Write a penetrating test report against the web application

Assignment Help Web Project
Reference no: EM131499077

Web Application Assessment

Overview

GlobalComm has hired you as an offensive security consultant. You have been tasked with writing a penetrating test report against the web application of GlobalComm - DVWA. The expectation is you use active information gathering techniques and methods to exploit web applications.

Rules of engagement

• The only computer that should targeted is Metasploitable

• Students must of preformed the lab preparation assignment before continuing

Tasks and expectations

• Show proficiency Web application security

• Write a response to the tasks and questions below

Technical Questions

For this lab report screenshots of every command is not needed, please use your judgment when documenting this. Screenshots again should be used but limited. I do not want 5 pages of screenshots; additionally use the cropping tool to tighten the screenshots that are used.

Design

Web Application Assessment

The CTO of GlobalComm has requested an in-depth assessment of the Web

Applications running on the Linux virtual machine provided. A report should be written outlining the risk the current system has and recommendations on how to resolve them. DVWA should be the focus of the report but feel free to include an assessment of the other web applications running. Within the report you should explain the following:

• Information gathering

• Vulnerability identification

• Authentication weaknesses

• Web Application Exploitation

o 4 Exploits should be demonstrated

- 1 SQL injection attack

- 1 attack using SQL Map

- 1 attack using demonstrating a web shell

- 1 attack of choice

• Data exfiltration or disclosure possibilities should be outline and explain the risk in-depth.

• Remediation steps and action items to resolve issues identified should be elaborated on.

Reference no: EM131499077

Questions Cloud

Outline the physical design of your database : Outline the physical design of your database. Explain the security mechanisms available for a database and how the data will be protected.
Define the use of quantitative business model : Throughout this course, you will participate in a variety of critical thinking exercises designed to engage you in evaluating and selecting appropriate.
Computational point of view : Discuss the role that partial differential equations play in Finance and Economics, both from the theoretical and computational point of view.
Evaluate the performance of the industrials sector : You want to evaluate the performance of the Industrials sector of your portfolio over the past year.
Write a penetrating test report against the web application : GlobalComm has hired you as an offensive security consultant. Write a penetrating test report against the web application of GlobalComm - DVWA.
Local and stochastic volatility : What is a volatility surface and how does it point in general to the limitations of the Black-Scholes model? Discuss.
Write a report to the chairpersons : Write a report of 2000 words to the chairpersons of the Financial Reporting Council and the Australian Accounting Standards Board commenting
Explain the four concepts of structural change : 1005HSL Individual Essay Assessment. Identify and explain the four concepts of structural change, linking each concept to a world-famous tourist, restaurant
Explain what is an incomplete market : Explain what is an incomplete market, what is hedging at minimum cost and what is understood by completing a market.

Reviews

Write a Review

Web Project Questions & Answers

  Evaluating an ecommerce website

Create a check list that contains key point for evaluating an ecommerce website - Write a short, reflective report about website

  Gpc and runtime magic quotes

Create a script that lets you know whether Zeus or Helios has the GPC and Runtime Magic Quotes turned on or off. The output should have appropriate labels that define what output signified and should display 'ON' or 'OFF' depending on the setting.

  Creating functions through conditional operator

Use the conditional operator and the cal_days_in_month function, determine the number of days in the current month and output to browser whether it is normal month or a leap month.

  Web development projects with database

Since the vast majority of web-development projects involve a database, do you think that computational activities should be performed there, or do you think they belong in the XML page or stylesheet?

  Comparing shelf software packages

Required assistance with comparing and contrasting two main off the shelf software packages that could be implemented in an organization.

  Web based scams

Web phishing, pharming and vishing are popular web based scams. Talk about currently used tools and recommended measures to defeat this kind of attacks efficiently?

  Explanation of contextual links

The most powerful hypertext capabilities is the the contextual link. Wikipedia . com is a great example of a site that utilizes contextual links.

  How architectural and protocol changes occur

Discuss how architectural and protocol changes happen, the administrative organization that oversees the technical development of the Internet,

  Traditional approaches for training professionals

Webinars and other web conferencing techniques have proved most beneficial for the provision of affordable quality corporate training.

  Internet for business

Discuss how can a business use the Internet and give at least three examples with web links demonstrating your answer.

  It influences the behavior of organizations

Information technology influences the behavior of organizations. Name one effect of Information technology implementation and long-term usage you suppose having a positive contribution and one having a negative consequence.

  Importance of a guided navigation system

Explain the use and importance of a guided navigation system and shopping cart for a website designed for e-commerce and business purpose.

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd