Bonanza Offer FLAT 20% off & $20 sign up bonus Order Now
PGI108
UK
Middlesex University
Penetration testing is a type of test, which helps in identifying and understanding the different kinds of open ports which are present in a computer machine or organization (Dieber et al. 2020). This task is mainly performed by ethical hackers, who signs a contract with the organization before conducting the penetration test. The contract contains various kinds of details about the penetration test, and the duration. After that, the ethical hackers start conducting the test on the computer system and the network connection. The penetration test is mainly conducted on the internet protocol address of the organization or the computer system. After the, test has been conducted, the ethical hackers generate a report, which contains the details of the vulnerabilities present in the organization (Zhang et al. 2019). They also help in suggesting the various kinds of mitigation plans with the help of which the organization can omit those vulnerabilities.
Before conducting the attack on the target, we had to connect the computer system with a Virtual Private Network connection. This is mostly used by hackers and intruders, in order to hide their geographical location. Along with that, we are also using the Kali Linux operating system, to conduct the penetration test. Here we will be executing the Red Net Virtual Private Network connection (McKinnel et al. 2019). We have followed the steps in order to connect the system to the Virtual Private Network connection. To test the connection, we have sent a ping request to the target IP address that is, 192.168.1.162.
The above screenshot shows all replies which we got after sending the ping request to the target internet protocol address. This confirms us that, our Kali Linux operating system has established the connection.
After that, to check for the vulnerabilities, we need to find the open port which are present in the computer system. In order to analyse, this we have used the nmap command. This command performs a network analysis on the targeted internet protocol (Zsikó et al. 2019). After analysing the targeted internet protocol address, it provides a report which shows the open ports which are available in the computer machine.
The screen shot displays the report which was produced from the nmap tool. It shows all the open ports which are available in the targeted internet protocol address (Zennaro and Erdodi 2020). As we can see, the first row of the report shows the port number, state of the port and service which it offers. After conducting the network analysis, we found that, a total number of eight ports were open. The name of the ports and their port number which are open, are ssh service with port number 22, http service with port number 80, netbios-ssn service with 139, Microsoft-ds service with port number 445, mysql service with port number 3306, vnc-3 service with port number 5903, X11 service with port number 6000 and X11:3 service with port number 6003.
Next, we have used the nikto tool in order to find the vulnerabilities that present in the port number 80 (Schwartz, Kurniawati and El-Mahassni 2020). We have used a command using the nikto tool, in order to find the vulnerability that is present in the port number 80.
The above screen shot shows the result of the nikto tool. Here we have found a vulnerability which is labelled as apache mod_negotiaton is enabled with MultiViews. This allows the hackers and intruders to easily perform brute force attack (Mudiyanselage and Pan 2020). In the event of a brute force attack, the hackers and intruders uses various kinds of hacking tools and software application on the server and database, in order to collect the file names and the folders names which are present.
The above screen shot shows another vulnerability which is present in the targeted IP address. In order to perform this task, we have used the OWASP ZAP tool. The full form of OWASP ZAP is Open-Source Web Application Security Protocol Zed Attack Proxy (Imai and Tonoughi 2021). With the help of this tool, we found that, the Anti-MIME Sniffing header X-Content-Type-Options was not set to “nosniff”. This means that, the hackers will be able to perform a sniffing attack on the network connection. With the help of the sniffing attack, the hackers are able to sniff out the data and information which are being transfered through the network connection.
The above screen shot another report generated by the OWASP ZAP tool. Here, the tool found that, the timestamp was disclosed by the application / web server (Niculae et al. 2020). The data stored in the server are encapsulated with a token, when they are encrypted. The token contains the token identification number and the time stamp at which it was encrypted. However, as the time stamp has been disclosed, then the hackers will be able to track the data which is being stored in the server and the database.
Once the vulnerability has been identified, the next task is to exploit the vulnerabilities in order to access the files and folders which are present in the target machine. In order to do that, we have used the Metasploit framework. This framework contains various kinds of tools for all the ports which are open. It has a range of exploits depending on the port number or the service which the port provides. In order arrange the exploit, we need to select the exploit from the list and then assign the target internet protocol address.
In this above screen shot, it displays the report generated from the Metasploit Framework, when we trying to find the operating system which is being used by the computer system. Along with that, we were also able to find the PHP version which the internet protocol address computer system is using (Shioi and Fukui 2021). The result generated is Apache / 1.3.37 (Unix) PHP / 4.4.4. From this, we are able to know that, the Apache version which is being used by the target computer system is 1.3.37. Along with that, we also came to know that, the operating system present in computer system is Unix.
The above screen shot displays, the result which tell us that, the exploit has been performed in the target computer system. The port number 80 is mainly used for the hypertext transfer protocol service (Kang et al. 2020). This service helps us in connecting with various kinds of websites. When the hackers and intruders gain access to this port, then they are able to view all the databases and information that are present in the website, and will be able to extract them. Along with that, the information and data sent by the users to the website, which are mostly personal data and information, those gets in the hands of the hackers and intruders.
In order secure the port number 80, the organization needs to install all the security patches which are available for the firewall of the server. Along with that, the information security team needs to remove unnecessary roles and responsibilities from the server. All the request must be set to use proxy.
The above screen shot shows the result of a nmap command in order to find the status of the port number 5903 which is used by the VNC service. The VNC Service also known as Virtual Network Computing helps in establishing a remote connection with the target computer system.
Once the VNC service has been exploited, we can use the VNC viewer command for the target internet protocol address. Once the Remote Frame Buffer protocol has established a connection with the remote computer system, it will launch the above screen. This will confirm that, we will be able to remotely control the targeted computer system. Once the hacker and intruders are able to exploit the VNC service, they will be able to remotely control the computer system and then perform various kinds of illegal functions.
In order to protect the port number 5903, we need to install antivirus software application into the computer system. Along with a system administrator needs to be assigned, which will monitor all the requests which are being made to the port number 5903. Any unverified service request must be removed.
In order to mitigate the vulnerabilities, present in the port number 22, we need to use transmission control protocol wrappers. It will help in protecting the header files of the service requests. Furthermore, direct login to root should also be disabled.
In order to conclude, in this report we have discussed about the various kinds of tests which are performed under penetration testing. We were able to find the vulnerabilities which are present in the computer system. After that, we have also performed exploitation on the vulnerabilities in order to gain data and information. Lastly, we have discussed about the various kinds of mitigation techniques which can be used in order to remove the vulnerabilities.
Dieber, B., White, R., Taurer, S., Breiling, B., Caiazza, G., Christensen, H. and Cortesi, A., 2020. Penetration testing ROS. In Robot Operating System (ROS) (pp. 183-225). Springer, Cham.
Imai, T. and Tonoughi, K., 2021, February. Correlation of N value with S-wave velocity and shear modulus. In Penetration Testing (pp. 67-72). Routledge.
Kang, X., Sun, H.M., Luo, H., Dai, T. and Chen, R.P., 2020. A Portable Bender Element-Double Cone Penetration Testing Equipment for Measuring Stiffness and Shear Strength of In-Situ Soft Soil Deposits. KSCE Journal of Civil Engineering, 24(12), pp.3546-3560.
McKinnel, D.R., Dargahi, T., Dehghantanha, A. and Choo, K.K.R., 2019. A systematic literature review and meta-analysis on artificial intelligence in penetration testing and vulnerability assessment. Computers & Electrical Engineering, 75, pp.175-188.
Mudiyanselage, A.K. and Pan, L., 2020. Security test MOODLE: a penetration testing case study. International Journal of Computers and Applications, 42(4), pp.372-382.
Neal, C., Dagdougui, H., Lodi, A. and Fernandez, J.M., 2021, January. Reinforcement Learning Based Penetration Testing of a Microgrid Control Algorithm. In 2021 IEEE 11th Annual Computing and Communication Workshop and Conference (CCWC) (pp. 0038-0044). IEEE.
Niculae, S., Dichiu, D., Yang, K. and Bäck, T., 2020. Automating penetration testing using reinforcement learning.
Schwartz, J., Kurniawati, H. and El-Mahassni, E., 2020, June. POMDP+ Information-Decay: Incorporating Defender's Behaviour in Autonomous Penetration Testing. In Proceedings of the International Conference on Automated Planning and Scheduling (Vol. 30, pp. 235-243).
Shioi, Y. and Fukui, J., 2021, February. Application of N-value to design of foundations in Japan. In Penetration Testing (pp. 159-164). Routledge.
Zennaro, F.M. and Erdodi, L., 2020. Modeling penetration testing with reinforcement learning using capture-the-flag challenges and tabular Q-learning. arXiv preprint arXiv:2005.12632.
Zhang, N., Arroyo, M., Ciantia, M.O., Gens, A. and Butlanska, J., 2019. Standard penetration testing in a virtual calibration chamber. Computers and Geotechnics, 111, pp.277-289.
Zsikó, S., Cutcher, K., Kovács, A., Budai-Szűcs, M., Gácsi, A., Baki, G., Csányi, E. and Berkó, S., 2019. Nanostructured lipid carrier gel for the dermal application of lidocaine: Comparison of skin penetration testing methods. Pharmaceutics, 11(7), p.310.
Are you in dire need of assignment help in the UK? Can’t figure out who can help you whenever you find yourself thinking, “Wouldn’t it be great if I could pay someone to do my assignment?” With Myassignmenthelp.co.uk, you can fulfil your desires without any hassle.
Send us your requirements, and our paper writers will take care of your assignment worries quickly. So now, you don't have to worry about, "Where can I find someone to do my assignment for me in the UK?” Instead, let our experts provide you with the best assignment help in London, Bristol, Manchester, Liverpool and more!
Upload your Assignment and improve Your Grade
Boost Grades