For this assignment I need you to do a pen testing on the webserver. Use 3 of the top 10 vulnerabilities from OWASP to find the website weakness. Write an assessment report on what you find. Tools:...

1 answer below »
For this assignment I need you to do a pen testing on the webserver. Use 3 of the top 10 vulnerabilities from OWASP to find the website weakness. Write an assessment report on what you find.

Tools:

Kali Linux, WebGoat, visual studio, and other free tools that you can find.

Instruction:



  • Go to the website: https://pentest.trutiksoftware.com/Account/Login to perform a pen testing.

  • Perform 3 vulnerabilities OWASP:
    A2-Broken Authentication and Session Management, A3-Cross-Site Scripting (XSS), A7-Missing Function Level Access Control.

  • List step by step on your work and provide multiple screenshots of your work. Make sure that you provide detail instruction so that a beginner can follow and able to perform a pen test if they are looking at the instruction. For example: step 1 (click on this search box and enter the following codes), step 2, etc…

  • Compare the method that you do with WebGoat. Does the tutorial from WebGoat work on the webserver that you try to pen test?

  • After you perform the pen test, write a security assessment report on what you find. What kind of codes, security weakness you find in the webserver. How do you prevent it?

  • Words limit: 2500 or less than.




Login Credentials:

Black box testing: https://pentest.trutiksoftware.com/
Tenant :pentest
Email : [email protected]
Password: Pen#123
Try to get in without use the password. If you are finding a hard getting in then there are the credentials.
Again, if a hashing algorithm or rainbow table is going to be used please restricted to less than 1 min intervals.

Allowed Servers:



Database:


SQL5030.Smarterasp.net
DB_A151F8_andresdev_admin
DB_A151F8_trutikdev_admin

Webservers:


Dev.trutik.com
Dev.trutiksoftware.com

Introduction to Scope

The scope will be against Trutik Dev environment. Only dev servers and localhost will be allowed to be pen tested and available for this assessment.
Primary pen test investigation should be against OWASP top 10 vulnerabilities.

DoS Testing

Basic stress testing is permitted for no more than 1 minute of execution.
Answered Same DayDec 26, 2021

Answer To: For this assignment I need you to do a pen testing on the webserver. Use 3 of the top 10...

Robert answered on Dec 26 2021
128 Votes
Vulnerability 1: Broken Authentication and Session Management
Following tools are needed:
1. Web
goat 7.0 version for learning all what is needed
2. Burp intruder to capture the sessions and forward as man in the middle attack
3. hackable website: http://altoromutual.com
Steps to Broken Authentication and Session Management we would be doing the following
steps:
Login to the dummy website using the credentials
Login: jsmith
Password: Demo1234
Welcome page after login
http://altoromutual.com/
Click the view recent transactions option
Check the burp interceptor for the info forwarded
Check the highlighted string, this is what we going to change to check another user...
SOLUTION.PDF

Answer To This Question Is Available To Download

Related Questions & Answers

More Questions »

Submit New Assignment

Copy and Paste Your Assignment Here