3809ICT: Assignment 2 Specification Assessment

Download Solution Order New Solution

Individual Assignment

This assignment aims to enhance knowledge and understanding of attacks on Active Directory systems through a penetration testing practice. This understanding will be demonstrated by submitting a report of the penetration test. The assignment also contains several questions for which you need to answer and provide details that support your answers.

Task

There are three main tasks:

1. Performing attacks on the target VM and composing a testing report.

Your report must include a step-by-step demonstration of how you performed the attack, using both text explanations and screenshots. You are also required to provide answers to the relevant questions. The demonstration should be fully reproducible another person following your documented steps should be able to replicate the attack exactly as described. Please note that marks will be deducted for any steps that are unclear, incomplete, or not reproducible.

2. Capturing the TWO flags and displaying the flag content

As in Assignment 1, the flag text strings start with a prefix “FLAG - ”

3. Answer the following questions:

  • Question 1: What are the SMB directory shares open on the Active Directory Server? Document them. (Hint: Use Nmap SMB discovery scripts) 
  • Question 2: What does the Active Directory structure look like? List the groups (a.k.a., Organisational Units) under the domain songbirds.snakes. 
  • Question 3: Identify two Active Directory user accounts that each use a different easily guessable password. For each account, provide the username and its associated weak password.

Brief summary of assessment requirements

Purpose:
Produce a reproducible penetration-test report that demonstrates your understanding of attacks against Active Directory (AD) environments. The deliverable combines a documented, step‑by‑step attack demonstration (text + screenshots), answers to specific AD discovery questions, and the capture/display of two assigned flags.

Core tasks (three):

  1. Perform attacks on the provided target VM and prepare a full testing report that someone else can reproduce exactly.
  2. Capture TWO flags from the VM and show their contents (flags begin with flags).
  3. Answer three technical questions about the AD target:
    • List SMB directory shares on the AD server.
    • Describe the AD structure (OUs/groups) under the domain songbirds.snakes.
    • Identify two AD user accounts each using a different easily-guessable password; provide username + weak password for each.

Marking emphasis: clarity and reproducibility of steps, correct identification of SMB shares and AD structure, successful flag capture, and accurate answers. Points are deducted for missing/unclear steps or non-reproducible procedures.

Key pointers the report must cover: 

  • Context & scope: VM name, IP address, date/time, test boundaries and authorization statement (lab only).
  • Environment setup: tools, versions, and platform used (e.g., Kali VM, Windows host, VPN).
  • Stepwise methodology: clear phases (planning, reconnaissance, enumeration, exploitation, post‑exploitation, cleanup).
  • Evidence: screenshots, logs, output excerpts, and file paths for every significant step (including where flags were found).
  • Findings: list of SMB shares; AD OU/group listing for songbirds.snakes; two accounts with weak passwords (username + password) — include how you validated them.
  • Reproducibility: exact commands or GUI actions (where allowed by policy) or a high-level description plus available scripts/output—presented so the grader can replicate results.
  • Risk & mitigation notes: high-level recommendations to remediate the weaknesses you found.
  • Appendix: raw outputs, screenshots, behaviour logs, and the captured flag content.

How the Academic Mentor guided the student step‑by‑step process

Note: Mentor guidance focused on methodology, documentation quality, and safety/ethics in a lab environment. No unsafe exploit instructions were provided.

Step 1: Confirm scope & ethics

  • Mentor ensured the student documented that testing is authorized on the provided VM only, and reminded them not to apply techniques on live systems.
  • Student recorded VM IP, hostname, class credentials (if provided), testing dates, and any constraints.

Step 2: Prepare lab environment & tools

  • Mentor recommended a consistent environment (tool versions, OS) and asked the student to list everything in the report: OS, VM snapshot used, tool names and versions (e.g., port scanner, AD enumeration tools, credential check utilities).
  • Emphasised taking a snapshot before starting so work is repeatable and recoverable.

Step 3: Planning & reconnaissance (high-level)

  • Mentor instructed the student to create a short plan with objectives (e.g., discover open services, enumerate AD structure, locate flags), expected deliverables, and success criteria.
  • Encouraged the use of passive and active reconnaissance in a limited, documented way and to record timestamps for each action.

