日韩精品一区二区三区高清_久久国产热这里只有精品8_天天做爽夜夜做爽_一本岛在免费一二三区

合肥生活安徽新聞合肥交通合肥房產生活服務合肥教育合肥招聘合肥旅游文化藝術合肥美食合肥地圖合肥社保合肥醫院企業服務合肥法律

代做 FIT3173、代寫 SQL 編程設計
代做 FIT3173、代寫 SQL 編程設計

時間:2025-05-05  來源:合肥網hfw.cc  作者:hfw.cc 我要糾錯



FIT3173 Software Security Assignment-2 (S1 2025)

Total Marks 100

Please see Moodle for the due date.

1 Overview

The primary learning objective of this assignment is to provide you with firsthand experience in exploiting

SQL Injection, Cross-site Scripting and Cross-site Request Forgery vulnerabilities. Additionally, it aims

to deepen your understanding of these vulnerabilities. This assessment does not require a specific virtual

machine (VM) and can be executed on any operating system. You can utilize the same setup as the Lab07

and Lab08.

2 Submission

For this assignment, you need to submit two files using a single submission link on Moodle:

? A PDF file with relevant screenshots, and

? a singlevideo filecontaining the recording of you carrying out all tasks.

Typeset your report into .pdf format (make sure it can be opened with Adobe Reader) and name it as the

format:[Your Name]-[Student ID]-FIT3173-Assignment.pdf.

All payloads, if required, should be embedded in your report. In addition, if a demonstration video is

required, you should record your screen demonstration with your voice explanation. You can use this free

tool to make the video:https://monash-panopto.aarnet.edu.au/ ; other tools, such as Zoom, are also fine.

Important notes and penalties:

? A part of the submitted video (at a corner) must clearly show your face at all times. Penalties may

apply when that’s not the case.

? Video demonstration should be a live exploitation of the vulnerabilities.

? Late submissions incur a 5-point deduction per day. For example, if you submit 2 days and 1 hour

late, that incurs 15-point deduction. Submissions more than 7 days late will receive a zero mark.

? If you require extension or special consideration, refer tohttps://www.monash.edu/students/

admin/assessments/extensions-special-consideration. No teaching team mem-

ber is allowed to give you extension or special consideration, so please do not reach out to a teaching

team member about this. Follow the guidelines in the aforementioned link.

? The maximum allowed duration for the recorded video is 15 mins in total. Therefore, only the first

15:00 mins of your submitted video will be marked. Any exceeding video components will be ignored.

? If your device does not have a camera (or for whatever reason you can’t use your device), you can

borrow a device from Monash Connect or Library. It’s your responsibility to plan ahead for this.

Monash Connect or Library not having available devices for loan at a particular point in time is not a

valid excuse.

? You can create multiple video parts at different times, and combine and submit a single video at the

end. Make sure that the final video is clear and understandable.

1

? You can do (online) research in advance, take notes and make use of them during your video recording.

You may also prepare exploit scripts in advance. But you cannot simply copy-paste commands to carry

out the tasks without any explanations. Explanations (of what the code does) while completing the

tasks are particularly important.

? Zero tolerance on plagiarism and academic integrity violations: If you are found cheating, penalties

will apply, e.g., a zero grade for the unit. The demonstration video is also used to detect/avoid plagia-

rism. University policies can be found athttps://www.monash.edu/students/academic/

policies/academic-integrity.

3 Web Application Vulnerabilities

Q1: Complete three labs fromPortSwigger Labs, one from SQL Injection, one from Cross-Site

Scripting, and one from Cross-Site Request Forgery section. Please select labs designated as PRAC-

TITIONER or EXPERT; APPRENTICE labs will not be accepted. You are permitted to utilize the

solutions and demonstrations available on the PortSwigger website for assistance. However, please

do not copy walkthroughs from the PortSwigger website. You will approach the labs as a penetration

tester, simulating a real-world scenario where you exploit each target as if you were doing it for the

first time. Your solution should include the logical steps that lead to the exploitation, which may not

be covered in the walkthroughs on the PortSwigger website.[60 Marks]

Record a video and write a report to answer the following questions for each lab. At the beginning

of each lab recording, please state your name, student ID, and the name of the lab you are solving;

no marks can be awarded without this information.

1. How did you identify the vulnerability? (5 Marks)

2. Which payload was chosen for exploitation and why? (5 Marks)

3. What an attacker could achieve using the vulnerability? (5 Marks)

4. How the vulnerability can be mitigated? (theoretically, no demonstration is required) (5 Marks)

The video submission must demonstrate solving the lab, addressing the questions outlined above. In

case time runs short during the video, you may use the report to address any unanswered questions,

making references to relevant sections of the video. However, it is important that the video includes,

at a minimum, a demonstration of the lab. The report does not need to be in detail, it should briefly

address the mentioned questions, i.e. it can contain one or two-line answer for each question, pay-

loads and important screenshots (if necessary). The marks mentioned above are for the videos and

report combined.The word limit for each sub-question is 200 words, i.e. maximum 800 words

are allowed for Q1 per lab.

2

Q2: Download theQ2.htmlfile from Moodle. Assume you are browsingmonash.edu, and

it is hypothetically vulnerable to various web attacks (although it is not).While navigating

monash.edu, assume you open another tab in the same browser, and visitattacker.com(as-

suming attacker convinced you to do that). You click theSubmitbutton on theattacker.com

webpage, which containsQ2.html, initiating attacks onmonash.edu. ExamineQ2.html(you

can open the file in the browser and intercept the request in BurpSuite if desired) and respond to the

following questions.No video is required for this question. The word limit for each sub-question

is 200 words, i.e. maximum 600 words are allowed for Q2. [20 Marks]

1. Which vulnerability/vulnerabilitiesattacker.comis trying to exploit onmonash.edu?

(please explain the scenario outlining how this exploitation could occur) (10 Marks)

2. If successful, what is the consequence of the attack(s)? (5 Marks)

3. What mitigation(s) would you suggest formonash.eduto counter attack(s) launched by

attacker.com? (5 Marks)

Note: The parameter values in the HTML file are URL encoded.

3

Q3: Assume you visitmonash.eduand it tries to talk tolms.monash.edu, the browser issues

an OPTIONS method tolms.monash.eduand gets a response, below is the HTTP request and

its response:

OPTIONS /doc HTTP/1.1

Host: lms.monash.edu

User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:71.0)

Accept: text/html,application/xhtml+xml,application/xml

Accept-Language: en-us,en;q=0.5

Accept-Encoding: gzip,deflate

Connection: keep-alive

Origin: monash.edu

Access-Control-Request-Method: POST

Access-Control-Request-Headers: x-requested-with

HTTP/1.1 204 No Content

Date: Mon, 01 Dec 2008 01:15:39 GMT

Server: Apache/2

Access-Control-Allow-Origin:

*

Access-Control-Allow-Methods: POST, GET, OPTIONS

Access-Control-Allow-Headers: x-requested-with

Access-Control-Allow-Credentials: true

Access-Control-Max-Age: 86400

Vary: Accept-Encoding, Origin

Keep-Alive: timeout=2, max=100

Connection: Keep-Alive

Explain the Cross-Origin Resource Sharing (CORS) HTTP headers in the above HTTP request and

response. Please avoid listing each header with an explanation; instead, gather the key information

and present it in a concise paragraph.

Would browser change future requests based on the above HTTP response?No video is required

for this question. The word limit for Q3 is 300 words. [10 Marks]

4 Report Completion and Quality of Presentation [10 Marks]

Marks are allocated to the quality and clarity of presentation in the report and the video.

請加QQ:99515681  郵箱:99515681@qq.com   WX:codinghelp


 

掃一掃在手機打開當前頁
  • 上一篇:代做 MATH2052編程、代寫 MATH2052設計程序
  • 下一篇:代做 EEB 504B、代寫 java/Python 程序
  • 無相關信息
    合肥生活資訊

    合肥圖文信息
    2025年10月份更新拼多多改銷助手小象助手多多出評軟件
    2025年10月份更新拼多多改銷助手小象助手多
    有限元分析 CAE仿真分析服務-企業/產品研發/客戶要求/設計優化
    有限元分析 CAE仿真分析服務-企業/產品研發
    急尋熱仿真分析?代做熱仿真服務+熱設計優化
    急尋熱仿真分析?代做熱仿真服務+熱設計優化
    出評 開團工具
    出評 開團工具
    挖掘機濾芯提升發動機性能
    挖掘機濾芯提升發動機性能
    海信羅馬假日洗衣機亮相AWE  復古美學與現代科技完美結合
    海信羅馬假日洗衣機亮相AWE 復古美學與現代
    合肥機場巴士4號線
    合肥機場巴士4號線
    合肥機場巴士3號線
    合肥機場巴士3號線
  • 短信驗證碼 trae 豆包網頁版入口 目錄網 排行網

    關于我們 | 打賞支持 | 廣告服務 | 聯系我們 | 網站地圖 | 免責聲明 | 幫助中心 | 友情鏈接 |

    Copyright © 2025 hfw.cc Inc. All Rights Reserved. 合肥網 版權所有
    ICP備06013414號-3 公安備 42010502001045

    日韩精品一区二区三区高清_久久国产热这里只有精品8_天天做爽夜夜做爽_一本岛在免费一二三区

      <em id="rw4ev"></em>

        <tr id="rw4ev"></tr>

        <nav id="rw4ev"></nav>
        <strike id="rw4ev"><pre id="rw4ev"></pre></strike>
        久久久999精品| 亚洲欧美日韩国产综合精品二区| 伊人成综合网伊人222| 1024日韩| 国内精品伊人久久久久av影院| 免费久久99精品国产自在现线| 久久久久久欧美| 午夜精品av| 国内成人精品一区| 久久久av毛片精品| 久久精品一区二区国产| 国产欧美一区在线| 国产情侣久久| 欧美一区二区三区啪啪| 欧美日韩亚洲一区二| 狠狠色狠狠色综合日日91app| 黄色精品一二区| 亚洲国产精品成人综合| 久久亚洲精品欧美| 欧美日韩免费区域视频在线观看| 麻豆久久久9性大片| 亚洲人成网站精品片在线观看| 国产欧美在线观看| 亚洲一区亚洲二区| 国产视频一区欧美| 国产精品99一区二区| 美女脱光内衣内裤视频久久影院| 亚洲电影免费在线观看| 在线观看视频一区二区| 在线看无码的免费网站| 亚洲淫片在线视频| 欧美资源在线| 亚洲美女中出| 亚洲综合视频网| 国产精品一区一区三区| 国产啪精品视频| 国产精品久久福利| 国产精品久久久久久久免费软件| 亚洲一区二区不卡免费| 国产一区二区三区黄视频| 久久视频国产精品免费视频在线| 国产精品乱码一区二区三区| 亚洲免费在线视频一区 二区| 国产综合色精品一区二区三区| 亚洲一区二区三区777| 亚洲区一区二| 久久精品国产久精国产爱| 国产精品一区一区三区| 久久久久综合网| 国产午夜亚洲精品理论片色戒| 一本大道av伊人久久综合| 国产精品视频精品视频| 欧美精品日本| 亚洲大胆视频| 久久亚洲精品中文字幕冲田杏梨| 久久亚洲精品中文字幕冲田杏梨| 悠悠资源网久久精品| 欧美激情小视频| 亚洲青涩在线| 亚洲一区二区三区免费观看| 欧美成人精品高清在线播放| 久久久噜噜噜久噜久久| 国产精品嫩草影院av蜜臀| 国产精品久久久久久久久久久久久| 久久精品国产96久久久香蕉| 欧美精品国产精品日韩精品| 亚洲免费观看视频| 国产精品久久久一本精品| 黑人巨大精品欧美一区二区小视频| 亚洲国产成人精品女人久久久| 国内精品视频久久| 麻豆精品视频在线| 欧美午夜不卡影院在线观看完整版免费| 亚洲精品国精品久久99热一| 国产午夜精品美女视频明星a级| 午夜精品福利视频| 国产欧美日韩精品a在线观看| 亚洲国产成人精品久久久国产成人一区| 亚洲日本电影| 亚洲美女啪啪| 欧美日韩另类国产亚洲欧美一级| 欧美三区视频| 欧美一区午夜精品| 精品51国产黑色丝袜高跟鞋| 欧美激情国产日韩| 欧美一区二区免费观在线| 欧美一级午夜免费电影| 欧美一区二区三区电影在线观看| 欧美黄色一区二区| 亚洲欧洲另类国产综合| 亚洲精品一区二区在线观看| 亚洲欧美激情一区| 国产欧美亚洲视频| 欧美激情 亚洲a∨综合| 国产亚洲a∨片在线观看| 欧美视频在线观看免费网址| 欧美午夜性色大片在线观看| 亚洲自拍偷拍视频| 欧美激情中文字幕在线| 国产一区二区欧美日韩| 在线看片欧美| 国产日韩亚洲欧美综合| 欧美成人高清视频| 欧美尤物一区| 蜜桃av一区二区三区| 久久国产精彩视频| 欧美jizz19hd性欧美| 欧美精选在线| 一区二区视频欧美| 国产精品日韩精品欧美在线| 99ri日韩精品视频| 久久久精品日韩欧美| 国产精品国产三级国产aⅴ无密码| 亚洲精品之草原avav久久| 久久美女艺术照精彩视频福利播放| 欧美精品久久久久久久| 国产精品一区视频| 国产综合色在线| 国产精品中文在线| 久久亚洲精品伦理| 国产一区二区三区最好精华液| 亚洲自拍偷拍色片视频| 久久九九电影| 久久天堂成人| 欧美专区日韩视频| 久久免费的精品国产v∧| 欧美激情一二区| 欧美中文字幕在线视频| 欧美与欧洲交xxxx免费观看| 欧美视频福利| 亚洲免费在线观看| 久久久久久久久岛国免费| 欧美亚州韩日在线看免费版国语版| 香蕉精品999视频一区二区| 极品少妇一区二区三区精品视频| 国产乱理伦片在线观看夜一区| 亚洲精品少妇30p| 国产一区二区三区奇米久涩| 欧美黄色日本| 亚洲激情av在线| 久久男人av资源网站| 一区二区电影免费观看| 国产一区二区在线免费观看| 欧美日韩国产va另类| 亚洲欧美日韩中文视频| 国产在线麻豆精品观看| 欧美精品 国产精品| 香蕉久久夜色精品国产| 日韩视频二区| 欧美二区在线观看| 亚洲三级电影全部在线观看高清| 亚洲一区www| 久久xxxx精品视频| 亚洲日本激情| 亚洲国产三级在线| 欧美日韩裸体免费视频| 国产精品一二三四| 国产亚洲综合精品| 国产女主播视频一区二区| 午夜精品久久久久久久99黑人| 欧美国产1区2区| 久久国产精品网站| 久久精品天堂| 伊人精品久久久久7777|