SIT382 : System Security - WebGoat Challenge - Computer System Assignment Help

Download Solution Order New Solution
Internal Code : 1IFGG

System Security Assignment Help

TASK You are required to complete the WebGoat Challenge question. The tasks to be completed are provided in WebGoat. You need to click on the Challenge menu item and complete the THREE  stages in this challenge. This part of the assignment requires you to know different application penetration testing techniques to complete successfully. An important note to remember is that you are attacking the WebGoat web server from a client (web browser). This means that the attacker does not have any write access to the server, thus you will not be able to modify the java source files to complete the Challenge questions. Any modification of the WebGoat source code to complete the Challenge questions will result in loss of marks. You need to select and choose ONE of the many tools available in the open-sourced domain, including tools which we have not covered but you may find interesting, for example, Nmap (http://sectools.org/tag/port-scanners/ ). Once chosen, a detailed description should be attached, including the reason for selecting this tool, the applied scenario, and supporting theory in behind. You will also provide a complete run through the activity by providing screenshots of how the attack was launched and also an evaluation of the data collected from the victim machine, such as the traffic packet data rom the Wireshark. In Part A, you are required to include the following: • Description of the scenarios in each stage compared them to real-world cases. • Theoretical description of the possible methods to launch attacks. You may list the possible methods that you may use to test the problems posed by the question of each stage? • A brief explanation of the method used (a couple of paragraphs) followed by details on how you used that method to test the problem. What are the results of those methods that you actually tested the problems posed by the question of each stage? (Analyse either successful or unsuccessful methods) • Any script code and images (screen dumps) showing the successful completion of the tasks in this part of the assignment. • A theoretical description of the attack. If for example, you decide to run a spear phishing attack, you will need to provide around 300-500 words describing the attack in detail. • A complete, beginning to end, tutorial-like the presentation of the attack, without omitting any variables, including screenshots, this could look like a manual or a journal. • An evaluation of the data if collected from Wireshark, in any given case, you will be able to find some pattern, like a redirection or uncommon data between clients in social network attacks, or the effect of a spoofing mechanism, you should describe in a fairly simplistic way, what has happened. • Provide a short evaluation and considerations of the attack, this can and should also include defence mechanisms which can be used to defend from such an attack. Please note, this should be done thoroughly and present various mechanisms and description of which you consider to be better and why. For example, for a DoS attack where the attacker has spoofed the IP address, there are mechanisms to trace back the attacker, you should include most of them. The above question has been solved by our system security assignment experts at My Uni Paper. Our Assignment Writing Experts are efficient to provide a fresh solution to this question. We are serving more than 10000+ Students in Australia, UK & US by helping them to score HD in their academics. Our Experts are well trained to follow all marking rubrics & referencing style.

Get It Done! Today

Country
Applicable Time Zone is AEST [Sydney, NSW] (GMT+11)
+

Every Assignment. Every Solution. Instantly. Deadline Ahead? Grab Your Sample Now.