Module 4 Assignment
Module 4 Assignment
Assignment : VAPT
Project Title: Vulnerability Assessment and Penetration Testing of "testphp.vulnweb.com"
Project Description:
In this project, students will conduct a hands-on vulnerability assessment and penetration test on the
"testphp.vulnweb.com" website. This website is intentionally vulnerable, making it an ideal target for learning and
practicing cybersecurity skills. The project will allow students to apply their knowledge in vulnerability
assessment, OWASP, CVE, CWE, and the use of tools like Nmap, Nikto, and Burpsuite.
Project Components:
Preparation:
Obtain authorization from the website owner or administrator to perform the assessment and penetration test.
Vulnerability Assessment:
Use Nmap to perform a network scan and identify open ports and services on the target website.
Run Nikto to conduct an automated vulnerability scan and gather information about the web application.
Web Application Assessment:
Identify common web vulnerabilities such as SQL injection, cross-site scripting (XSS), and cross-site request forgery
(CSRF).
Identify and document instances of OWASP Top 10 vulnerabilities found on the website.
Research and identify specific CVEs (Common Vulnerabilities and Exposures) and CWEs (Common Weakness
Enumeration) associated with any vulnerabilities discovered.
Reporting:
Include an executive summary, methodology, findings, risk assessment, and recommendations for mitigating
vulnerabilities.
Remediation Recommendations:
Provide detailed recommendations and steps to remediate the vulnerabilities found during the assessment.
Presentation:
Present the findings and recommendations to the class or instructor, simulating a real-world scenario where you
report to a client or management.
The students are encouraged to discuss the challenges they faced during the project and the lessons they learned.
Project Benefits: