BWAPP: Difference between revisions

From Alpine Linux
(Created page with "{{Draft}} [http://sourceforge.net/projects/bwapp/ bWAPP] or a buggy web application is a vulnerable web application. == Install lighttpd, PHP, and MySql == {{:Setting Up Lig...")
 
(replace /etc/init.d with rc-service)
 
(3 intermediate revisions by 2 users not shown)
Line 1: Line 1:
{{Draft}}
{{Draft}}


[http://sourceforge.net/projects/bwapp/ bWAPP] or a buggy web application is a vulnerable web application.
[https://sourceforge.net/projects/bwapp/ bWAPP] or a buggy web application is a vulnerable web application.


== Install lighttpd, PHP, and MySql ==
== Install lighttpd, PHP, and MySql ==
Line 7: Line 7:


Install extra packages:
Install extra packages:
{{Cmd|apk add php-mysql mysql mysql-client php-zlib}}
{{Obsolete|<code>php-mysql</code> doesn't exist anymore}}
{{Cmd|apk add {{pkg|php-mysql}} {{pkg|mysql}} {{pkg|mysql-client}} {{pkg|php-zlib}}}}


== Installing and configuring SQLol ==
== Installing and configuring SQLol ==
Line 17: Line 18:
Switch to the {{Path|webapps}} folder and download the source files
Switch to the {{Path|webapps}} folder and download the source files
{{Cmd|cd /usr/share/webapps/
{{Cmd|cd /usr/share/webapps/
wget http://downloads.sourceforge.net/project/bwapp/bWAPPv1.3/bWAPPv1.3.zip}}
<nowiki>wget https://downloads.sourceforge.net/project/bwapp/bWAPPv1.3/bWAPPv1.3.zip</nowiki>}}


Unpack the archive and delete it  
Unpack the archive and delete it  
Line 39: Line 40:


{{Cmd|<nowiki>/usr/bin/mysql_install_db --user=mysql
{{Cmd|<nowiki>/usr/bin/mysql_install_db --user=mysql
/etc/init.d/mysql start && rc-update add mysql default
rc-service mysql start && rc-update add mysql default
/usr/bin/mysqladmin -u root password 'password'</nowiki>}}
/usr/bin/mysqladmin -u root password 'password'</nowiki>}}


Line 48: Line 49:
{{Cmd|nano -w /usr/share/webapps/bwapp/config.inc.php}}
{{Cmd|nano -w /usr/share/webapps/bwapp/config.inc.php}}


Browse to http://WEBSERVER_IP_ADDRESS/install.php for the installation.
Browse to <nowiki>http://WEBSERVER_IP_ADDRESS/install.php</nowiki> for the installation.


[[Category:SQL]] [[Category:Security]]
[[Category:SQL]] [[Category:Security]]

Latest revision as of 09:58, 17 November 2023

This material is work-in-progress ...

Do not follow instructions here until this notice is removed.
(Last edited by Sertonix on 17 Nov 2023.)

bWAPP or a buggy web application is a vulnerable web application.

Install lighttpd, PHP, and MySql

Basic Installation

For installing the additional packages first activate community packages and update the package index

Install the required packages:

# apk add lighttpd php82 fcgi php82-cgi

Configure Lighttpd

Edit lighttpd.conf (/etc/lighttpd/lighttpd.conf) and uncomment the line:

Contents of /etc/lighttpd/lighttpd.conf

... include "mod_fastcgi.conf" ...

Edit mod_fastcgi.conf (/etc/lighttpd/mod_fastcgi.conf), find and change /usr/bin/php-cgi to /usr/bin/php-cgi82.

Contents of /etc/lighttpd/mod_fastcgi.conf

... "bin-path" => "/usr/bin/php-cgi82" # php-cgi ...

Start lighttpd service and add it to default runlevel

# rc-service lighttpd start # rc-update add lighttpd default

Install extra packages:

This material is obsolete ...

php-mysql doesn't exist anymore (Discuss)

apk add php-mysql mysql mysql-client php-zlib

Installing and configuring SQLol

Create a folder named webapps

mkdir -p /usr/share/webapps/

Switch to the webapps folder and download the source files

cd /usr/share/webapps/ wget https://downloads.sourceforge.net/project/bwapp/bWAPPv1.3/bWAPPv1.3.zip

Unpack the archive and delete it

unzip bWAPPv1.3.zip rm bWAPPv1.3.zip

Rename the folder

mv bWAPP bwapp

Change the folder permissions

chown -R lighttpd /usr/share/webapps/

Create a symlink to the bwapp folder

ln -s /usr/share/webapps/bwapp/ /var/www/localhost/htdocs/bwapp

Configuration and start MySQL

/usr/bin/mysql_install_db --user=mysql rc-service mysql start && rc-update add mysql default /usr/bin/mysqladmin -u root password 'password'

bWAPP configuration

Please add the MySQL configuration details to the bWAPP config file.

nano -w /usr/share/webapps/bwapp/config.inc.php

Browse to http://WEBSERVER_IP_ADDRESS/install.php for the installation.