99爱在线视频这里只有精品_窝窝午夜看片成人精品_日韩精品久久久毛片一区二区_亚洲一区二区久久

合肥生活安徽新聞合肥交通合肥房產生活服務合肥教育合肥招聘合肥旅游文化藝術合肥美食合肥地圖合肥社保合肥醫院企業服務合肥法律

代做 FIT3173、代寫 SQL 編程設計
代做 FIT3173、代寫 SQL 編程設計

時間:2025-05-05  來源:合肥網hfw.cc  作者:hfw.cc 我要糾錯



FIT3173 Software Security Assignment-2 (S1 2025)

Total Marks 100

Please see Moodle for the due date.

1 Overview

The primary learning objective of this assignment is to provide you with firsthand experience in exploiting

SQL Injection, Cross-site Scripting and Cross-site Request Forgery vulnerabilities. Additionally, it aims

to deepen your understanding of these vulnerabilities. This assessment does not require a specific virtual

machine (VM) and can be executed on any operating system. You can utilize the same setup as the Lab07

and Lab08.

2 Submission

For this assignment, you need to submit two files using a single submission link on Moodle:

? A PDF file with relevant screenshots, and

? a singlevideo filecontaining the recording of you carrying out all tasks.

Typeset your report into .pdf format (make sure it can be opened with Adobe Reader) and name it as the

format:[Your Name]-[Student ID]-FIT3173-Assignment.pdf.

All payloads, if required, should be embedded in your report. In addition, if a demonstration video is

required, you should record your screen demonstration with your voice explanation. You can use this free

tool to make the video:https://monash-panopto.aarnet.edu.au/ ; other tools, such as Zoom, are also fine.

Important notes and penalties:

? A part of the submitted video (at a corner) must clearly show your face at all times. Penalties may

apply when that’s not the case.

? Video demonstration should be a live exploitation of the vulnerabilities.

? Late submissions incur a 5-point deduction per day. For example, if you submit 2 days and 1 hour

late, that incurs 15-point deduction. Submissions more than 7 days late will receive a zero mark.

? If you require extension or special consideration, refer tohttps://www.monash.edu/students/

admin/assessments/extensions-special-consideration. No teaching team mem-

ber is allowed to give you extension or special consideration, so please do not reach out to a teaching

team member about this. Follow the guidelines in the aforementioned link.

? The maximum allowed duration for the recorded video is 15 mins in total. Therefore, only the first

15:00 mins of your submitted video will be marked. Any exceeding video components will be ignored.

? If your device does not have a camera (or for whatever reason you can’t use your device), you can

borrow a device from Monash Connect or Library. It’s your responsibility to plan ahead for this.

Monash Connect or Library not having available devices for loan at a particular point in time is not a

valid excuse.

? You can create multiple video parts at different times, and combine and submit a single video at the

end. Make sure that the final video is clear and understandable.

1

? You can do (online) research in advance, take notes and make use of them during your video recording.

You may also prepare exploit scripts in advance. But you cannot simply copy-paste commands to carry

out the tasks without any explanations. Explanations (of what the code does) while completing the

tasks are particularly important.

? Zero tolerance on plagiarism and academic integrity violations: If you are found cheating, penalties

will apply, e.g., a zero grade for the unit. The demonstration video is also used to detect/avoid plagia-

rism. University policies can be found athttps://www.monash.edu/students/academic/

policies/academic-integrity.

3 Web Application Vulnerabilities

Q1: Complete three labs fromPortSwigger Labs, one from SQL Injection, one from Cross-Site

Scripting, and one from Cross-Site Request Forgery section. Please select labs designated as PRAC-

TITIONER or EXPERT; APPRENTICE labs will not be accepted. You are permitted to utilize the

solutions and demonstrations available on the PortSwigger website for assistance. However, please

do not copy walkthroughs from the PortSwigger website. You will approach the labs as a penetration

tester, simulating a real-world scenario where you exploit each target as if you were doing it for the

first time. Your solution should include the logical steps that lead to the exploitation, which may not

be covered in the walkthroughs on the PortSwigger website.[60 Marks]

Record a video and write a report to answer the following questions for each lab. At the beginning

of each lab recording, please state your name, student ID, and the name of the lab you are solving;

no marks can be awarded without this information.

1. How did you identify the vulnerability? (5 Marks)

2. Which payload was chosen for exploitation and why? (5 Marks)

3. What an attacker could achieve using the vulnerability? (5 Marks)

4. How the vulnerability can be mitigated? (theoretically, no demonstration is required) (5 Marks)

The video submission must demonstrate solving the lab, addressing the questions outlined above. In

case time runs short during the video, you may use the report to address any unanswered questions,

making references to relevant sections of the video. However, it is important that the video includes,

at a minimum, a demonstration of the lab. The report does not need to be in detail, it should briefly

address the mentioned questions, i.e. it can contain one or two-line answer for each question, pay-

loads and important screenshots (if necessary). The marks mentioned above are for the videos and

report combined.The word limit for each sub-question is 200 words, i.e. maximum 800 words

are allowed for Q1 per lab.

2

Q2: Download theQ2.htmlfile from Moodle. Assume you are browsingmonash.edu, and

it is hypothetically vulnerable to various web attacks (although it is not).While navigating

monash.edu, assume you open another tab in the same browser, and visitattacker.com(as-

suming attacker convinced you to do that). You click theSubmitbutton on theattacker.com

webpage, which containsQ2.html, initiating attacks onmonash.edu. ExamineQ2.html(you

can open the file in the browser and intercept the request in BurpSuite if desired) and respond to the

following questions.No video is required for this question. The word limit for each sub-question

is 200 words, i.e. maximum 600 words are allowed for Q2. [20 Marks]

1. Which vulnerability/vulnerabilitiesattacker.comis trying to exploit onmonash.edu?

(please explain the scenario outlining how this exploitation could occur) (10 Marks)

2. If successful, what is the consequence of the attack(s)? (5 Marks)

3. What mitigation(s) would you suggest formonash.eduto counter attack(s) launched by

attacker.com? (5 Marks)

Note: The parameter values in the HTML file are URL encoded.

3

Q3: Assume you visitmonash.eduand it tries to talk tolms.monash.edu, the browser issues

an OPTIONS method tolms.monash.eduand gets a response, below is the HTTP request and

its response:

OPTIONS /doc HTTP/1.1

Host: lms.monash.edu

User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:71.0)

Accept: text/html,application/xhtml+xml,application/xml

Accept-Language: en-us,en;q=0.5

Accept-Encoding: gzip,deflate

Connection: keep-alive

Origin: monash.edu

Access-Control-Request-Method: POST

Access-Control-Request-Headers: x-requested-with

HTTP/1.1 204 No Content

Date: Mon, 01 Dec 2008 01:15:39 GMT

Server: Apache/2

Access-Control-Allow-Origin:

*

Access-Control-Allow-Methods: POST, GET, OPTIONS

Access-Control-Allow-Headers: x-requested-with

Access-Control-Allow-Credentials: true

Access-Control-Max-Age: 86400

Vary: Accept-Encoding, Origin

Keep-Alive: timeout=2, max=100

Connection: Keep-Alive

Explain the Cross-Origin Resource Sharing (CORS) HTTP headers in the above HTTP request and

response. Please avoid listing each header with an explanation; instead, gather the key information

and present it in a concise paragraph.

Would browser change future requests based on the above HTTP response?No video is required

for this question. The word limit for Q3 is 300 words. [10 Marks]

4 Report Completion and Quality of Presentation [10 Marks]

Marks are allocated to the quality and clarity of presentation in the report and the video.

請加QQ:99515681  郵箱:99515681@qq.com   WX:codinghelp


 

掃一掃在手機打開當前頁
  • 上一篇:代做 MATH2052編程、代寫 MATH2052設計程序
  • 下一篇:代做 EEB 504B、代寫 java/Python 程序
  • 無相關信息
    合肥生活資訊

    合肥圖文信息
    2025年10月份更新拼多多改銷助手小象助手多多出評軟件
    2025年10月份更新拼多多改銷助手小象助手多
    有限元分析 CAE仿真分析服務-企業/產品研發/客戶要求/設計優化
    有限元分析 CAE仿真分析服務-企業/產品研發
    急尋熱仿真分析?代做熱仿真服務+熱設計優化
    急尋熱仿真分析?代做熱仿真服務+熱設計優化
    出評 開團工具
    出評 開團工具
    挖掘機濾芯提升發動機性能
    挖掘機濾芯提升發動機性能
    海信羅馬假日洗衣機亮相AWE  復古美學與現代科技完美結合
    海信羅馬假日洗衣機亮相AWE 復古美學與現代
    合肥機場巴士4號線
    合肥機場巴士4號線
    合肥機場巴士3號線
    合肥機場巴士3號線
  • 短信驗證碼 trae 豆包網頁版入口 目錄網 排行網

    關于我們 | 打賞支持 | 廣告服務 | 聯系我們 | 網站地圖 | 免責聲明 | 幫助中心 | 友情鏈接 |

    Copyright © 2025 hfw.cc Inc. All Rights Reserved. 合肥網 版權所有
    ICP備06013414號-3 公安備 42010502001045

