æä¿®æ¹ã
Damn Vulnerable Web Application (DVWA) çåå¸æ¯ä¸ºäºå¸æå®æç¨ï¼ä½ä¸ï¼å¯¹"æç¨æ§"ï¼åä»»ä½ä¿è¯ï¼ çè³ä¸å¯¹ééæ§ï¼MERCHANTABILITYï¼æé对ç¹å®ç®ççéç¨æ§ï¼FITNESS FOR A PARTICULAR PURPOSEï¼çåä»»ä½æ示ä¿è¯ã æå
³æ´å¤è¯¦ç»ä¿¡æ¯ï¼è¯·åé
GNU éç¨å
Œ
±è®¸å¯è¯ã
æ¨åºè¯¥å·²ç»éDamn Vulnerable Web Application (DVWA)æ¶å°ä¸ä»½GNUéç¨å
Œ
±è®¸å¯è¯ã å¦æ没æï¼è¯·åé
ã
- - -
## å½é
å
该æ件æå¤ç§è¯è¨çæ¬ï¼
- ä¸æ: [ç®ä½ä¸æ](README.zh.md)
å¦ææ¨æ³è´¡ç®ç¿»è¯ï¼è¯·æ交 PRã ä½æ¯è¯·æ³¨æï¼è¿å¹¶ä¸æå³çåªæ¯ç®åçéè¿è°·æç¿»è¯å¹¶æ交ï¼è¿ç§æ交å°è¢«æç»ã
- - -
## ä¸è½½
è½ç¶æåç§çæ¬ç DVWAï¼ä½å¯ä¸åæ¯æççæ¬æ¯æ¥èªå®æ¹ GitHub åå¨ä»åºï¼repositoryï¼çææ°æºç ã ä½ å¯ä»¥ä» repo ä¸å
éå®ï¼
```
git clone https://github.com/digininja/DVWA.git
```
æè
[ä¸è½½æ件ç ZIP](https://github.com/digininja/DVWA/archive/master.zip)ã
- - -
## å®è£
**请确ä¿æ¨ç config/config.inc.php æ件åå¨ã åªæ config.inc.php.dist æ¯ä¸å¤çï¼æ¨å¿
é¡»ç¼è¾å®ä»¥éåºæ¨çç¯å¢å¹¶å°å
¶éå½å为 config.inc.phpã [Windows å¯è½ä¼éèæ件æ©å±åã](https://support.microsoft.com/en-in/help/865219/how-to-show-or-hide-file-name-extensions-in-windows-explorer)**
### å®è£
è§é¢
- [å¨ Windows 10 ä¸å®è£
DVWAï¼Installing Damn Vulnerable Web Application (DVWA) on Windows 10ï¼](https://www.youtube.com/watch?v=cak2lQvBRAo) [12:39 åé]
### Windows + XAMPP
å¦ææ¨è¿æ²¡æ设置 Web æå¡å¨ï¼å®è£
DVWA çæç®åæ¹æ³æ¯ä¸è½½å¹¶å®è£
[XAMPP](https://www.apachefriends.org/en/xampp.html)ã
XAMPP æ¯ä¸ä¸ªé常æäºå®è£
ç Apache åè¡çï¼éç¨äº LinuxãSolarisãWindows å Mac OS Xã该软件å
å
æ¬ Apache Web æå¡å¨ãMySQLãPHPãPerlãä¸ä¸ª FTP æå¡å¨å phpMyAdminã
XAMPP å¯ä»¥ä»ä»¥ä¸ä½ç½®ä¸è½½ï¼https://www.apachefriends.org/en/xampp.html
åªé解å缩 dvwa.zipï¼å°è§£å缩çæ件æ¾å¨æ¨çå
Œ
± html æ件夹ä¸ï¼ç¶å使ç¨æµè§å¨è®¿é®ï¼`http://127.0.0.1/dvwa/setup.php`
