Quote:
Originally Posted by michaelk
2.0 is the current version of Kali which was released 11 August 2015 and is based on Debian Jessie. When the package is installed via apt-get everything should be configured...
You do have a phpinfo.php file, so what happens when you try http://localhost/phpinfo.php?
Check your /var/log/apache2/error.log for errors. It might provide a clue why the php pages are not being displayed.
How did you install dvwa?
http://www.geekyshows.com/2014/07/in...ali-linux.html
|
Thanks for the clarification on Kali Linux. That makes sense of course.
When I attempt to to go to
http://localhost/phpinfo.php? I get a message saying; Unable to connect
Iceweasel can't establish a connection to the server at 127.0.0.1.
That is new. The other .php files just come up blank.
I went through my log files and I noticed this;
[Mon Dec 21 07:35:12.412644 2015] [mpm_prefork:notice] [pid 98692] AH00163: Apache/2.4.10 (Debian) configured -- resuming normal operations
[Mon Dec 21 07:35:12.412745 2015] [core:notice] [pid 98692] AH00094: Command line: '/usr/sbin/apache2'
[Mon Dec 21 19:29:57.763967 2015] [core:error] [pid 16261] (13)Permission denied: [client 127.0.0.1:55774] AH00035: access to /dvwa/setup.php denied (filesystem path '/var/www/html/dvwa/setup.php') because search permissions are missing on a component of the path
[Mon Dec 21 19:31:39.542788 2015] [:error] [pid 16262] [client 127.0.0.1:55777] PHP Warning: require_once(dvwa/includes/dvwaPage.inc.php): failed to open stream: Permission denied in /var/www/html/login.php on line 4
[Mon Dec 21 19:31:39.542882 2015] [:error] [pid 16262] [client 127.0.0.1:55777] PHP Fatal error: require_once(): Failed opening required 'dvwa/includes/dvwaPage.inc.php' (include_path='.:/usr/share/php:/usr/share/pear') in /var/www/html/login.php on line 4
[Mon Dec 21 19:32:04.891782 2015] [:error] [pid 16263] [client 127.0.0.1:55778] PHP Warning: require_once(dvwa/includes/dvwaPage.inc.php): failed to open stream: Permission denied in /var/www/html/index.php on line 4
[Mon Dec 21 19:32:04.891854 2015] [:error] [pid 16263] [client 127.0.0.1:55778] PHP Fatal error: require_once(): Failed opening required 'dvwa/includes/dvwaPage.inc.php' (include_path='.:/usr/share/php:/usr/share/pear') in /var/www/html/index.php on line 4
So I went to login.php line 4...
<?php
define( 'DVWA_WEB_PAGE_TO_ROOT', '' );
require_once DVWA_WEB_PAGE_TO_ROOT . 'dvwa/includes/dvwaPage.inc.php';
and dvwa.Page.inc.php...
<?php
if( !defined( 'DVWA_WEB_PAGE_TO_ROOT' ) ) {
define( 'DVWA System error- WEB_PAGE_TO_ROOT undefined' );
exit;
}
session_start(); // Creates a 'Full Path Disclosure' vuln.
// Include configs
require_once DVWA_WEB_PAGE_TO_ROOT . 'config/config.inc.php';
require_once( 'dvwaPhpIds.inc.php' );
So in conclusion, Apache2 is working fine, this is a DVWA problem and I will figure it out. Many thanks to all who so kindly held my hand through this.