M0138 - Web Application Penetration Testing Assignment Help

Download Solution Order New Solution

Assessment Task

Task

The assignment requires you to demonstrate a critical understanding of penetration tools, techniques, and procedures. Answer the following questions:

1. For each of the relevant sections in the Computer Misuse Act (CMA) 1990 (1, 2 and 3) describe two scenarios. Firstly, one in which a “normal” person may be prosecuted, and secondly, one in which a penetration tester may be prosecuted while working, assuming their scope of work is invalid.

2. Using the information below, generate a scope of work for a penetration testing engagement. This is to include:

a. A list of suggested methodologies to be carried out

b. Prerequisites to carry out the methodologies engagement

c. Questions to obtain information that is missing and/or insufficient.

We have an AWS based infrastructure, combining regular VMs with ECS containers. Our field engineers log into the public front-end with their domain credentials, which then grants them access to a web-based RDP session. From here they access the administration website, this runs on a wildfly server and supporting database is hosted using RHEL 6.8. The public facing website is load balanced using the AWS load-balancer service and our own kubernetes instance in then cloud.

3. Using the Nmap scan shown in the following image, provide 5 different ways you might obtain a remote shell session on the host. NOTES:

a. No actual scanning or exploitation is required, this is based on the tool output shown. Access and exploitation should be based on the type of service running or the software version.

b. Your shell does not need to be the root user.

c. You may only use each method once, using the same exploit for multiple users is not allowed.

d. Provide a brief description of the exploitation process sufficient for it to be replicated.

e. Describe briefly the key facts about each vulnerability you have used.

f. Copy and pasting from existing guides will result in loss of marks.

 

This M0138 - IT Assignment Help has been solved by our IT Experts at My Uni Paper. Our Assignment Writing Experts are efficient to provide a fresh solution to this question. We are serving more than 10000+ Students in Australia, UK & US by helping them to score HD in their academics. Our Experts are well trained to follow all marking rubrics & referencing style.

Get It Done! Today

Country
Applicable Time Zone is AEST [Sydney, NSW] (GMT+11)
+

Every Assignment. Every Solution. Instantly. Deadline Ahead? Grab Your Sample Now.