In episode 41 of the in-security.org podcast we recommended trying a SQL injection using Mutillidae. To learn how an attacker might go about compromising an insecure system. We've completed the the same task.
Episode 41: http://in-security.org/2016/06/09/handsomeware/
XAMPP: https://www.apachefriends.org/index.html
IronGeek And Mutillidae: http://www.irongeek.com/i.php?page=mutillidae/mutillidae-deliberately-vulnerable-php-owasp-top-10
In-security: http://in-security.org/
Twitter: https://twitter.com/insecurityshow