SECURITY PRACTICAL EXAM
TIME: 3 HOURS
LAB SETUPMachines:
Attacker: Kali Linux
Victim 1: Metasploitable 2
Victim 2: Windows Server (optional)
Network:
Kali: 192.168.1.5
Metasploitable: 192.168.1.10
SECTION A: RECON & ENUMERATION (20 MARKS)
Task 1: Identify Live Hosts
Task 2: Full Port Scan
Task 3: Service Enumeration
SECTION B: VULNERABILITY ANALYSIS (20 MARKS)
Task 4: Scan for Vulnerabilities
Using OpenVAS or Nessus
Task 5: Risk Analysis
SECTION C: EXPLOITATION (20 MARKS)
Task 6: Exploit FTP Backdoor
Using Metasploit Framework
Task 7: Post Exploitation
a) whoami
b) uname -a
c) cat /etc/passwd
SECTION D: PASSWORD ATTACK (15 MARKS)
Task 8: Brute Force SSH
Using Hydra
Task 9: Security Analysis
SECTION E: PRIVILEGE ESCALATION (10 MARKS)
Task 10: Check Sudo Permissions
SECTION F: WEB ATTACK (15 MARKS)
Task 11: SQL Injection
Target:
http://192.168.1.10/dvwa
Using Burp Suite
Task 12: XSS Attack
Input:
<script>alert('Hacked')</script>
SECTION G: LOG ANALYSIS (10 MARKS)
Task 13: Investigate Logs
SECTION H: SYSTEM HARDENING (10 MARKS)
Task 14: Secure the System
--------------------------------------------------------------------------------------
FOR ANY ENQUIRIES WHATSAPP: 0692 127 931
0 comments:
Post a Comment