Demonstrate the setup of the attacker

Assignment Help Other Subject
Reference no: EM134013792

Assessment:

Overview

Assessment tasks Learning Outcome Mapping

Project Report - Group Introduction

This guide helps you set up a closed virtual lab for the group penetration test. You will run an attacker VM (Kali Linux) and one or more target VMs (instructor-supplied OVAs such as Metasploitable2 or other target images). All testing must stay inside this isolated lab network.

Students working on Data Communication And Networking projects should ensure the lab environment remains fully isolated during testing activities.

Important:

Do not scan or attack live campus/Internet hosts.
Only test the provided VMs or instructor-approved lab images.

Files you must have:

Kali Linux OVA or installer image (Kali current release).
Target OVA(s) - e.g., Metasploitable2 OVA or instructor-supplied target images.Use official sources for Kali and Metasploitable2 as directed by your instructor in the step-by-step guide.

VirtualBox: create the lab network (recommended)

We recommend an Internal Network named labnet (isolated from your real network).

1. Open VirtualBox -) File -+ Host Network Manager (optional if using Host-Only).
2. For simplicity use Internal Network: when configuring each VM's network adapter set Attached to -) Internal Network and Name -) labnet. (Alternative: use Host-Only Adapter if instructor prefers.)
3. No Internet is required. Keep it isolated.

Importing OVAs (Kali & targets)

1. In VirtualBox: File -) Import Appliance -) select the OVA file Next -) Import.
2. Repeat for each target OVA.
3. After import, check each VM's settings:
o System -) ensure enough RAM (Kali: 2-4 GB min; targets per instructor).
o Network -) Adapter 1: Internal Network (Name: labnet).
o Storage -) verify disks are present.

Starting the lab VMs

1. Start the target VM(s) first.
2. Start the Kali VM last (attacker).
3. Log in to each VM. For Linux targets, find their IP with ip a or ifconfig (inside the VM). On Kali you can also use arp -a or an initial nmap -sn 192.168.56.0/24 to discover live hosts.

Practical exercises using Linux environments can help students better understand penetration testing workflows and virtual machine management.

Recommended IP addressing

Use subnet:
- Subnet: 192.168.56.0/24
- Kali: 192.168.56.100
- Target1: 192.168.56.101
- Target2: 192.168.56.102
But it's fine to use DHCP inside the internal network or rely on discovery commands to learn IPs.

Take snapshots BEFORE testing

Critical: Take a snapshot of every target VM before you begin any active testing. This allows reset if something breaks.
- VirtualBox Right-click VM -) Snapshots -) Take Snapshot name pre-test.

Basic tools students will use (Kali)

nmap (scanning)
netcat nc (banner probing)
enum4linux smbclient (SMB enumeration)
wget, curl (file retrieval)
Nikto nikto (web vuln scans)
sqlmap (SQL injection testing, only on lab targets)
Burp Suite / OWASP ZAP (web app testing)
Metasploit (controlled exploitation)
John the Ripper, Hydra (password testing, with lab-only credentials)
Nessus or OpenVAS (vulnerability scanner) - optional/if instructed
Wireshark (packet capture)
msfconsole, msfvenom (Metasploit tooling)

Database testing and query-based vulnerabilities may also relate to concepts covered in Database Management Dbms assignments.

Recommended lab workflow (high-level)

1. Snapshot targets.
2. Host discovery: nmap -sn 192.168.56.0/24
3. Port & service scan: nmap -sS -sV -p- -T4 192.168.56.101
4. Targeted scans: nmap -sC -sV --script vuln 192.168.56.101
5. Banner grabs / simple probes: nc -v 192.168.56.101 80 or curl -I https://192.168.56.101/
6. Enumerate SMB: enum4linux -a 192.168.56.101 or smbclient -L //192.168.56.101 -N
7. Web testing: browse locally or use Burp/Nikto/sqlmap on discovered web apps.
8. Nessus scan (if permitted): run host discovery and vulnerability scans, export results to HTML/PDF for evidence.
9. Research CVEs for top findings (link Nessus problem to CVE details).
10. Controlled exploitation: use a PoC exploit against the vulnerable lab target (only use Metasploit or manual exploit as allowed by RoE). Keep it safe and document every step.
11. Remediate: patch, change config, and re-scan to demonstrate remediation where required. Then restore snapshot if needed.

Useful command examples (students should save outputs)

• Host discovery (ping sweep): nmap -sn 192.168.56.0/24 -oN outputs/nmap_ping_sweep.txt
• Full TCP port scan + service version + OS detection: nmap -sS -sV -O -p- -T4 192.168.56.101 -oN outputs/nmap_full_101.txt
• Quick vulnerability script scan: nmap --script vuln -sV 192.168.56.101 -oN outputs/nmap_vuln_101.txt
• SMB enumeration: enum4linux -a 192.168.56.101 | tee outputs/enum4linux_101.txt
• HTTP header (banner) grab: nc -v 192.168.56.101 80 then GET / HTTP/1.1\r\nHost: 192.168.56.101\r\n\r\n
• Download a file with wget: wget https://192.168.56.101/index.html -O outputs/index_101.html
• Start Metasploit and search exploits: msfconsole search name_of_service
• Use sqlmap (lab-only): sqlmap -u "https://192.168.56.101/vuln.php?id=1" --batch --dump
• Save terminal activity (script): script outputs/session_kali_YYYYMMDD.txt -> run your commands exit to save.

