OWASP Security Auditing & Risk Mitigation

Job ID: 39995901

Budget: £20 – £250 GBP

Scenario-based lab: OWASP Security Auditing using Burp Suite
Learning Outcomes Covered in this Assignment:
Critically evaluate security threats on web applications and identify various methods to mitigate them.
Demonstrate critical understanding how mis-configured servers can lead to critical data being exposed.
Recommend effective countermeasures to enhance the security of database systems and database-powered web applications.
What to do :
Download Module VMs Image: You are required to download the Module VMs image from the Cyber Security VMs repository, accessible through the link provided in Lab environm nt setup document. Refer to the document for specific details on which Vito download.
• Web Security Assessment on Juice shop: Conduct an extensive web application security assessment on the OWASP juice shop site provided for this assessment.
• You must follow to the "The OWASP Testing Framework Guide" for your penetration testing methodology for all your penetration test.
• Provide a Technical report: In this report, you should explain the technical details of the vulnerability Assessment. You will need to assume that the reader will be responsible for implementing changes to secure the environment.
• Attack Surface Categories: You are required to identify and analyze eight distinct vulnerabilities (two from each category) across the following four attack surface categories:
- Broken Authentication & Access Controls
Server-side Injection Attacks
- Client-side Attacks
- Other Types of Attacks (select two vulnerabilitles from any other OWASP
Top Ten security risks)
• For each identified vulnerability, you must provide!
- Exploit steps and supporting evidence (e.g., screenshots, payloads, or logs)
- Root cause analysis explaining why vulnerability exists
• Mitigation Strategies: For each successful exploit, provide a mitigation method such as the necessary steps to protect the web environment against such attacks.
• Threat modelling: Finally, for each identified vulnerability, present a threat model using the DREAD threat modelling technique, providing a brief summary for each of the DREAD components. No more than 3500 words