Highlights
Task
LOs Assessed 1. Identify, analyse and discuss the main threats to databases and web applications.
2. Analyse and appraise the necessary countermeasures to secure databases and web applications.
3. Apply the methods and techniques used in designing secure databases and webapplications.
4. Discuss the legal and ethical considerations related to data and web privacy and security.
The aim of this coursework is to analyse, exploit and discuss the security vulnerabilities of a website. Please see Appendix A for detailed instructions on how to access this website.
1. Fingerprinting/Mapping of the website: you should investigate the web site to determine the following:
(a) the name and version of (i) the Operating System; (ii) the Web Server; and (iii) the server-side web technology used.
(b) the list of all the first-level directories of the website, including any hidden directories.
2. Identifying and exploiting the website vulnerabilities: you should identify and exploit the following four vulnerabilities:
(a) Stealing users’ credentials using SQL injection: Identify a place on the website that is vulnerable to SQL injection and exploit it to list the emails and (hashed) passwords of all users, using two different approaches: (i) a manual approach, by injecting code and (ii) an automatic approach, using sqlmap.
(b) Authentication bypass using SQL injection: Register a new user (author) on the website, then try to sign-in that user. You will get a message saying that you need to get approved by an administrator first (before you could start posting your adventures to the website). Identify a place within the web site where you could authenticate as an admin user then “Approve” your registered user.
(c) File Upload: An approved user (author) is able to post images of their adventures. However, instead of uploading an image, show that you can upload the script available from this link1 and that you are able to successfully access that script once uploaded into the website.
(d) Stored XSS: Find a place on the website that is vulnerable to Stored XSS and exploit it by injecting a pop-up box that displays your name.
For each exploited vulnerability, your report should include screenshots to evidence the steps and results of your exploits.
The diagram shows that the application is accessed from both (i) the Internet (authors, customers and admin) through the web server located in the Demilitarised Zone (DMZ) and (ii) the company’s internal network trough Active Directory (Domain Controller).
The company’s “admin” team consists of the following staff:
To allow working from home all staff can access the database server remotely. However, when in the office, staff access the database server through their Windows accounts.
Discuss potential risks to the company to be able to assess and score risks.
To help you with this task, consider the following:
4. Discussing/Implementing security measures: Having analysed risks in section 3, discuss the security measuresthat can be implemented in order to harden the security of the web application and database. As part of this task, research best practice in web server security, and describe any changes that need to be implemented in the webserver configuration (conf folder) in order to strengthen the five weaknesses identified in task 3.
Note: For task 3 and 4, please cite any resources used in your answers (See RGU Library for help with citations/referencing).
5. Forensics of web attacks: You are given a sample of the entries found in the webserver log file (available on Moodle) to analyse indicators of security attacks. In particular, you are expected to:
a. Look for the following
(i) TWO SQL Injection attacks,
(ii) ONE Directory Traversal attacks, and
(iii) ONE Login Brute Force Attack.
For each attack indicate the full log entry (origin IP address; Date/Time; HTTP request made) and a description of any data that was breached.
b. Discuss the legal and ethical implications for a company when discovering the above attacks.
This CMM523-IT Computer Science Assignment has been solved by our IT Computer Science Expert at My Uni Paper. Our Assignment Writing Experts are efficient to provide a fresh solution to this question. We are serving more than 10000+ Students in Australia, UK & US by helping them to score HD in their academics. Our Experts are well trained to follow all marking rubrics & referencing Style. Be it a used or new solution, the quality of the work submitted by our assignment experts remains unhampered.
You may continue to expect the same or even better quality with the used and new assignment solution files respectively. There’s one thing to be noticed that you could choose one between the two and acquire an HD either way. You could choose a new assignment solution file to get yourself an exclusive, plagiarism (with free Turn tin file), expert quality assignment or order an old solution file that was considered worthy of the highest distinction.
© Copyright 2026 My Uni Papers – Student Hustle Made Hassle Free. All rights reserved.