Hands-on web security testing project using DVWA. Simulated and exploited common vulnerabilities such as SQL Injection, SQL Injection Blind , XSS, CSRF, Brute Force, and Command Injection. Documented each attack with screenshots and provided remediation steps. Demonstrates skills in vulnerability assessment, OWASP Top 10, and security reporting.