### Linux Packages
å¦ææ¨ä½¿ç¨çæ¯åºäº Debian ç Linux åè¡çï¼åéè¦å®è£
以ä¸è½¯ä»¶å
_ï¼æä¸å®ä»¬å
·æç¸ååè½ç软件å
ï¼_ï¼
`apt-get -y install apache2 mariadb-server php php-mysqli php-gd libapache2-mod-php`
该ç«ç¹å¨ä½¿ç¨ MySQL æ¶ä¹å¯æ£å¸¸è¿è¡ï¼ä½æ们强çæ¨è MariaDBãå 为å®å¼ç®±å³ç¨ï¼èæ¨å¿
é¡»è¿è¡é
ç½®æ´æ¹æè½ä½¿ MySQL æ£å¸¸å·¥ä½ã
### æ°æ®åºè®¾ç½®
è¦è®¾ç½®æ°æ®åºï¼åªéåå»ä¸»èåä¸ç`Setup DVWA`æé®ï¼ç¶ååå»`Create / Reset Database`æé®ã è¿å°ä¸ºæ¨å建/éç½®æ°æ®åºï¼å¹¶å¡«å
¥ä¸äºæ°æ®ã
å¦ææ¨å¨å°è¯å建æ°æ®åºæ¶æ¶å°é误æ¶æ¯ï¼è¯·ç¡®ä¿æ¨å¨ `./config/config.inc.php` ä¸çæ°æ®åºåæ®æ¯æ£ç¡®çã *config.inc.php.dist ä»
ä½ä¸ºç¤ºä¾ï¼./config/config.inc.php ä¸çå
容ä¸å¿
ä¸å
¶ç¸åã*
åéé»è®¤è®¾ç½®å¦ä¸ï¼
```php
$_DVWA[ 'db_user' ] = 'dvwa';
$_DVWA[ 'db_password' ] = 'p@ssw0rd';
$_DVWA[ 'db_database' ] = 'dvwa';
```
注æï¼å¦æä½ ä½¿ç¨çæ¯ MariaDB èä¸æ¯ MySQLï¼ Kali é»è®¤ä½¿ç¨ MariaDB ï¼ï¼é£ä¹ä½ ä¸è½ä½¿ç¨æ°æ®åº root ç¨æ·ï¼ä½ å¿
é¡»å建ä¸ä¸ªæ°çæ°æ®åºç¨æ·ã 为æ¤ï¼è¯·ä»¥ root ç¨æ·èº«ä»½è¿æ¥å°æ°æ®åºï¼ç¶å使ç¨ä»¥ä¸å½ä»¤ï¼
```mysql
mysql> create database dvwa;
Query OK, 1 row affected (0.00 sec)
mysql> create user dvwa@localhost identified by 'p@ssw0rd';
Query OK, 0 rows affected (0.01 sec)
mysql> grant all on dvwa.* to dvwa@localhost;
Query OK, 0 rows affected (0.01 sec)
mysql> flush privileges;
Query OK, 0 rows affected (0.00 sec)
```
### å
¶ä»é
ç½®
æ ¹æ®æ¨çæä½ç³»ç»ä»¥å PHP çæ¬ï¼æ¨å¯è½å¸ææ´æ¹é»è®¤é
ç½®ã ç¸å
³æ件çä½ç½®å æºå¨èå¼ã
**æ件夹æé**ï¼
* `./hackable/uploads/` - éè¦å
许webæå¡å¯åï¼ç¨äºæ件ä¸ä¼ ï¼ã
* `./external/phpids/0.6/lib/IDS/tmp/phpids_log.txt` - éè¦å
许webæå¡å¯åï¼å¦æä½ æ³ä½¿ç¨ PHPIDSï¼ã
**PHPé
ç½®**:
* `allow_url_include = on` - å
许è¿ç¨æ件å
å« (RFI) [[allow_url_include](https://secure.php.net/manual/en/filesystem.configuration.php#ini.allow-url-include)]
