Perform a security audit of a web application

Assignment Help Computer Engineering
Reference no: EM133263331 , Length: word count:2000

Web Application Security

Security Audit

Learning Outcome 1: Interact with the protocols that define the World Wide Web
Learning Outcome 2: Demonstrate practical knowledge of digital certification and TLS
Learning Outcome 3: Perform a security audit of a web application
Learning Outcome 4: Recommend security measures to protect web applications

Task: In this assessment you are required to write a report on the security of a web application of up to 2000 words.

This report should consist of two elements:
1. Short report demonstrating successful exploitation of common web vulnerabilities (CTF Style)
2. Discussion of ONE topic from the OWSAP top 10

Security Assessment
For the first element of the report you will need to complete a series of hacking tasks on a virtual machine.
The machine will allow you to demonstrate your ability to exploit common web application flaws including topics like:
• Directory Scanning
• Cross Site Scripting
• SQL Injection
For the report you are expected to write a brief summary of how you exploited the flaw. For example, a description of the attack, and any payloads used.
This element of the report can be screenshots or code samples, some discussion of the thought process used for exploitation, along with any flags gained during the process.

OWASP Topic Discussion
For the second element of the report you are required to write a short report on ONE element of the OWASP top 10. You are free to choose any element, either one of the topics we study in the lab sessions such as XSS or SQLi, or another element that interests you.
1. Introduction to the topic: What it is, and why it is of interest in Cyber security
2. Discussion of this topic including:
o Technical discussion of the topic (How does this flaw happen)
o Discussion of the topic in the wider security context (What does it mean in terms of security, how common is it, how "dangerous" is the vulnerability)
o Example of the topic in the "Real world"
3. Considerations for mitigating this problem.
4. Social, Legal and Ethical considerations with this particular topic

Report Structure
The recommended structure for the report is
1. Introduction
2. Results of the Security Audit
3. Discussion of OWASP topic
4. Summary
5. References

Attachment:- Web Application Security.rar

Reference no: EM133263331

Questions Cloud

Explain the dignity for all students act : Explain the Dignity for All Students Act. Why was it created and how does it help to prevent bullying? Do you believe it is enough to eliminate bullying in scho
First impressions of persons : Find and read the following article: Kelley, H. (1950). The warm-cold variable in first impressions of persons. Journal of Personality, 18 (4), 431.439.
Difference between contingency and contiguity : The issue of contingency vs. contiguity has been of major importance in conditioning and learning in recent years.
What the participants are feeling : In a lab setting, there is an emotion that shows a relatively very low heart rate, and low finger temperature, which is associated with disgust. When asked what
Perform a security audit of a web application : Web Application Security Demonstrate practical knowledge of digital certification and TLS and Perform a security audit of a web application
Work performance reports : Work Performance Reports are described in small sections of Chapters 4, 9, 10, and 11 of the PMBOK Guide. Review all of these sections and provide a summary exp
Values for standard critical path notation : 1. Draw the critical path and include all the values for standard critical path notation: task identifier, duration, early start, early finish, late start, late
Contrast the status of women in pro-islamic arabia : Compare and contrast the status of women in pro-Islamic Arabia and the status of women after Quranic reforms.
Steps of organizing a seminar : 1. You have been appointed as a Project Manager for this upcoming event. Your responsibility is to manage a team on organizing a seminar as per requested by the

Reviews

Write a Review

Computer Engineering Questions & Answers

  Write a c program for a mini calculator

Write a C program for a mini calculator using only the command line options. You must use getopt to parse the command line.

  Using a lock guarantees that deadlock cannot occur

Once a Lock has been obtained by a thread, the Lock object will not allow another thread to obtain lock until the first thread releases it.

  Design a combinational circuit with three inputs

Design a combinational circuit with three inputs, x, y, and z, and three outputs, A, B, and C. When the binary input is 0. I, 2. or 3. the binary output is one greater than the input.

  Java application that indicates invalid ticket number entrie

Ticket numbers are designed so that if you drop last digit of the number, then divide the number by 7, the remainder of the division would be identical to the last dropped digit.

  Would a round-robin preemptive scheduler using your approach

Would a round-robin preemptive scheduler using your approach be fair? Explain why or why not. If not, how would you go about fixing it

  Estimate the computation time for the program

Estimate the computation time for the program in the above problem assuming the following time characteristics.

  Write a program that accepts positive integer from keyboard

Write a program that accepts a positive integer from the keyboard and then displays all integers from 1 up to that number, each on a separate line.

  Program for translates letter grade into number grade

Write down a program which translates the letter grade into number grade.

  What methods should each class have

What methods should each class have? How and where would you keep track of things like orbital parameters?

  CP3404 Information Security Assignment

CP3404 Information Security Assignment Help and Solution, James Cook University - Assessment Writing Service - Write a short summary of his activities

  Write a program to print the letters a thru lower case z

Write a program to ask for a character from key board called ch and try to guess a prestored character in your program called answer.

  Develop a charter for the rals rostering project

Analyse these risks, assign a risk to an appropriate member, and describe a strategy for the management of each specific risk - Define Scope and produce a Scope Management Plan - Develop a charter for the RALS Rostering project.

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd