Analysis of Website Security Using Sql Injection Penetration Testing on Damn Vulnerable Web Application
DOI:
https://doi.org/10.62671/nmw6kn69Keywords:
Website Security, DVWA, Cybersecurity, Penetration Testing, SQL InjectionAbstract
Website security has become one of the primary concerns in the development of information systems due to the increasing number of cyberattacks targeting web-based applications. Among various cyber threats, SQL Injection remains one of the most critical vulnerabilities because it allows attackers to manipulate Structured Query Language (SQL) statements through unsensitized user inputs, potentially resulting in unauthorized access, data leakage, data manipulation, or complete system compromise. This research aims to analyse website vulnerabilities against SQL Injection attacks using a penetration testing approach on the Damn Vulnerable Web Application (DVWA), a deliberately vulnerable web application widely utilized for cybersecurity education and security assessment. The research employed an experimental methodology consisting of reconnaissance, vulnerability identification, exploitation, and vulnerability analysis. Penetration testing was conducted using Burp Suite, browser developer tools, and manually crafted SQL Injection payloads. The testing results demonstrated that the low-security configuration of DVWA was highly susceptible to authentication bypass attacks, allowing unauthorized access to sensitive information. The analysis further revealed that the primary causes of these vulnerabilities were inadequate input validation, dynamic SQL query construction, and the absence of parameterized queries or prepared statements. This study emphasizes the importance of implementing secure coding practices, input validation, parameterized SQL queries, and Web Application Firewall (WAF) technologies to mitigate SQL Injection risks. The findings contribute to cybersecurity education by providing practical evidence of common SQL Injection vulnerabilities and effective mitigation strategies that can be adopted by software developers and information system administrators
Downloads
References
[1] OWASP Foundation, OWASP Top 10: The Ten Most Critical Web Application Security Risks, 2021.
[2] OWASP Foundation, OWASP Web Security Testing Guide (WSTG) Version 4.2, 2021.
[3] OWASP Foundation, SQL Injection Prevention Cheat Sheet, 2023.
[4] OWASP Foundation, Application Security Verification Standard (ASVS) Version 4.0.3, 2021.
[5] MITRE Corporation, CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), 2024.
[6] FIRST, Common Vulnerability Scoring System (CVSS) Version 3.1 Specification, 2019.
[7] National Institute of Standards and Technology (NIST), Secure Software Development Framework (SSDF) Version 1.1, NIST SP 800-218, 2022.
[8] National Institute of Standards and Technology (NIST), Security and Privacy Controls for Information Systems and Organizations, NIST SP 800-53 Rev. 5, 2020.
[9] PortSwigger Ltd., Burp Suite Documentation, 2024.
[10] PortSwigger Ltd., Web Security Academy – SQL Injection, 2024.
[11] DVWA Project Team, Damn Vulnerable Web Application Documentation, GitHub, 2024.
[12] A. Halfond, J. Viegas, and A. Orso, "A Classification of SQL Injection Attacks and Countermeasures," Proceedings of the International Symposium on Secure Software Engineering, 2006.
[13] A. K. Jain and B. B. Gupta, "SQL Injection Detection and Prevention Techniques: A Survey," Journal of Information Security and Applications, vol. 56, 2021.
[14] M. Almseidin, M. Alzubi, S. Kovacs, and M. Alkasassbeh, "Evaluation of SQL Injection Detection Techniques for Web Applications," IEEE Access, vol. 10, pp. 48731–48745, 2022.
[15] B. B. Gupta and A. Goyal, "Recent Advances in Web Application Security Against Injection Attacks," Future Generation Computer Systems, vol. 131, pp. 190–205, 2022.
[16] N. Antunes and M. Vieira, "Comparing the Effectiveness of Penetration Testing and Static Code Analysis in Web Security," Information and Software Technology, vol. 145, 2022.
[17] R. Kumar, S. Tanwar, and N. Kumar, "Secure Web Applications Through Penetration Testing Approaches," IEEE Access, vol. 11, pp. 21150–21170, 2023.
[18] S. Ali, M. Khan, and H. Abbas, "Analysis of SQL Injection Vulnerabilities Using Automated Security Testing," Computers & Security, vol. 128, 2023.
[19] Y. Li, H. Zhang, and J. Wang, "Machine Learning-Based Detection of SQL Injection Attacks in Modern Web Applications," IEEE Access, vol. 11, pp. 74532–74546, 2023.
[20] M. Alenezi and A. Alshammari, "A Comparative Analysis of SQL Injection Prevention Mechanisms," Journal of King Saud University – Computer and Information Sciences, vol. 35, no. 7, 2023.
[21] A. Alwan and M. Younis, "Secure Coding Practices for Web Application Security," International Journal of Information Security, vol. 22, no. 2, pp. 221–238, 2023.
[22] B. Schneier, Secrets and Lies: Digital Security in a Networked World. Wiley, 2015.
[23] R. S. Pressman and B. Maxim, Software Engineering: A Practitioner's Approach, 9th ed. McGraw-Hill, 2020.
[24] I. Sommerville, Software Engineering, 10th ed. Pearson, 2016.
[25] W. Stallings, Network Security Essentials: Applications and Standards, 7th ed. Pearson, 2020.
[26] W. Stallings, Effective Cybersecurity. Addison-Wesley, 2018.
[27] CERT Coordination Center, CERT Secure Coding Standards, Carnegie Mellon University, 2022.
[28] Open Worldwide Application Security Project, OWASP DevSecOps Guideline, 2023.
[29] NIST, National Vulnerability Database (NVD), 2024.
[30] OpenSSF, Secure Software Development Fundamentals, 2023.
[31] M. Howard and D. LeBlanc, Writing Secure Code, 2nd ed. Microsoft Press, 2003.
[32] S. McConnell, Code Complete, 2nd ed. Microsoft Press, 2004.
[33] C. Anley, J. Heasman, F. Lindner, and G. Richarte, The Shellcoder's Handbook, 2nd ed. Wiley, 2007.
[34] B. B. Gupta, Handbook of Computer Networks and Cyber Security, Springer, 2020.
[35] IEEE Computer Society, Guide to the Software Engineering Body of Knowledge (SWEBOK v4), 2024.
[36] ENISA, Threat Landscape Report, European Union Agency for Cybersecurity, 2024.
[37] CISA, Secure by Design: Shifting the Balance of Cybersecurity Risk, 2024.
[38] OWASP Foundation, OWASP API Security Top 10, 2023.
[39] MITRE ATT&CK Team, MITRE ATT&CK Enterprise Matrix, 2024.
[40] ISO/IEC 27001:2022, Information Security, Cybersecurity and Privacy Protection — Information Security Management Systems — Requirements, ISO, 2022.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Rustam Efendi, Ismael (Author)

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.
