해커 192.168.56.101
서버 192.168.56.102
엘크 192.168.56.103
윈도우 192.168.56.104
dns .102
gateway .254
dns=서버
계정 획득에 단서가 될 목록
user varchar(15)
password carchar(32)
last_login timestamp
failed_login init
[worbench]
dvwa.st.kr 접속
select users 확인해보기
web2
기존 tables 안에 users 삭제 후 재생성
CREATE TABLE users (
idx int(6),
id_param varchar(15),
pw_param varchar(32),
last_login TIMESTAMP DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP,
failed_login INT(3),
PRIMARY KEY (idx)
);
[edit+]
web2.st.kr
< ?php
    include __DIR__ . "/includes/db.php";
    $id_param = $_GET['id_param'];
    $pw_param = $_GET['pw_param'];
    //디볼트 변수 선언
    $total_failed_login=3;
    $lockout_time=5;
    $account_locked=false;
    //if()
? >
v
db.php
< ?php
    $host="localhost"
    $user="web2";
    $pw="123456";
    $db="web2";
    $conn = mysqli_connect($host, $user, $pw, $db);
    if ($conn
      echo mysqli_connect_error();
    } else {
     echo