Via: Moodle
Marks release expected: None
Feedback Method: Individual Feedback Via Turnitin / Aula
Word limit: 2000
In this assessment you are required to write a report on the security of a web application of up to 2000 words.
This report should consists of two elements:
For the first element of the report you will need to complete a series of hacking tasks on a virtual machine.
The machine will allow you to demonstrate your ability to exploit common web application flaws including topics like:
For the report you are expected to write a brief summary of how you exploited the flaw. For example, a description of the attack, and any payloads used.
This element of the report can be screenshots or code samples, some discussion of the thought process used for exploitation, along with any flags gained during the process.
For the second element of the report you are required to write a short report on ONE element of the OWASP top 10. You are free to chose any element, either one of the topics we study in the lab sessions such as XSS or SQLi, or another element that interests you.
Element | Marks Available |
---|---|
Introduction / Conclusions / Structure | 10 |
Audit | 50 |
Discussion | 40 |
(Consisting of) | |
- Technical Implementation | (15) |
- Context / Example | (10) |
- Mitigation | (10) |
- Legal and Ethical Considerations | (5) |
The recommended structure for the report is
Grade | Mark | Description |
---|---|---|
No submission | 0 | No work submitted |
Fail | 0-25 | Clear failure demonstrating little understanding of relevant theories, concepts and issues. Minimal evidence of research and use of established methodologies and incomplete knowledge of the area. Serious and fundamental errors and aspects missing. No evidence of research. |
Near Fail | 25-39 | Very limited understanding of relevant theories, concepts and. Little evidence of research and use of established methodologies. Some relevant material will be present. Deficiencies evident in analysis. Fundamental errors and some misunderstanding likely to be present. |
Pass | 40-49 | Meets the learning outcomes with a basic understanding of relevant theories, concepts and issues.. Demonstrates an understanding of knowledge and subject-specific theories sufficient to deal with concepts. Assessment may be incomplete and with some errors. Research scope sufficient to evidence use of some established methodologies. Some irrelevant material likely to be present |
2:2 | 50-59 | Good understanding of relevant theories, concepts and issues with some critical analysis. Research undertaken accurately using established methodologies, enquiry beyond that recommended may be present. Some errors may be present and some inclusion of irrelevant material. Good understanding, with evidence of breadth and depth, of knowledge and subject-specific theories with indications of originality and autonomy |
2:1 | 60-69 | Very good work demonstrating strong understanding of theories, concepts and issues with clear critical analysis. Thorough research, using established methodologies accurately, beyond the recommended minimum with little, if any, irrelevant material present. Very good understanding, evidencing breadth and depth, of knowledge and subject-specific theories with some originality and autonomy. |
First | 70-79 | Excellent work with clear evidence of understanding, creativity and critical/analytical skills. Thorough research well beyond the minimum recommended using methodologies beyond the usual range. Excellent understanding of knowledge and subject-specific theories with evidence of considerable originality and autonomy. |
Outstanding | 80-90 | Outstanding work with high degree of understanding, creativity and critical/analytical skills. Outstanding understanding of knowledge and subject-specific theories. Evidence of outstanding research well beyond minimum recommended using a range of methodologies. Demonstrates creative flair, originality and autonomy. |
Exceptional | 90-100 | Exceptional work with very high degree of understanding, creativity and critical/analytic skills. Evidence of exceptional research well beyond minimum recommended using a range of methodologies. . Exceptional understanding of knowledge and subject-specific theories. Demonstrates creative flair, a high degree of originality and autonomy. |