Practical Lab Task
Practical Lab Task
Requirements
1. Tools/Software Needed:
o PC/Laptop
o VirtualBox Download VirtualBox
o Access to Vulnerable VMs
Platforms:
▪ VulnHub – VMs designed for practice and learning.
▪ Hack The Box – An online platform with various penetration testing
challenges.
Task Instructions
Example Command:
nmap -A -T4 target_ip
Objective: Identify open ports and running services that might be exploited.
1. Introduction:
o Brief description of the target system.
o Purpose of the penetration test.
2. Tools and Methodology Used:
o List of tools employed (e.g., Nmap, Nikto).
o Brief explanation of each tool and its purpose.
3. Vulnerability Identification and Assessment:
o Summary Table: List the identified vulnerabilities, their impact, and CVSS
scores (if applicable).
o Sample Table:
4. Mitigation Recommendations:
• For each vulnerability, propose specific mitigation actions (e.g., patching, disabling
unnecessary services).
5. Conclusion:
• Summary of findings.
• Reflections on challenges faced during the process.
Depending on the nature of the VM and discovered vulnerabilities, students may need
additional tools, such as:
Category Tools
Network Sniffing Dsniff, Ettercap, Kismet, Wireshark
File Integrity Checking Autopsy, RootkitHunter, Sleuthkit
Vulnerability Scanning Nmap, Metasploit, Hydra, SuperScan
Wireless Scanning Airsnarf, Kismet, WiFiTAP
Password Cracking John the Ripper, Hydra, WebCrack
Assessment Criteria
Submission Guidelines
• Submit your final report as a PDF through the Microsoft Teams channel.
• Include screenshots of key steps (e.g., open ports, vulnerability scan results).
• Submission Deadline: 10 days after starting the task.
Important Notes
• This task is individual; each student should select a different target VM.
• Students can use online resources but must reference any external material.
• Plagiarism will result in disqualification from the lab.