Students exploring system-level configurations may also benefit from concepts discussed in Operating System coursework.

How to capture reproducible evidence

• Save all command outputs to files (>, tee, or script).
• Use clear file naming: groupX_nmap_full_target1.txt, groupX_nessus_highs.pdf, groupX_exploit_screenshot1.png.
• Screenshots: include terminal + command visible. Filename format: G1_exploit_STEP1.png
• Nessus: export HTML/PDF for the report.
• Include timestamps and the VM IPs used in the evidence appendix.

Rules of Engagement (ROE) - required for Project Demonstration & Presentation

Task Description

Using the penetration testing lab environment developed in Part A, each group is required to conduct a live demonstration of a controlled cybersecurity assessment within the isolated virtual lab environment. The demonstration will assess the student's ability to perform reconnaissance, vulnerability assessment, controlled exploitation, remediation, and professional presentation of findings while following ethical and safe testing practices.

Demonstration Requirements

Each group should demonstrate the setup of the attacker and target virtual machines, including connectivity verification and reconnaissance activities using appropriate tools such as Nmap, Wireshark, Netcat, or similar approved tools. Students are also expected to perform vulnerability scanning, identify key vulnerabilities, and explain relevant CVEs and their potential impact.

The demonstration must include at least one web-based exploitation example and one system or network exploitation example within the approved lab environment. Students should clearly explain the methodology, tools used, and exploitation outcomes. Remediation strategies and re-testing after applying fixes should also be demonstrated where possible.

Evidence such as screenshots, scan outputs, command results, or logs should be presented during the demonstration. All testing activities must strictly follow the Rules of Engagement (RoE) and remain limited to the approved virtual lab systems.

Reference no: EM134013792

Questions Cloud

Physical-Cognitive-emotional-spiritual and environmental : Dimensions of Health include: Physical, Cognitive, emotional, social, spiritual and environmental. How much does one dimension of health affect other dimensions
Discuss the implications of court mandates for counseling : Discuss the implications of court mandates for counseling on informed consent. What steps should counselors who accept court referrals take to ensure?
Describe the disease process-prognosis : Describe the disease process, prognosis, and treatment goals.
Analyze the role of new media in reshaping traditional image : Analyze the role of new media in reshaping traditional images of crime and criminality. Does it challenge or reinforce mainstream narratives?
Demonstrate the setup of the attacker : Demonstrate the setup of the attacker and target virtual machines, including connectivity verification and reconnaissance activities using appropriate tools
Emergency room for fever and pain in the joints : A patient from Liberia, West Africa, is in the emergency room for fever and pain in the joints.
Describe in detail what will happen at the court hearings : Describe in detail what will happen at the court hearings and how many there will be. They have no previous criminal history.
Develop a comprehensive plan for future drug control : Develop a comprehensive plan for future drug control. Address international drug trafficking, interdiction efforts of U.S. law enforcement and drug enforcement.
DVT and PE are treatable if diagnosed early enough : DVT and PE are treatable if diagnosed early enough. If DVT and PE are left untreated or undiagnosed it can be life threatening.

Reviews

Write a Review

Other Subject Questions & Answers

  Cross-cultural opportunities and conflicts in canada

Short Paper on Cross-cultural Opportunities and Conflicts in Canada.

  Sociology theory questions

Sociology are very fundamental in nature. Role strain and role constraint speak about the duties and responsibilities of the roles of people in society or in a group. A short theory about Darwin and Moths is also answered.

  A book review on unfaithful angels

This review will help the reader understand the social work profession through different concepts giving the glimpse of why the social work profession might have drifted away from its original purpose of serving the poor.

  Disorder paper: schizophrenia

Schizophrenia does not really have just one single cause. It is a possibility that this disorder could be inherited but not all doctors are sure.

  Individual assignment: two models handout and rubric

Individual Assignment : Two Models Handout and Rubric,    This paper will allow you to understand and evaluate two vastly different organizational models and to effectively communicate their differences.

  Developing strategic intent for toyota

The following report includes the description about the organization, its strategies, industry analysis in which it operates and its position in the industry.

  Gasoline powered passenger vehicles

In this study, we examine how gasoline price volatility and income of the consumers impacts consumer's demand for gasoline.

  An aspect of poverty in canada

Economics thesis undergrad 4th year paper to write. it should be about 22 pages in length, literature review, economic analysis and then data or cost benefit analysis.

  Ngn customer satisfaction qos indicator for 3g services

The paper aims to highlight the global trends in countries and regions where 3G has already been introduced and propose an implementation plan to the telecom operators of developing countries.

  Prepare a power point presentation

Prepare the power point presentation for the case: Santa Fe Independent School District

  Information literacy is important in this environment

Information literacy is critically important in this contemporary environment

  Associative property of multiplication

Write a definition for associative property of multiplication.

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd