Beginner SQL Injection - CTF Walkthrough Part 1

Опубликовано: 06 Сентябрь 2026
на канале: Daniel Lowrie
1,655
106

Welcome to Part 1 of our full Boot-to-Root CTF Walkthrough of DC-3 from VulnHub! If you are an aspiring pentester or just started learning ethical hacking, this challenge provides crucial, real-world experience in web exploitation.

In this episode, we focus on the initial foothold and database compromise, mastering two of the most critical skills for the CompTIA PenTest+ and OSCP exams: SQL Injection and Password Cracking.

Here is the full penetration testing methodology covered in Part 1:

Reconnaissance & Enumeration: Using tools like Nmap to identify the running web service and map out the target's attack surface.

Vulnerability Scanning: Employing Joomscan to quickly find a known vulnerability in the exposed Joomla CMS.

Database Compromise: Executing a powerful SQL Injection (SQLi) attack using SQLmap to dump hashed user credentials from the backend database.

Credential Cracking: Utilizing John the Ripper to quickly identify and crack the hashed password, gaining admin access to the web application.

Initial Foothold Setup: Preparing the web shell for command execution—setting the stage for privilege escalation in Part 2!

Stay tuned for Part 2 where we take our webshell access and pivot into the system, perform Linux enumeration, and achieve Root Access to grab the final flag!

🔗 Tools & Resources Used in This Video
CTF Target: DC-3 VulnHub (Download link: https://download.vulnhub.com/dc/DC-3-... )
Vulnerability Scanner: Joomscan
SQL Injection Tool: SQLmap
Password Cracker: John the Ripper
OS/Platform: Kali Linux
👍 If you want to see Part 2, hit that Like button and Subscribe!

#DC3 #CTFWalkthrough #BootToRoot #SQLInjection #SQLmap #JoomlaHacking #JohnTheRipper #PasswordCracking #Joomscan #PenetrationTesting #EthicalHacking #BeginnerHacking #OSCPPrep #PenTestPlus #HackingTutorial #WebExploitation #ethicalhacker #CEH #pjpt #pnpt #ejpt #hackingcourse