Vulnerability and Penetration Testing (VAPT) Assignment

Download Solution Order New Solution

Assignment Task

Overview

This is an individual exam-style assignment that will test if students can perform a time-boxed web application penetration test and produce a technical findings report detailing identified misconfigurations and vulnerabilities along with recommendations for mitigation.

Objectives

Your task is to perform a time-boxed web application penetration test of the following web application Your task is to identify, exploit, and report 100 points worth of vulnerabilities from the following categories: Vulnerability Class Points per Vulnerability Writeup File Upload Vulnerabilities (Directory Traversal, File Inclusion, Web Shell Upload, and any other kind of vulnerability where a file is uploaded or written to that results in RCE) SQL Injection (Auth bypass using SQL injection, RCE, or sensitive information retrieval)

Auth Vulnerabilities Hardcoded credentials secrets improper password storage susceptibility to brute-force attacks IDORs username enumeration insecure sessions privilege escalation improper missing access controls account takeovers Business Logic Flaws Vulnerability Create a descriptive title for the issue which captures both the affected component and the vulnerability affecting it. 

Description: Provide a sentence summary of the finding including both the affected service or system component and the security issue affecting it. Impact: Provide a sentence summary of how an attacker could abuse the issue to compromise the application, the application’s users, the underlying system, or organization that deployed it. 

Sating control (ex. install a firewall, implement antivirus, turn off the service, etc.)  Steps to Reproduce: This represents the longest and most important section of your vulnerability writeup where you will include every step taken to identify and exploit the security issue and provide supporting evidence in the form of screenshots, commands issued  tools ran and or proof-of-concept code. This section should outline all the work you performed that directly contributed to your successful exploitation of the target: it is not necessary to include rough work and research that did not contribute to your eventual successful compromise.

This IT and Computer Science has been solved by our PHD Experts at My Uni Paper.

Get It Done! Today

Country
Applicable Time Zone is AEST [Sydney, NSW] (GMT+11)
+

Every Assignment. Every Solution. Instantly. Deadline Ahead? Grab Your Sample Now.