7COM1068 Penetration Testing Assignment sample

The grey box testing is done to understand the concept of grey box testing that is implemented in the penetration testing of the network.

  • 92650+ Project Delivered
  • 1500+ Experts 24x7 Online Help
  • No AI Generated Content
GET 45% OFF + EXTRA 10% OFF
- +
45% Off
£ 7.27
Estimated Cost
£ 4
Prices Start From
GBP 4.00GBP 9.00
8 Pages 1897 Words

Introduction Of Penetration Testing Assignment Sample

Get free written samples from our top-notch subject experts and Assignment Helper team.

Penetration testing is the process of testing a networking system or web applications that enables the high security of the network. The major vulnerabilities of the network are detected by the penetration testing method. The penetration testing includes different network services as well as applications. The penetration testing is done using the code 8807. The login ID and the password are provided to access the penetration test in the selected IP address that is 192.168.1.187, which is given in the report.

Concept of pen testing & ethical considerations

The penetration testing is used to protect against the cyberattack against the network system. The penetration testing checks the different vulnerabilities that exploit the overall cyberattack. The web application system totally depends on the testing of the penetration in the network system. The penetration testing involves the number of application systems. Besides, the frontend and the backend servers are susceptible to the code injection attacks. There are different methods that are involved in the penetration testing process. According to Khalsa et al. (2021, p. 336), they are external testing, internal testing, blind testing, double-blind testing, and targeted testing. The penetration testing has some vulnerabilities, such as user awareness, unsupported legacy software, and insecure in-house developed applications. The penetration testing has many issues regarding the software-related problems that occurred in the connection of the networks.

Figure 1: Stages of penetration testing

(Source: Self-created)

Ethical Considerations

The penetration testing is authorised within legal limits. The penetration testing provides the security that enables the confirmation of the user to secure their network-related problems. The penetration testing is very useful in order to ensure the information of the systems by performing the hacking operations. As commented by Khumaidi (2021, p. 225). The penetration testing offers the optimisation of the network system that enables the encryption of the sensitive data and protects it from the corruption of the crucial data. The penetration testing enables the provision of the theories which are used to classify the arguments by providing appropriate action.

Concept of HTTP, SSH and VNC

HTTP

The HTTP server is software that represents the web addresses as well as the different server protocols (Hawedi et al., p. 112). The HHTP server can be accessed from the domain of the websites, and it transfers the hosted websites to the end user’s device.

Figure 2: Flowchart of HTTP

(Source: Self-created)

The above diagram shows the working stages of the HTTP server. The execution of the testing is achieved by the flowchart diagram.

SSH

The SSH is a protocol that is used to exchange the data between the two computers. The SSH server protects the privacy and the integrity of the transferred identities of the data and files. The SSH server runs on every computer as well as on every server.

Figure 3: Flowchart of SSH

(Source: Self-created)

The above figure shows the stages of penetration testing using the SSH server (Garre et al., 2021, p. 390). The flowchart describes that the connection of the SSH server is important in order to establish the link between user 1 and user 2.

VNC

Virtual Network Computing is the desktop sharing system that is used to control another computer system. The virtual network computing uses the Remote Frame Buffer Protocol to control the computer system remotely.

Figure 4: Flowchart of VNC

(Source: Self-created)

The above diagram describes the working principle of the virtual network computing process. The connection of the virtual LAN is developed in the very first stage of the VNC process. Then the IP configuration is done to create the virtual network with the default IP address.

Grey Box Testing

Grey box testing is one of the software testing techniques that enables the testing of a software product. Besides, the web application and the internal structure of the application are developed by the grey box testing process. The grey box testing is identifying the detection of the improper structure of code as well as misuse of applications. As commented by Reti et al. (2021, p. 882), the grey box testing is used to provide the benefits of the black box and white box testing. The grey box testing is basically the combination of two testing processes that improves the design of the source code as well as the implementation of the network system. The grey box testing reduces the long process of the functional testing and the presence of non-functional types. The grey box testing provides more time to free up the time that the developer is required to fix the problems regarding the penetration of the network. The main advantage of grey box testing is that the completion of the testing on the user end is very much faster than the designer's point of view. Therefore, the grey box testing uses suitable GUI platforms that enable the functional testing and the security measurements of the network system.

This grey box testing has been executed on the target IP address 192.168.1.187. This grey box testing has been executed in order to reflect the IP address and the details of the target machine. This complete process has been executed upon the Kali Linux machine. As stated by Xu et al. (2021, p. 0120115) The complete process has been executed by the researcher through the help of the exploits. The grey box penetration testing is therefore considered as the translucent box, as the box only reveals information like the IP address of the machine and the machine details. This grey box is considered the combinational box of the black box and the white box.

Figure 5: Depicts the codes of Grey box testing codes in Linux

(Source: Self-created)

The above-represented figure depicts the codes that have been used by the researcher in order to execute the grey box testing upon the assigned IP address.

This grey box testing has been represented through the help of the SMB delivery type of exploit and the SMB library type of exploits.

Attack narrative

This part of the report describes the vulnerabilities and the risks that are involved with the penetration testing. The researcher has also reflected on the ways to encounter the vulnerabilities and the ways to encounter the vulnerabilities.

Vulnerabilities and ways to mitigate the encounter with the vulnerabilities

The penetration testing process has also some vulnerabilities that affect the configuration of the server by data hacking and data corruption. While the execution of the penetration testing is done, the server will exhibit the sudden changes that have occurred in the configuration process of the server as well as the machine. As commented by Nikolic et al. (2021, p. 225), the penetration testing involves the international data hacking that is effective for the security purpose of the network. The internal process of the can be affected by the availability of the data that might be shared by the user. The grey box testing procedure is done using the exploits like the SMB delivery type and the SMB relay type. The whole execution process is done by the Red Dot VPN connection. Therefore, the Ethernet network has been changed to execute the existing VPN which is assigned in the network.

Figure 6: Depicts the VPN configuration status

(Source: Self-created)

The above-represented figure depicts the VPN configuration status that the researcher has developed in order to reflect the communication between the target IP and the IP address of the virtual machine.

Through the help of exploits like SMB Relay and the SMB Delivery, the target IP address has been penetrated. The exploits have been identified through the help of the certain IP address

Figure 7: Depicts the exploit SMB relay

Source: (Self-created)

The above-represented figure depicts the server mailbox relay type of exploits that have been identified by the researcher in order to execute the grey box testing.

Figure 8: Depicts the exploit SMB delivery

Source: (Self-created)

The above-mentioned figure depicts the SMB delivery that has been identified by the researcher as an exploit. The VPN connection is an essential part of developing the configuration of the server that is working inside the network. Data corruption is one of the major issues that occurs in the penetration testing. The data is corrupted in case of any kind of misuse of the VPN network by the developer. Therefore, the data corruption represents the point that is effective in the system which is modified by the developer (Dong et al., 2021, March, p. 012112). The penetration testing involves the awareness that is the major problem in order to secure the network parameters. Besides, the different software-related problems are associated with the penetration testing process, as it uses many computer systems to transfer the data from the user end to the developer end.

The vulnerabilities can be minimised by performing different actions in the designed connection. The main step is to stop the involvement of various penetration tests in the system.

Ways to encounter the vulnerabilities of pen testing

The steps for minimising the vulnerabilities of penetration testing are mentioned below.

  • The alternate storage device is designed to develop the storing of the data for targeting the machine. Therefore, the data will be secure for the whole execution process of the network.
  • The strong password should be generated in such a way that the anonymous user cannot access the data. The encryption of the data is used to define the integrity of the system that will surely help for restricting the allowance of malicious objects.
  • The security firewalls should be upgraded to the latest version so that the regular time taken by the server to complete the penetration of the malicious objects is reduced.

Conclusion

Conclusively, the report describes the concept of penetration testing and its working principle. Penetration testing is the process which is associated with the hacking process. Penetration testing basically serves network-related security that enables the encryption of data that is transferred by the network. The working principle of the HHTP, SSH, and VNC server is described in this report. The grey box testing is done to understand the concept of grey box testing that is implemented in the penetration testing of the network. The penetration testing can be performed either with an external or an internal source to simulate different kinds of attacking vectors in the proposed network. The main purpose of penetration testing is to determine the weakness of the security in the network, machine and software.

Need Help Tackling Your Computer Science Assignment?

Get Expert Support with Programming, Algorithms, Reports and Technical Projects

References

  • Dong, K., Zhang, H., Liu, Y., Li, Y. and Peng, Y., 2021, March. Research on Technologies of Vulnerability Mining and Penetration Testing for Satellite Communication Networks. In IOP Conference Series: Earth and Environmental Science (Vol. 693, No. 1, p. 012112). IOP Publishing.
  • Garre, J.T.M., Pérez, M.G. and Ruiz-Martínez, A., 2021. A novel machine learning-based approach for the detection of SSH botnet infection. Future Generation Computer Systems115, pp. 387-396.
  • Hawedi, H.S., Bentaher, O.A. and Abodhir, 2021. K.E., REMOTE ACCESS TO A ROUTER SECURELY USING SSH.
  • Khalsa, S., Castaneda, G., Rivera, R. and Crichigno, J., 2021. A Network Management Software Based on Secure Shell (SSH) Channels and Java Universal Network Graph (JUNG).
  • Khumaidi, A., 2021. IMPLEMENTATION OF DEVOPS METHOD FOR AUTOMATION OF SERVER MANAGEMENT USING ANSIBLE. Jurnal Transformatika18(2), pp. 199-209.
  • NICULA, S. and ZOTA, R.D., 2021. Technical and Economical Evaluation of IOT Attacks and Their Corresponding Vulnerabilities. Informatica Economica, 25(1).
  • Nikolic, I., Mantu, R., Shen, S. and Saxena, P., 2021. Refined Grey-Box Fuzzing with SIVO. arXiv preprint arXiv:2102.02394.
  • Reti, D., Klaaßen, D., Anton, S.D. and Schotten, H.D., 2021. Secure (S) Hell: Introducing an SSH Deception Proxy Framework. arXiv preprint arXiv:2104.03666.
  • Rustamov, F., Kim, J., Yu, J., Kim, H. and Yun, J., 2021. BugMiner: Mining the Hard-to-Reach Software Vulnerabilities through the Target-Orientated Hybrid Fuzzer. Electronics, 10(1), p.62.
  • Xu, Y., Zhong, X., Yepes, A.J. and Lau, J.H., 2021. Grey-box Adversarial Attack And Defence For Sentiment Classification. arXiv preprint arXiv:2103.11576.
Ready to Get Expert Help You Can Trust?

Speak with experienced professionals and get clear, honest guidance tailored to your needs.

45% OFF

×
Securing Higher Grades Costing Your Pocket? Book Your Assignment At The Lowest Price Now!
X