    99爱在线视频这里只有精品_窝窝午夜看片成人精品_日韩精品久久久毛片一区二区_亚洲一区二区久久

          9000px;">

                蜜桃视频一区二区三区在线观看 | 4438成人网| 中文字幕av免费专区久久| 久久免费偷拍视频| 麻豆国产欧美日韩综合精品二区| 成人综合在线观看| 亚洲国产岛国毛片在线| 日本美女一区二区三区视频| 91亚洲国产成人精品一区二区三| 国产婷婷色一区二区三区在线| 国产一区二区剧情av在线| 国产精品久久久久久久裸模| 欧美性猛片aaaaaaa做受| 麻豆精品视频在线| 亚洲视频在线一区| 2020国产精品| 欧美日韩精品电影| 不卡的av电影在线观看| 久久成人久久爱| 一区二区三区不卡视频在线观看| 精品国产一区二区三区久久影院| 色八戒一区二区三区| 国产一区二区三区四区五区入口| 亚洲美女在线国产| 日本一区二区成人在线| 精品三级在线看| 成人午夜免费av| 亚洲午夜免费电影| 亚洲欧洲国产日韩| 精品少妇一区二区三区日产乱码| 色就色 综合激情| 国产成人综合网站| 久久99精品一区二区三区三区| 国产精品国产自产拍高清av王其| 精品国内二区三区| 99国产精品久久久久久久久久| 精品国产伦一区二区三区观看体验 | 91网页版在线| 欧美日韩精品系列| 欧美大片拔萝卜| 国产精品视频九色porn| 日韩精品每日更新| 国产老女人精品毛片久久| 91视频国产观看| 日韩免费福利电影在线观看| 国产蜜臀av在线一区二区三区| 亚洲最大成人综合| 国产精品1区二区.| 91精品国产全国免费观看 | 亚洲国产一二三| 亚洲一区二区三区精品在线| 一区二区三区国产精华| 国产精品麻豆网站| 国产精品亲子伦对白| 久久久久久影视| 国产亚洲精品7777| 国产日韩精品一区二区浪潮av| 久久综合国产精品| 日韩免费性生活视频播放| 欧美一区二区三区视频免费 | 精品久久国产老人久久综合| 色婷婷av一区二区三区软件| 在线观看亚洲a| 在线观看日韩毛片| 欧美色男人天堂| 欧美嫩在线观看| 欧美精品三级在线观看| 日韩欧美国产系列| 2014亚洲片线观看视频免费| 中文字幕欧美日本乱码一线二线| 久久精品人人做人人综合| **欧美大码日韩| 一色屋精品亚洲香蕉网站| 亚洲午夜在线电影| 亚洲国产一区二区三区青草影视| 美女网站在线免费欧美精品| 久久精品国产999大香线蕉| 国产成人精品免费在线| 色婷婷久久久综合中文字幕| 欧美日韩日日骚| 精品国产电影一区二区| 18涩涩午夜精品.www| 亚洲国产精品一区二区久久| 蜜臀av性久久久久av蜜臀妖精| 国产成人免费xxxxxxxx| av不卡免费电影| 欧美三级中文字| 国产亚洲综合色| 亚洲午夜影视影院在线观看| 狠狠色狠狠色综合日日91app| 99久久精品国产一区| 成人午夜私人影院| 国产精品乱码妇女bbbb| 亚洲啪啪综合av一区二区三区| 午夜精品一区在线观看| 成人永久aaa| 精品1区2区3区| 亚洲欧美综合色| 免费国产亚洲视频| 91国在线观看| 国产精品污www在线观看| 亚洲成人免费视| 99免费精品在线观看| 久久免费电影网| 奇米精品一区二区三区在线观看| 色琪琪一区二区三区亚洲区| 久久久夜色精品亚洲| 蜜臀av一区二区在线免费观看| 欧美亚洲另类激情小说| 亚洲精品国产成人久久av盗摄| 国产麻豆视频一区| 精品国产三级a在线观看| 奇米精品一区二区三区在线观看 | 亚洲精品乱码久久久久久久久 | 亚洲美女视频在线| 丁香啪啪综合成人亚洲小说| 精品久久久久久久人人人人传媒| 午夜精品影院在线观看| 欧美视频精品在线| 午夜久久久久久电影| 欧美美女直播网站| 亚洲成a人片综合在线| 欧美在线观看你懂的| 亚洲国产精品影院| 91精品国模一区二区三区| 美国精品在线观看| 精品日韩成人av| 国产综合久久久久久鬼色| 久久婷婷国产综合精品青草| 国产盗摄精品一区二区三区在线| 国产亚洲精品精华液| 成人av在线电影| 一区二区三区四区精品在线视频| 欧洲一区二区三区在线| 午夜一区二区三区在线观看| 欧美日韩成人在线| 狠狠色狠狠色综合| 国产精品麻豆99久久久久久| 色综合欧美在线| 蜜桃视频在线一区| 亚洲国产成人在线| 在线观看国产日韩| 七七婷婷婷婷精品国产| 亚洲精品一区二区三区精华液| 国产不卡在线视频| 亚洲一线二线三线视频| 精品国产精品一区二区夜夜嗨| 不卡视频免费播放| 日本三级亚洲精品| 中文字幕制服丝袜成人av| 欧美日韩国产综合视频在线观看| 国产美女av一区二区三区| 亚洲精品少妇30p| 日韩欧美国产午夜精品| 99久久精品费精品国产一区二区| 视频一区中文字幕| 欧美国产一区视频在线观看| 欧美日韩亚洲国产综合| 国产乱码精品一品二品| 一区二区三区电影在线播| 精品福利在线导航| 欧美日韩精品一区二区| 成人一区二区三区| 六月丁香综合在线视频| 一区二区在线观看免费视频播放| 日韩视频一区二区| 欧美在线一区二区三区| 国产成人在线观看| 久久精品国产成人一区二区三区| 中文字幕视频一区二区三区久| 精品日韩av一区二区| 欧美精品黑人性xxxx| 日本高清成人免费播放| 精品系列免费在线观看| 亚洲图片一区二区| 国产偷v国产偷v亚洲高清| 日韩一二在线观看| 成人av资源站| 国产麻豆91精品| 日日夜夜一区二区| 国产精品久久国产精麻豆99网站| 日韩一区二区三区免费看 | 亚洲国产精品一区二区久久恐怖片| 日韩精品一区二区三区在线观看| 成人手机电影网| 国产一区二区影院| 国内精品久久久久影院一蜜桃| 最近日韩中文字幕| 久久久不卡网国产精品二区| 精品乱人伦小说| 日韩精品一区二区三区四区| 欧美视频精品在线| 91丨九色丨蝌蚪丨老版| 国产成人综合自拍| 国产一区二区三区美女| 91亚洲国产成人精品一区二三| 亚洲精品一区在线观看| 欧美放荡的少妇| 欧美精品久久天天躁| 欧美日韩成人在线|