Pen Testing a server

Job ID: 33489455

Budget: £20 – £250 GBP

Scenario:
Assume that you are working for a company called PentestingPros, which has a track record of successful pentest. Your client has asked your employer to retest a server following a previous penetration test, which was conducted by another SME. Your penetration test will take place as soon as the client remediates the major findings from the initial pentest. During the first briefing meeting, the client informed you that the retest of the server will take place during some weeks of March and April 2022. In particular, you will be assigned specific timeslots throughout the week in which you will be able to pentest the server. They also inform you that the main vulnerabilities found by the previous pentest include:
• A backdoor listening on port 55
• A number of compromised ssh credentials
• Sensitive data exposure via the web server
that will assess your ability to conduct a full-scale penetration test. Please ensure that in completing these tasks you deploy the techniques you have been taught in your course and, especially, in this module. If you produce work that is not concise and to the point, then marks may be reduced.
Task
You are expected to undertake a grey-box Penetration Test in response to the penetration test that has been described in the scenario above.
Thus, plan your time and make sure that you complete all the technical work on time. Information about the IP address of the target of your pentest as well as the schedule to access it is available on Canvas. Specifically, please navigate to the module on Canvas and select the “Your Assignment IP address and your Access Schedule” page, which is available under the “Module Information” Unit, in order to find more information.
Assignment IP Address: 192.168.2.14