Highlights
Provide a very short opening introduction of which vulnerability you selected and why. The purpose of this project is to provide a deep-dive analysis of a chosen vulnerability and demonstrate how an attacker would exploit the vulnerability. This is not intended to be a general discussion on vulnerabilities or why organizations should protect against threats. This project calls for specific research and a demonstration that you are able to run security assessment tools.
Describe your topology here. Provide a detailed network diagram of your lab environment. Ensure that the diagram accurately represents your specific setup. Document your own IP address. A screen capture of this documentation is required. Do not use or copy the IP addresses provided in any example diagrams. You may use Draw.io for free online diagramming and modeling software, or you can hand-draw your diagram.
Identify the Network scanner and vulnerability scanner software and insert a screenshot of your (1) port scan and (2) vulnerability scan. The vulnerability scanning tool must show your name and when the scan took place. The screenshot should also show actual discovered vulnerabilities. These screenshots can be a little larger but around this size. Do not do entire “Print Screens”—crop the image appropriately, displaying only relevant information, e.g., the most critical or (top) vulnerabilities.
Discuss the two vulnerabilities you have selected. Research the vulnerability and discuss the specifics. What does the software do, and why does the vulnerability exist? You must explain the technical aspects of the vulnerability to get full credit. Remember: This is the research portion. Learn about the vulnerability and discuss it in your own words – do not simply copy and paste.
Describe the vulnerability in terms of complexity, access, privileges required, vulnerability scoring, etc. Reference the National Vulnerability Database (NVD) scoring. Explore the links associated with the vulnerability in the NVD. This typically provides a lot of high-level and low-level technical details. The difference between this section and the vulnerability research section is that this should be specific to the implementation of the software and the existing environment. For example, does the vulnerability exist across all instances of this software or is it specific to a configuration, or installation stack?
This is the most important step of the project. Discuss the steps that were taken for the exploitation. Use as many screen captures as needed here. Please provide the configuration of the script or the tool settings. To receive full credit for the exploitation, you need to show the time when the exploitation took place in your screen capture. You also need to show system-level access, root-level access, or admin-level access.
Use this area to discuss briefly what the risk represents to an organization. Would it change the risk if it were on a public-facing server as opposed to an internal server? What would happen if this exploit were successful? Assume that the vulnerable software would be installed in a business environment, not your home lab network. Discuss a few different risks that would be dependent on where and how the vulnerable software would be installed across the organization.
Discuss how you fix this vulnerability. Can you patch it? Are there additional security controls, protections, or sensing mechanisms that could be installed to lessen the impact of an attack?
Introduction – Briefly introduce the selected vulnerability and the reason for choosing it.
Lab Topology – Document the lab network setup, including a detailed diagram and IP addresses used.
Mapping and Scanning – Perform and document port scans and vulnerability scans using appropriate tools, with clear screenshots showing actual results.
Vulnerability Research – In-depth explanation of the chosen vulnerabilities, detailing the technical nature and causes of the vulnerability in own words.
Vulnerability Analysis – Assess the vulnerability based on complexity, access requirements, and NVD scoring, and relate to the specific lab environment.
Vulnerability Exploitation – Provide step-by-step description of exploitation using appropriate tools, with screen captures showing timestamps and elevated access (admin/root).
Risk Assessment and Analysis – Analyze the business impact if the vulnerability were exploited in a real environment, considering public-facing vs internal setups.
Mitigation and Security Control Recommendation – Propose concrete solutions such as patching, security controls, or additional defenses to fix or mitigate the vulnerability.
The Academic Mentor started by clearly explaining the objective: to go beyond theoretical knowledge and demonstrate hands-on capability in vulnerability discovery and exploitation within a controlled lab environment. The student was advised to choose a specific vulnerability that is well-documented and supported by community tools.
The mentor guided the student to select a well-known vulnerability (e.g., Shellshock, Heartbleed, SQL Injection) that had sufficient technical detail available in the National Vulnerability Database (NVD) and public resources. The student was encouraged to pick a vulnerability they found interesting or relevant to real-world systems.