* `allow_url_fopen = on` - å
许è¿ç¨æ件å
å« (RFI) [[allow_url_fopen](https://secure.php.net/manual/en/filesystem.configuration.php#ini.allow-url-fopen)]
* `safe_mode = off` - ï¼å¦æ PHP <= v5.4ï¼å
许 SQL 注å
¥ï¼SQLiï¼ [[safe_mode](https://secure.php.net/manual/en/features.safe-mode.php)]
* `magic_quotes_gpc = off` - ï¼å¦æ PHP <= v5.4ï¼å
许 SQL 注å
¥ï¼SQLiï¼ [[magic_quotes_gpc](https://secure.php.net/manual/en/security.magicquotes.php)]
* `display_errors = off` - ï¼å¯éï¼éè PHP è¦åæ¶æ¯ä»¥ä½¿å
¶ä¸é£ä¹åé¿ [[display_errors](https://secure.php.net/manual/en/errorfunc.configuration.php#ini.display-errors)]
**æ件: `config/config.inc.php`**:
* `$_DVWA[ 'recaptcha_public_key' ]` & `$_DVWA[ 'recaptcha_private_key' ]` - è¿äºå¼éè¦ä»https://www.google.com/recaptcha/admin/create çæ
### é»è®¤çåè¯
**é»è®¤ username = `admin`**
**é»è®¤ password = `password`**
_...å¾å®¹æ被æ´åç ´è§£ï¼)_
ç»å½ URLï¼http://127.0.0.1/login.php
_注æï¼å¦ææ¨å° DVWA å®è£
å°ä¸åçç®å½ä¸ï¼ä¸è¿°ç»å½ URL å°ææä¸åã_
- - -
## Docker容å¨
- [dockerhub 页é¢](https://hub.docker.com/r/vulnerables/web-dvwa/)
`docker run --rm -it -p 80:80 vulnerables/web-dvwa`
ç±äºèçæ¬ç MySQL é®é¢ï¼è¯·ç¡®ä¿æ¨æ£å¨ä½¿ç¨ aufsã è¿è¡ `docker info` æ¥æ£æ¥ä½ çåå¨é©±å¨ç¨åºã å¦æå®ä¸æ¯aufsï¼è¯·æ´æ¹å®ä¸ºaufsã æ¯ä¸ªæä½ç³»ç»é½æå
³äºå¦ä½æ§è¡æ¤æä½çæåï¼ä½å®ä»¬ææä¸åï¼å æ¤æ们ä¸åæ¤èµè¿°ã
- - -
## æ
éæé¤
以ä¸çæ
éæé¤æä½ï¼å设æ¨ä½¿ç¨çæ¯åºäº Debian çåè¡çï¼ä¾å¦ DebianãUbuntu å Kaliã 对äºå
¶ä»åè¡çï¼å¯åèæ§è¡ï¼ä½éè¦éå½æ´æ¢å½ä»¤ã
### é
ç½®æ°æ®åºæ¶ç"Access denied"é误
å¦ææ¨å¨é
ç½®æ°æ®åºæ¶çå°ä»¥ä¸å
容ï¼å表示é
ç½®æ件ï¼./config/config.inc.phpï¼ä¸çç¨æ·åæå¯ç ï¼ä¸æ°æ®åºä¸é
ç½®çç¨æ·åæå¯ç ä¸å¹é
ï¼
```
Database Error #1045: Access denied for user 'notdvwa'@'localhost' (using password: YES).
