ITNET302A - Advanced Network Security & EternalBlue Research Project - Files'R'Us Company Case Study - TAFE Assignment Help

Download Solution Order New Solution
Assignment Task

 

Assessment Description  

This is an Individual Assessment.  

Technical research project on CVE-2017-0144, “EternalBlue”.  

Content and Structure: 

• Explain the 3 vulnerability components of CVE-2017-0144 

• Explain how the vulnerabilities are leveraged for exploitation 

• Perform a risk analysis of EternalBlue 

• Provide a Proof-of-Concept EternalBlue exploitation 

• Analyse the domain impact based on the supplied attack scenario 

• Explain three immediate mitigation and/or remediation actions 

• Explain three prevention measures that can be taken to reduce future events Detailed Submission  Requirements 

 

Background 

On August 13th, 2016, the shadow brokers tweeted their sale page for an all-inclusive state  sponsored cyber weapons toolkit developed by the Equation Group. 

No one bought. 

In response, on April 14th, 2017, the shadow brokers tweeted “...TheShadowBrokers rather being  getting drunk with McAfee on a desert island with hot babes...” and released the exploits free of  charge. One of these exploits, leveraging vulnerability CVE-2017-0144, has the name EternalBlue. 

Scenario 

Files'R'Us is a small company with 30 employees that earns its profits from hosting files for clients.  Files'R'Us is all inclusive, offering hosting solutions across all file transfer protocols such as, FTP,  HTTP, SMB, SFTP, SCP, WebDav and more. This hosting solution allows any customer to upload files  and any internet user to download files using any of the available file transfer protocols. 

In this scenario you work for Files'R'Us as a recently employed undergraduate. Your job  responsibilities include customer service and managing the file servers through file transfers and  configuration. This is a non-trivial task as you are in the Corporate Environment and the Windows  fileservers are segregated off in a DMZ that is only accessible via RDP using a domain account.  Without the ability to use normal file transfer protocols, such as SMB, you are forced to use RDP.  You have noticed you can RDP in and out of the DMZ speeding up this process. Reviewing  documentation on this, you notice there is no company vulnerability patch management process.

Task 

Your boss has recently learned that SMB is being targeted by the EternalBlue exploit and is  concerned about the company’s Windows file servers as they have SMB externally facing for  customers and internet users. He has supplied you with a simplified company network diagram (below) and asked you, the network security student, to write a research paper addressing the  following concerns: 

  •  Why does the CVE-2017-0144 vulnerability occur (cover all 3 components)  ? How is CVE-2017-0144 leveraged to perform the EternalBlue exploit 
  •  Using a risk matrix, what risk does the EternalBlue exploit pose to Files’R’Us? (Include a risk rating with a brief justification) 
  •  Provide a Proof of Concept (PoC) EternalBlue exploitation against one of Files’R’Us  machines and, using your shell, print the flag on the tafe user’s Desktop. 
  •  Immediate mitigation and/or remediation actions 
  • (Files’R’Us has not been owned by Ransomware. Do not include scanning for Ransomware) 
  •  Prevention measures that can be taken to reduce/eliminate future events (Files’R’Us has not been owned by Ransomware. Do not include scanning for Ransomware) 
  • As part of the exploitation process, include screenshots of the following: 
  •  Network discovery of the Virtual Machine, including discovery of port 445 being open. ? Vulnerability scanning for EternalBlue against the Virtual Machine 
  •  Exploitation being launched (use msf5, msf6 has a bug) 
  •  Successful shell acquired 
  •  Using the shell, printing the file contents of C:\Users\tafe\Desktop\flag.txt

 

Domain Impact 

As a recent hire, you want to impress your boss by going above and beyond. You decide to use  your knowledge of the company’s business operations and network setup to determine, in the  event of a compromised DMZ, whether the Corporate environment can also be compromised.  Knowing that RDP is the only allowed port (3389) between the DMZ and Corporate environment,  EternalBlue cannot be used to attack the Corporate environment - however employees are still  using RDP to access the DMZ.  

The question remains: 

If the DMZ is compromised and employees are still accessing it via RDP, can an attacker spread to  the corporate environment? 

For example, a possible exploitation path to compromise a domain via phishing would be:

1. Clone company’s Outlook web login page and host it on an attacker-controlled server 

2. Send phishing email asking company employees to log in, including a link to the attacker controlled outlook web login page 

3. Capture employee credentials as they click the phishing link and try to log in 4. Access the corporate network using employee credentials 

5. Using Wireshark, sniff HTTP traffic on port 80 to capture domain administrative credentials 6. Once acquired, log into the domain controller and add a new domain administrative user.

 

Simple Network Diagram

 

This ITNET302A - IT Assignment has been solved by our IT Experts at My Uni Paper. Our Assignment Writing Experts are efficient to provide a fresh solution to this question. We are serving more than 10000+Students in Australia, UK & US by helping them to score HD in their academics. Our Experts are well trained to follow all marking rubrics & referencing style.

Be it a used or new solution, the quality of the work submitted by our assignment Experts remains unhampered. You may continue to expect the same or even better quality with the used and new assignment solution files respectively. There’s one thing to be noticed that you could choose one between the two and acquire an HD either way. You could choose a new assignment solution file to get yourself an exclusive, plagiarism (with free Turnitin file), expert quality assignment or order an old solution file that was considered worthy of the highest distinction.

Get It Done! Today

Country
Applicable Time Zone is AEST [Sydney, NSW] (GMT+11)
+

Every Assignment. Every Solution. Instantly. Deadline Ahead? Grab Your Sample Now.