The student was instructed to carefully plan and set up their lab network using tools like VirtualBox or VMware.
The Academic Mentor emphasized the importance of creating an accurate network diagram using Draw.io or a hand-drawn diagram.
The student documented their own IP address and took a screenshot as required to validate authenticity.
The mentor explained how to use network scanners such as Nmap for port scanning, and Nessus or OpenVAS for vulnerability scanning.
The student performed scans, then selected the most relevant screenshot evidence that included:
Date/time of the scan.
The student’s name (to authenticate ownership).
Identified vulnerabilities.
The mentor helped crop images to highlight only critical information.
The Academic Mentor instructed the student to research the vulnerability thoroughly via trusted sources (CVE details, NVD, official vendor advisories).
The student summarized the findings in their own words, focusing on:
How the vulnerability works.
Why the software is vulnerable.
Technical mechanisms causing the issue.
The student was guided to analyze the vulnerability’s complexity, access required, privilege levels, and scoring (CVSS) from NVD.
The mentor helped the student relate these factors specifically to their lab environment, clarifying:
Is the vulnerability dependent on a specific configuration?
Does it exist across all installations or only certain setups?
The Academic Mentor coached the student to perform the actual exploitation using tools such as Metasploit Framework or custom scripts.
The student was advised to:
Document each step clearly.
Capture screenshots showing timestamps and successful access (e.g., root shell).
Include tool configuration settings and scripts used.
The mentor reviewed the student's steps to ensure they were valid and clearly explained.
The student was guided to consider real-world implications of the vulnerability:
What would happen if exploited on a public-facing web server vs internal system?
Possible business impacts (e.g., data theft, system downtime, reputational damage).
The mentor helped the student articulate these risks clearly, making the analysis business-focused rather than purely technical.
The student was advised to research patch solutions, configuration changes, and additional security controls such as:
Firewall rules.
Intrusion detection systems (IDS).
Regular patch management.
Security training for employees.
The mentor ensured the mitigation strategies were practical, supported by references, and clearly explained.
The student submitted a well-structured Vulnerability Discovery and Exploitation report that included:
A clear and concise introduction explaining their choice of vulnerability.
A detailed lab topology diagram with proper IP documentation.
Effective mapping and scanning results with authenticated screenshots.
Comprehensive vulnerability research written in their own words.
Thoughtful vulnerability analysis tied specifically to the lab environment and referencing NVD scores.
A fully documented and successful vulnerability exploitation section, with screenshots showing access and timestamps.
In-depth risk assessment, considering different deployment scenarios.
Practical and researched mitigation strategies to fix the vulnerability.
LO1 : The student developed the ability to analyse and implement technology tools (network scanners, vulnerability scanners) to map, scan, and understand the vulnerability in the context of a digital environment.
LO2 : The student evaluated information risk by creating a detailed risk register and providing a clear risk assessment aligned with enterprise practices.
LO3 : The student constructed a data management strategy through a clear mitigation plan, demonstrating an understanding of data governance and security controls to prevent exploitation.
Need help understanding your assignment? Our sample solutions provide you with a valuable reference to help you structure your work, grasp key concepts, and develop your own unique approach. Download the sample solution now to get inspired and stay on track.
Important Reminder: This sample solution is provided for reference purposes only. Submitting it as your own work is considered plagiarism and may lead to serious academic consequences. Always use sample solutions responsibly to support your learning and not as a ready-made submission.
For guaranteed peace of mind and high-quality results, order a custom-written, 100% original solution created by our professional academic writers. Each solution is tailored specifically to your assignment brief, fully researched, and written from scratch with a strong focus on academic integrity.
Original, custom-written content based on your exact brief
In-depth research and accurate academic references
Proper structure aligned with your course requirements
Delivered on time, ready to submit
Guaranteed plagiarism-free with full quality assurance
Take the stress out of assignments and submit confidently today.
Download Sample Solution
Order Fresh Assignment
© Copyright 2026 My Uni Papers – Student Hustle Made Hassle Free. All rights reserved.