Security & Penetration Testing of Web Application

Closed
Carnival Guide
Toronto, Ontario, Canada
Leron Baptiste
Process and Development
(7)
3
Project
Academic experience
120 hours per learner
Learner
Anywhere
Intermediate level

Project scope

Categories
Website development Security (cybersecurity and IT security) Information technology Databases Networking
Skills
nmap penetration testing nessus preparing executive summaries open web application security project (owasp) vulnerability research
Details

We would like a group of students to design and perform a pen test on our application, involving:

  1. Students become familiar with our product and understand generally how it works.
  2. Students should spend time conducting research on state of the art pen testing technologies. They should look into common vulnerability lists such as OWASP Top 10, and common security tools such as Nmap, Burp Suitar, Nessus, and Wireshark.
  3. Students should have a written attack plan and present it to us so we can confirm we understand what the test will do and what might be uncovered.
  4. Students are free to attack our product per the presented plan.
  5. Students submit a final report of any findings.
Deliverables

First, before testing begins, students should present a testing plan to us. This should include tools they will use, techniques for exploitation, what categorical vectors of attack will they go after, and any other information they feel like they need to present.

The final deliverable should be a written report detailing how the test was conducted, what tests passed, what tests failed, recommendations for mitigation strategies, and any further notes from the testers. Other items to consider for a final report should be:

  • An executive summary detailing overview, timeline, key findings.
  • Categorizing all findings into vulnerability levels such as critical, high, medium, low.
  • High detailed summaries of any findings.
  • Low detailed summaries of any tests conducted with no findings.
  • A recap of any tools used.
Mentorship

A walk through of the product, as well as lighter technical details of it will be provided to students before they begin testing.

Students will be able to ask questions at any point during the process.

About the company

Company
Toronto, Ontario, Canada
2 - 10 employees
Entertainment, Travel & tourism, Events services, Media & production, Retail

Carnival Guide operates as the main hub for all Caribbean Carnival Committees that host carnivals around the world.

Carnival Guide brings you an all-inclusive approach to all your carnival experiences and needs... we keep you in the know. It’s your guide to all things Carnival. A one stop shop that includes Flights, Hotels, Costumes purchase, Car rentals, Events tickets, Artiste/Music, Picture/Media gallery, Tours and Adventures, restaurants and much more.

Carnival Guide provides an end to end solution, making it much easier to plan one carnival experience to the next.