Step 4: Enumeration (document everything)

  • Mentor advised focusing on SMB discovery and AD enumeration, and to capture and save outputs that answer the assignment questions.
  • Student captured: SMB share listings (noted exact commands or GUI steps used), AD domain structure summaries, and user lists or group membership evidence.
  • Mentor stressed clear labeling of screenshots (what the screenshot shows, command used, and file name).

Step 5: Credential validation and weak-password identification (controlled, documented)

  • Mentor directed the student to test credential guesses carefully within the lab (and to document the method used to identify weak passwords).
  • Student listed each account identified with weak credentials, described how the password was validated (login attempt evidence), and included relevant outputs/screenshots.

Step 6: Flag capture (evidence trail)

  • Mentor required that the student show the exact evidence trail for each flag: the file path, the screenshot showing the flag, and a short description of how the file was discovered (e.g., enumeration step X revealed share Y containing file Z).
  • Emphasised reproducibility: every action that led to a flag needed enough context so another grader could find the same file using the documented steps.

Step 7: Report writing & reproducibility practices

  • Mentor coached the student to structure the report into clear sections: Introduction, Environment, Methodology, Findings (with sub‑sections for each required question), Evidence Appendix, Remediation Recommendations, and Conclusion.
  • Advised writing repeatable steps: timestamped actions, exact tool options where safe, or a description plus saved output files.
  • Insisted on including a short “How to reproduce” checklist near the top for the grader.

Step 8: Remediation & reflection

  • Mentor asked for a short remediation section tied to each finding (e.g., harden SMB shares, enforce password policy, disable unnecessary shares, review AD user password policies) and for a reflection on what defensive controls would have prevented the attack path the student followed.

Step 9: Final check & submission

  • Mentor ran through a submission checklist with the student: are the flags displayed clearly? Are the answers to the three questions supported by screenshots/output? Is every step reproducible? Are all files and screenshot captions included?
  • Student then exported the report and included raw outputs in the appendix.

Outcome what the student delivered and how it was achieved

Deliverables produced:

  • A full penetration-test report with: scope/authority, lab environment, methodology, sequenced steps, screenshots and saved outputs.
  • Clear documentation of the SMB shares discovered (answers to Question 1) with supporting Nmap/SMB output references.
  • An organized listing of the AD structure / OUs and groups under songbirds.snakes (Question 2) with exported directory listings or console screenshots.
  • Identification of two AD user accounts each using a different weak password (Question 3), with login attempt evidence and timestamps.
  • Capture and display of the two flags (file path + screenshot + copied text).
  • A remediation section with practical, prioritized recommendations.

How it was achieved: by following a disciplined, documented workflow: controlled lab setup → systematic enumeration → careful validation of credentials → evidence capture → clear reporting and reproducibility checks under mentor supervision.

Learning objectives covered

  • Practical AD security awareness: understand common Active Directory attack surfaces (SMB shares, weak passwords, misconfigured OUs).
  • Methodical penetration testing workflow: plan → enumerate → test → validate → document → remediate.
  • Reproducible reporting: produce a report that conveys steps clearly so another competent person can replicate results.
  • Evidence collection & presentation: capture and present logs/screenshots and annotate them for clarity.
  • Ethics & legal boundaries: operate only in authorized lab environments and learn to document authorization.
  • Remediation reasoning: translate technical findings into prioritized, practical fixes for defenders.

Get Your Academic Assignment Right Reference or Custom Solution

Boost your learning and improve your grades with our carefully prepared assignment solutions. The sample solution provided here is for reference only designed to help you understand the structure, methodology, and key insights. Submitting it as your own work can lead to plagiarism issues, so always use it as a guide for your own learning.

If you want a fully original, plagiarism-free solution tailored to your requirements, our team of professional academic writers can create a custom assignment just for you. With a fresh solution, you get:

  • Unique, 100% original content crafted to your instructions.
  • Expertly researched material with proper referencing.
  • Time-saving convenience and stress-free submission.
  • Guaranteed academic integrity, helping you avoid plagiarism concerns.

Take control of your grades today:

Download Sample Solution              Order Fresh Assignment

Get It Done! Today

Country
Applicable Time Zone is AEST [Sydney, NSW] (GMT+11)
+

Every Assignment. Every Solution. Instantly. Deadline Ahead? Grab Your Sample Now.