Highlights
Planet of the grapes Planet of the Grapes, a local wine and spirit merchant currently operates in three stores around Perth. Stores are independent from one another and there is no data sharing between stores, although this is not by design but simply a by-product of faster than expected expansion. The organisation has contracted your computer security consulting company to perform an audit on their computer network. The owners have never employed any IT security staff in the past and have preferred to set up systems for themselves. However, the risks posed by inadequate cyber security have now become too great to be ignored. For this reason you are being asked to investigate the security of the system and make recommendations.
Scenario Description The site being audited has a total of 10 full time staff and an unspecified number of casual staff. The back-office duties are only undertaken by full time staff, but the staff common areas and offices are not locked or physically separated. Full time staffers handle payroll, HR and scheduling tasks. The front counter/cashier duties are sometimes taken on by full timers but also by casual staff. You have been informed that the turnover of casual staff is quite large, although the reasons for this are unknown. The computer systems in the back office are all networked via a Cisco small business series ADSL router supplied by Telstra. To permit the owner(s) to check on files from home, remote access services are enabled on some but not all of the machines. There is no centralized authentication server and users logon locally to all machines. All machines contain two local user accounts “admin” and “user”. These accounts are shared by staff to ensure that files are always accessible to fellow staff. The server used for hosting the online presence runs Ubuntu Linux and is located in one of the offices. The server will also be used as print and file server for other Windows 7 PCs which will run office applications (payroll, HR etc.). An image of the server machine has been supplied to you as VirtualBox VM. You can obtain the VM from: http://www.it.murdoch.edu.au/szander/ICT287/assignment1/form.php You will require your student number to download the VM. You should download your own specific VM as there are multiple different VMs for different people. The network interface of the VM is set to Host-only Adapter and normally you should leave it that way. For the VM to run, it is necessary to have a Host-only Network configured in VirtualBox. This may already exist, but if it does not exist you can configure it under File->Preferences->Network->Host-only Networks. Make sure you enable the DHCP server. Attack Surface Analysis Your task is to assess the attack surface.
The scope of your analysis is limited to:
1. Network attacks on the server (based on the image provided);
2. Other attacks including physical attacks (based on the description of the site). You should NOT login to the server machine and analyse the individual software packages that have been installed. You only need identify and describe any vulnerable services from a network level (using suitable tools) and identify and describe any potential attacks including physical attacks given the scenario description above. It is not mandatory, but you may use a vulnerability scanner (e.g. Nessus) for the networklevel analysis. However, you are not allowed to simply copy and paste output of these tools. Like in the real world you must synthesise the output of the (different) tools into a form appropriate for the audience and add textual descriptions. Your report should outline possible weaknesses and vulnerabilities. The report should start with an executive summary of 1 page that summarises the most important findings and is understandable by a layperson. The following pages should describe the details and should be ICT287 Computer Security Assignment 1 – V6 Last Updated 26/03/2020 presented in a format suitable for a general technical audience – i.e. someone who is proficient in IT in general, but may not be a security expert. Citations should be used where appropriate. Your report should enumerate all potential network accessible services with as much detail as possible (based on the viewpoint of an external attacker) and identify possible vulnerabilities for these services referencing specific CVE items (with brief explanations). An exhaustive list of CVEs is not required (there are too many), but you should at least discuss the 10 most critical and these must be relevant to the actual system and services. Your report should also discuss possible other attack points including physical attack points and how these could be potentially exploited by attackers. Your report should end with a summary of the findings which is more in-depth than the executive summary and also clearly demonstrates a prioritisation of the most important issues. Based on your findings you should also make recommendation on how to improve the security of the server as well as the site in general. Your report must have a title page and table of contents (ToC). It should be presented in a clear and concise way and should be written in your own words (simply copying CVE descriptions is not acceptable).
This IT Assignment has been solved by our IT experts at My Uni Paper. Our Assignment Writing Experts are efficient to provide a fresh solution to this question. We are serving more than 10000+Students in Australia, UK, US by helping them to score HD in their academics. Our experts are well trained to follow all marking rubrics referencing style.
Be it a used or new solution, the quality of the work submitted by our assignment experts remains unhampered. You may continue to expect the same or even better quality with the used and new assignment solution files respectively. There’s one thing to be noticed that you could choose one between the two and acquire an HD either way. You could choose a new assignment solution file to get yourself an exclusive, plagiarism (with free Turnitin file), expert quality assignment or order an old solution file that was considered worthy of the highest distinction.
© Copyright 2026 My Uni Papers – Student Hustle Made Hassle Free. All rights reserved.