Highlights
To successfully complete this assessment task you must meet requirements for all criteria as listed below. Where you are unsuccessful or you are required to provide further evidence your teacher will provide feedback and request further evidence as needed.
It is important that you clearly understand all the requirements of this assessment task. If you have difficulty with the assessment terms or the steps to follow please speak to your teacher as soon as possible. Your teacher is your first point of contact when you need clarification and they will provide additional information as required to help you.
During this assessment task you are required to complete a project or section of a project . Your teacher will provide you a project brief that will list all criteria that must be covered and any specific tasks that must be carried out. This evidence may be gathered over time in a range of situations and dates.
Project assessments are generally a combination of several tasks combined. Projects will require significant planning, research and may follow a systematic process as outlined by your teacher.
These tasks will generate evidence that must be submitted as a collective to demonstrate competence and may involve the submission of work samples a well as evidence of research and specific tasks undertaken.
Your company has just developed a new web application. A few weeks prior to releasing it, they’ve asked you to assess the security of the application, list any issues you’ve found, and provide a report of your assessment.
For this assignment you are allowed to use:
• Paper-based notes from this class (no more than 2 pages, front and back)
• Any notes from Studentweb
Do not discuss the assignment with other students or use other websites unless specifically allowed.
1. Preparation
1.Download the Report Template document from studentweb.
2.Download the NewWebApp.iso file from studentweb. The system runs directly from the ISO and requires the creation of a VM as follows:
a.Linux (Ubuntu) based OS
b.No hard drive space needed (you can accept the default of 20GB, multiple files)
c.One network adaptor with internet access (VMNet: NAT)
d.1GB of RAM with 1 CPU
3.Start your existing Kali virtual machine
4.Fill out the information below
2.Evaluation of the NewWebApp Server App
The web app your company is working on consists of several URLs (see below). You must evaluate them looking for security issues and vulnerabilities we discussed in class (Cross Site Scripting, Insecure Direct Object Reference, SQL Injection):
•http://x.x.x.x/xvwa/vulnerabilities/idor
•http://x.x.x.x/xvwa/vulnerabilities/sqli
•http://x.x.x.x/xvwa/vulnerabilities/stored_xss
Requirements
•Briefly describe each of the issues you discovered
oInclude the type of issue it is, a brief description of the type of issue, and screenshots of:
? Normal operation (e.g. “get item 1” shows the details for item 1)
?Abnormal operation (e.g. you can see item details you shouldn’t be allowed to see)
•Provide a formal, detailed description of one of the issues found
oYou can choose from IDOR or XSS (i.e. you can’t pick SQLi)
oComplete a report using the template in studentweb (identical to the one we used in the previous assessment)
oMust be completed in full (e.g. reference to OWASP Top 10 report, etc)
Student Responses
Vulnerability 1 (include type of vulnerability, description of how it was exploited, URL, screenshots of normal and abnormal operation)
Vulnerability 2 (include type of vulnerability, description of how it was exploited, URL, screenshots of normal and abnormal operation)
Vulnerability 3 (include type of vulnerability, description of how it was exploited, URL, screenshots of normal and abnormal operation)
Detailed report – copy/paste your report in here:
Issue
•IDOR
Categorization and Rating
•High Risk
•OWASP Issue: A1 FOR IDOR
•https://owasp.org/www-project-top-ten/OWASP_Top_Ten_2017/Top_10-2017_A1-Injection
Authenticated Access Required
•No
External/Internal Access
•Currently, this server is available internally only as indicated by the example description.
Vulnerability Description
For example:
Risk
With unfiltered access to the database, an attacker can likely retrieve all database content including sensitive and confidential data. The consequence of such an event is considered Major / Significant.
As the page is easily found and does not require authentication, the likelihood of this vulnerability being discovered is Almost Certain.
This issue would be rated Critical.
Remediation
The company must find a solution to stop the interception of the website. The connection must be secure and restrict access.
3.Evaluation of Web Server Security
In addition to testing the web application, the company isn’t sure the web server itself is fully secured or patched. Use a tool of your choice to:
a.Use nmap do a port scan of the NewWebApp VM, and
b.Use nikto to scan the server and identify possible web server vulnerabilities
Requirements
•Port Scan: Include a screenshot (of all open ports and the command you ran)
•Vulnerability Scan:
oInclude a screenshot (of all open ports and the command you ran)
oSearch online for information about one of the vulnerabilities and take a screenshot
Student Responses
Nmap scan screenshot showing open ports on the NewWebApp VM
Nikto scan showing vulnerabilities potentially found on the NewWebApp VM web server
Screenshot of a summary/basic explanation of the vulnerability chosen in Nikto (you can use online web resources for this)
4.Install a Proxy and run Web Application Proxy tools
Demonstrate the correct use Burp Spider to spider the entire NewWebApp site (e.g. http://x.x.x.x/xvwa).
Insert the screenshot of the site map in BurpSuite after the spider completes below:
5.Short Answer Questions
In class, we used the DIRB (Directory Buster) against our vulnerable web servers. Look at the DIRB result below to the screenshot below (this is not based on the NewWebApp site). Complete the table below:
The following picture is an HTTP request from a client to a web server. Answer the following questions about the HTTP protocol:
Which line tells us the:
•Name of the web server we are trying to connect to? www.test101.com
•Browser the user is using? Mozilla/4.0
•Specific web page the user is trying to open? /doc/test.html
•Web protocol used? (including version) HTTP/1.1
This IT/Computer Science Assignment has been solved by our IT/Computer Science Experts at My Uni Paper. Our Assignment Writing Experts are efficient to provide a fresh solution to this question. We are serving more than 10000+ Students in Australia, UK & US by helping them to score HD in their academics. Our Experts are well trained to follow all marking rubrics & referencing style.
Be it a used or new solution, the quality of the work submitted by our assignment experts remains unhampered. You may continue to expect the same or even better quality with the used and new assignment solution files respectively. There’s one thing to be noticed that you could choose one between the two and acquire an HD either way. You could choose a new assignment solution file to get yourself an exclusive, plagiarism (with free Turnitin file), expert quality assignment or order an old solution file that was considered worthy of the highest distinction.
© Copyright 2026 My Uni Papers – Student Hustle Made Hassle Free. All rights reserved.