CTEC3410: Web Application Penetration Testing

Download Solution Order New Solution

Web Application Penetration Test

Objectives

  • Analyse the given web application to evaluate its current security status

  • Expose any existing vulnerability and misconfiguration on the target

  • Apply allowed tactics and techniques to exploit vulnerabilities and misconfigurations

  • Summarise the findings, processes, and provide mitigation recommendations

  • Demonstrate the ability to develop a final pen test report to a high standard

Background

An e-commerce business has requested a penetration test to be carried out against their newly developed web application created to support and facilitate their business. the business’ management has become suspicious of the quality of the application produced by a web development bureau, and have approached you, as a security consultant, to conduct a web application penetration test.

Requirements

This assessment focuses on your ability to develop a final penetration test report to a high standard:

  1. To conduct the penetration testing, you should consider implementing the steps listed in the OWASP Web Security Testing Guide (WSTG). You will need to research tools and techniques, and to ensure that you have thoroughly documented all processes used in your engagement.
  2. You need to identify vulnerabilities and misconfigurations, you need to conduct a comprehensive exploit attempt of all vulnerabilities and misconfigurations discovered, demonstrate an authoritative exploitation and post-exploitation process. You are to use any TTP allowed by scope, including existing exploits and your own bespoke scripts.
  3. You will need to take notes and produce a final penetration test report based upon the TTPs you used and the results of your exploitations, regardless of whether or not you are successful exploiting the vulnerabilities and misconfigurations discovered. Provide evidence (i.e. screenshots, test outputs) of all the steps you carry out, and document the commands you use during the test. Finally, you need to provide recommendations to address the vulnerabilities and critically evaluate these security solutions.

Scope

The scope of the penetration test is limited to the website using only ports 80 and 443. The Rules of Engagement allows to actively scan the web application for OSINT, and to use any TTP, including existing exploits, and your own bespoke scripts. However, your client considers the use of SQLmap as potentially damaging. Hence, the use of this tools is out of scope. Any offline attacks on the victim Virtual Hard Disk are out of scope. Interacting with the GRUB loader on the coursework VM is out of scope. You should not look at files directly on the coursework VM, and interaction with the target should always occur through the network.

Your client has also requested 3 separate documents to be included within the Final Penetration Test Report: i) Executive Summary, ii) Technical Summary, iii) Assessment Summary. Each document should be standalone (i.e., there can be no cross referencing between the documents). Each of these documents should address the relevant audience, and be written using the adequate narrative. The technical summary must include a table summarising the vulnerabilities uncovered. For each vulnerability, include the risk level, risk matrix, description of the vulnerability, potential impact, and recommendations to mitigate the vulnerability. When possible, these recommendations should come from the MITRE ATT&CK framework. The exploitation and post-exploitation processes need to be replicable.

Instructions to access the Virtual Machine will be shared on BlackBoard on the release of the coursework specification. You will need VMWare Player or Oracle VirtualBox to run both VMs, the one containing the web application and another running Kali Linux 2022.4.

This CTEC3410: IT/Computer Science Assignment help has been solved by our IT/Computer Science Experts at My Uni Paper. Our Assignment Writing Experts are efficient to provide a fresh solution to this question. We are serving more than 10000+ Students in Australia, UK & US by helping them to score HD in their academics. Our Experts are well trained to follow all marking rubrics & referencing style.

Get It Done! Today

Country
Applicable Time Zone is AEST [Sydney, NSW] (GMT+11)
+

Every Assignment. Every Solution. Instantly. Deadline Ahead? Grab Your Sample Now.