```
该é误åè¯æ¨ï¼æ¨æ£å¨ä½¿ç¨ç¨æ·å`notdvwa`ã
以ä¸é误表示ï¼æ¨å¨é
ç½®æ件ä¸è®¾ç½®äºé误çæ°æ®åºã
```
SQL: Access denied for user 'dvwa'@'localhost' to database 'notdvwa'
```
è¿è¡¨ç¤ºæ¨æ£å¨ä½¿ç¨ç¨æ· `dvwa` 并è¯å¾è¿æ¥å°æ°æ®åº `notdvwa`ã
é¦å
è¦åçï¼æ¯å次确认æ¨é
ç½®æ件ä¸çå
容æ¯å¦ççå¦æ¨ææ³ã
å¦æå®ç¬¦åæ¨çé¢æï¼æ¥ä¸æ¥è¦åçæ¯æ£æ¥ï¼æ¨æ¯å¦å¯ä»¥ä½¿ç¨å½ä»¤è¡ï¼ä»¥æ¨é
ç½®çç¨æ·èº«ä»½ç»å½æ°æ®åºã åè®¾ä½ çæ°æ®åºç¨æ·æ¯ `dvwa`ï¼å¯ç æ¯ `p@ssw0rd`ï¼è¿è¡ä»¥ä¸å½ä»¤ï¼
```
mysql -u dvwa -pp@ssw0rd -D dvwa
```
*注æï¼-på没æç©ºæ ¼*
å¦ææ¨çå°ä»¥ä¸å
容ï¼åå¯ç æ¯æ£ç¡®çï¼
```
Welcome to the MariaDB monitor. Commands end with ; or \g.
Your MariaDB connection id is 14
Server version: 10.3.22-MariaDB-0ubuntu0.19.10.1 Ubuntu 19.10
Copyright (c) 2000, 2018, Oracle, MariaDB Corporation Ab and others.
Type 'help;' or '\h' for help. Type '\c' to clear the current input statement.
MariaDB [dvwa]>
```
ç±äºæ¨å¯ä»¥å¨å½ä»¤è¡ä¸è¿è¡è¿æ¥ï¼å æ¤é
ç½®æ件ä¸å¯è½æé®é¢ï¼è¯·ä»ç»æ£æ¥ãå¦æä»ç¶æ æ³æ£å¸¸å·¥ä½ï¼è¯·å¨ GitHub ä¸æ交issueã
å¦ææ¨çå°ä»¥ä¸å
容ï¼åæ¨ä½¿ç¨çç¨æ·åæå¯ç æ误ã éå¤ [æ°æ®åºè®¾ç½®](#æ°æ®åºè®¾ç½®) æ¥éª¤ï¼å¹¶ç¡®ä¿å¨æ´ä¸ªè¿ç¨ä¸ä½¿ç¨ç¸åçç¨æ·ååå¯ç ã
```
ERROR 1045 (28000): Access denied for user 'dvwa'@'localhost' (using password: YES)
```
å¦ææ¨å¾å°ä»¥ä¸ä¿¡æ¯ï¼åç¨æ·åæ®æ£ç¡®ï¼ä½ç¨æ·æ æ访é®æ°æ®åºã å次éå¤è®¾ç½®æ¥éª¤å¹¶æ£æ¥æ¨æ£å¨ä½¿ç¨çæ°æ®åºå称ã
```
ERROR 1044 (42000): Access denied for user 'dvwa'@'localhost' to database 'dvwa'
```
æåä¸ä¸ªæ¨å¯è½éå°çé误æ¯ï¼
```
ERROR 2002 (HY000): Can't connect to local MySQL server through socket '/var/run/mysqld/mysqld.sock' (2)
```
è¿ä¸æ¯èº«ä»½éªè¯é®é¢ï¼èæ¯åè¯æ¨æ°æ®åºæå¡å¨æ²¡æè¿è¡ã å¦ä¸å¯å¨æ°æ®åºæå¡å¨ï¼
```sh
sudo service mysql start
```
### Unknown authentication methodé误
PHP æ æ³åä¸ææ°çæ¬ç MySQL é»è®¤é
ç½®ä¸çæ°æ®åºéä¿¡ã å¦ææ¨å°è¯è¿è¡é
ç½®èæ¬å¹¶æ¶å°ä»¥ä¸æ¶æ¯ï¼å表示æ¨æ£å¨ä½¿ç¨è¿ä¸ªé»è®¤é
ç½®ã
```
Database Error #2054: The server requested authentication method unknown to the client.
```
æ¨æ两个éæ©ï¼æç®åçæ¯å¸è½½ MySQL 并å®è£
MariaDBã 以ä¸æ¯æ¥èª MariaDB 项ç®çå®æ¹æåï¼
æè
ï¼æç
§ä»¥ä¸æ¥éª¤æä½ï¼
1. 以 root ç¨æ·èº«ä»½ç¼è¾ä»¥ä¸æ件ï¼`/etc/mysql/mysql.conf.d/mysqld.cnf`
2. å¨ `[mysqld]` è¡ä¸ï¼æ·»å 以ä¸å
å®¹ï¼ `default- authentication-plugin=mysql_native_password`
3. éå¯æ°æ®åºï¼`sudo service mysql restart`
4. æ£æ¥æ°æ®åºç¨æ·ç身份éªè¯æ¹æ³ï¼
```sql
mysql> select Host,User, plugin from mysql.user where mysql.user.User = 'dvwa';
+-----------+------------------+-----------------------+
| Host | User | plugin |
+-----------+------------------+-----------------------+
| localhost | dvwa | caching_sha2_password |
+-----------+------------------+-----------------------+
1 rows in set (0.00 sec)
```
5. ä½ å¯è½ä¼çå° `caching_sha2_password`ã å¦ææ¯è¿æ ·ï¼è¯·è¿è¡ä»¥ä¸å½ä»¤ï¼
```sql
mysql> ALTER USER dvwa@localhost IDENTIFIED WITH mysql_native_password BY 'p@ssw0rd';
```
6. éæ°è¿è¡æ£æ¥ï¼æ¨ç°å¨åºè¯¥çå°`mysql_native_password`ã
```sql
mysql> select Host,User, plugin from mysql.user where mysql.user.User = 'dvwa';
+-----------+------+-----------------------+
| Host | User | plugin |
+-----------+------+-----------------------+
| localhost | dvwa | mysql_native_password |
+-----------+------+-----------------------+
1 row in set (0.00 sec)
```
ç»è¿ä»¥ä¸æ¥éª¤ï¼è®¾ç½®è¿ç¨ç°å¨åºè¯¥å¯ä»¥æ£å¸¸å·¥ä½äºã
å¦ææ¨æ³äºè§£æ´å¤ä¿¡æ¯ï¼è¯·åé
以ä¸é¡µé¢ï¼ã
### æ°æ®åºé误 Error #2002: No such file or directory.
æ°æ®åºæå¡å¨æ²¡æè¿è¡ã å¨åºäº Debian çåè¡çä¸ï¼è¿å¯ä»¥éè¿ä»¥ä¸æ¹å¼å®æï¼
```sh
sudo service mysql start
```
### "MySQL server has gone away" å "Packets out of order" é误
åºç°è¿äºé误çåå æå¤ç§ï¼ä½ææå¯è½çåå æ¯æ¨è¿è¡çæ°æ®åºæå¡å¨çæ¬ä¸ PHP çæ¬ä¸å
¼å®¹ã
æ常è§çæ¯ï¼ä½ è¿è¡äºææ°çæ¬ç MySQL ä¸ PHP æé
é¨ç½²ï¼èè¿ä¸¤è
并ä¸ååå
¼å®¹ãæ好ç建议æ¯ï¼æ¾å¼ MySQL 并å®è£
MariaDBï¼å 为è¿ï¼è¯æ³¨ï¼ä½¿ç¨ææ°çMySQLï¼ä¸æ¯æ们å¯ä»¥æ¯æçã
æå
³æ´å¤ä¿¡æ¯ï¼è¯·åé
ï¼
### SQL注å
¥å¨ PHP v5.2.6.ä¸ä¸æ£å¸¸
PHP 5.x çç»´æ¤å·²äº 2019 å¹´ 1 æç»æ¢ï¼å æ¤æ们建议æ¨ä½¿ç¨å½å 7.x çæ¬è¿è¡ DVWAï¼å¦ææ¨ä¸å®è¦ä½¿ç¨ 5.x â¦â¦
å¦ææ¨ä½¿ç¨çæ¯ PHP v5.2.6 ææ´é«çæ¬ï¼åéè¦æ§è¡ä»¥ä¸æä½æè½ä½¿ SQL 注å
¥åå
¶ä»æ¼æ´åæ¥ä½ç¨ã
å¨`.htaccess`ä¸ï¼
å°ä»¥ä¸è®¾ç½®ï¼
```php
php_flag magic_quotes_gpc off
#php_flag allow_url_fopen on
#php_flag allow_url_include on
```
æ¿æ¢ä¸ºï¼
```php
magic_quotes_gpc = Off
allow_url_fopen = On
allow_url_include = On
```
### å½ä»¤è¡æ³¨å
¥ ä¸å·¥ä½
-A. Apache å¯è½æ²¡æ足å¤çæéå¨ Web æå¡å¨ä¸è¿è¡å½ä»¤ã å¦ææ¨å¨ Linux ä¸è¿è¡ DVWAï¼è¯·ç¡®ä¿æ¨ä»¥ root 身份ç»å½ã å¨ Windows ä¸ä»¥ç®¡çå身份ç»å½ã
### CentOSä¸ä¸ºä»ä¹ä¸è½è¿æ¥æ°æ®åºï¼
æ¨å¯è½éå° SELinux çé®é¢ã ç¦ç¨ SELinux æè¿è¡æ¤å½ä»¤ä»¥å
许 Web æå¡å¨ä¸æ°æ®åºéä¿¡ï¼
```
setsebool -P httpd_can_network_connect_db 1
```
### å
¶ä»äºé¡¹
æå
³ææ°çæ
éæé¤ä¿¡æ¯ï¼è¯·é
读 GitHub Issues ä¸ä»å¼æ¾æå·²å
³éçé®é¢ï¼
å¨æ交issueä¹åï¼è¯·ç¡®ä¿æ¨æ£å¨è¿è¡ä»åºï¼repoï¼ä¸ææ°çæ¬ç代ç ã注æï¼ä¸æ¯ææ°åå¸ (release) çæ¬ï¼èæ¯ master åæ¯çææ°ä»£ç ã
å¦ææ交issueï¼è¯·è³å°å
å«ä»¥ä¸ä¿¡æ¯ï¼
- æä½ç³»ç»
- æ¨æ£å¨æ¥åçé误åçæ¶ï¼ç´§æ¥çæ¥èª Web æå¡å¨é误æ¥å¿çæå 5 è¡
- å¦ææ¯æ°æ®åºèº«ä»½éªè¯é®é¢ï¼è¯·æ§è¡ä¸æä¸çæ¥éª¤å¹¶å¯¹æ¯ä¸ªæ¥éª¤è¿è¡æªå¾ãæ交è¿äºæªå¾ï¼åæ¶æ交æ°æ®åºé
ç½®æ件ä¸ï¼ç¨æ·åå¯ç é¨åçå±å¹æªå¾ã
- å®æ´æè¿°åºäºä»ä¹é®é¢ï¼æ¨ææåçä»ä¹ï¼ä»¥åæ¨å·²ç»éåäºä»ä¹æªæ½ã 类似"ç»å½ä¸æ"è¿ç§æè¿°ï¼ä¸è¶³ä»¥è®©æ们äºè§£æ¨çé®é¢å¹¶å¸®å©è§£å³å®ã
- - -
## é¾æ¥
主页:
项ç®ä¸»é¡µ:
*Created by the DVWA team*