国产人妻人伦精品_欧美一区二区三区图_亚洲欧洲久久_日韩美女av在线免费观看

合肥生活安徽新聞合肥交通合肥房產生活服務合肥教育合肥招聘合肥旅游文化藝術合肥美食合肥地圖合肥社保合肥醫院企業服務合肥法律

代做 FIT3173、代寫 SQL 編程設計
代做 FIT3173、代寫 SQL 編程設計

時間:2025-05-05  來源:合肥網hfw.cc  作者:hfw.cc 我要糾錯



FIT3173 Software Security Assignment-2 (S1 2025)

Total Marks 100

Please see Moodle for the due date.

1 Overview

The primary learning objective of this assignment is to provide you with firsthand experience in exploiting

SQL Injection, Cross-site Scripting and Cross-site Request Forgery vulnerabilities. Additionally, it aims

to deepen your understanding of these vulnerabilities. This assessment does not require a specific virtual

machine (VM) and can be executed on any operating system. You can utilize the same setup as the Lab07

and Lab08.

2 Submission

For this assignment, you need to submit two files using a single submission link on Moodle:

? A PDF file with relevant screenshots, and

? a singlevideo filecontaining the recording of you carrying out all tasks.

Typeset your report into .pdf format (make sure it can be opened with Adobe Reader) and name it as the

format:[Your Name]-[Student ID]-FIT3173-Assignment.pdf.

All payloads, if required, should be embedded in your report. In addition, if a demonstration video is

required, you should record your screen demonstration with your voice explanation. You can use this free

tool to make the video:https://monash-panopto.aarnet.edu.au/ ; other tools, such as Zoom, are also fine.

Important notes and penalties:

? A part of the submitted video (at a corner) must clearly show your face at all times. Penalties may

apply when that’s not the case.

? Video demonstration should be a live exploitation of the vulnerabilities.

? Late submissions incur a 5-point deduction per day. For example, if you submit 2 days and 1 hour

late, that incurs 15-point deduction. Submissions more than 7 days late will receive a zero mark.

? If you require extension or special consideration, refer tohttps://www.monash.edu/students/

admin/assessments/extensions-special-consideration. No teaching team mem-

ber is allowed to give you extension or special consideration, so please do not reach out to a teaching

team member about this. Follow the guidelines in the aforementioned link.

? The maximum allowed duration for the recorded video is 15 mins in total. Therefore, only the first

15:00 mins of your submitted video will be marked. Any exceeding video components will be ignored.

? If your device does not have a camera (or for whatever reason you can’t use your device), you can

borrow a device from Monash Connect or Library. It’s your responsibility to plan ahead for this.

Monash Connect or Library not having available devices for loan at a particular point in time is not a

valid excuse.

? You can create multiple video parts at different times, and combine and submit a single video at the

end. Make sure that the final video is clear and understandable.

1

? You can do (online) research in advance, take notes and make use of them during your video recording.

You may also prepare exploit scripts in advance. But you cannot simply copy-paste commands to carry

out the tasks without any explanations. Explanations (of what the code does) while completing the

tasks are particularly important.

? Zero tolerance on plagiarism and academic integrity violations: If you are found cheating, penalties

will apply, e.g., a zero grade for the unit. The demonstration video is also used to detect/avoid plagia-

rism. University policies can be found athttps://www.monash.edu/students/academic/

policies/academic-integrity.

3 Web Application Vulnerabilities

Q1: Complete three labs fromPortSwigger Labs, one from SQL Injection, one from Cross-Site

Scripting, and one from Cross-Site Request Forgery section. Please select labs designated as PRAC-

TITIONER or EXPERT; APPRENTICE labs will not be accepted. You are permitted to utilize the

solutions and demonstrations available on the PortSwigger website for assistance. However, please

do not copy walkthroughs from the PortSwigger website. You will approach the labs as a penetration

tester, simulating a real-world scenario where you exploit each target as if you were doing it for the

first time. Your solution should include the logical steps that lead to the exploitation, which may not

be covered in the walkthroughs on the PortSwigger website.[60 Marks]

Record a video and write a report to answer the following questions for each lab. At the beginning

of each lab recording, please state your name, student ID, and the name of the lab you are solving;

no marks can be awarded without this information.

1. How did you identify the vulnerability? (5 Marks)

2. Which payload was chosen for exploitation and why? (5 Marks)

3. What an attacker could achieve using the vulnerability? (5 Marks)

4. How the vulnerability can be mitigated? (theoretically, no demonstration is required) (5 Marks)

The video submission must demonstrate solving the lab, addressing the questions outlined above. In

case time runs short during the video, you may use the report to address any unanswered questions,

making references to relevant sections of the video. However, it is important that the video includes,

at a minimum, a demonstration of the lab. The report does not need to be in detail, it should briefly

address the mentioned questions, i.e. it can contain one or two-line answer for each question, pay-

loads and important screenshots (if necessary). The marks mentioned above are for the videos and

report combined.The word limit for each sub-question is 200 words, i.e. maximum 800 words

are allowed for Q1 per lab.

2

Q2: Download theQ2.htmlfile from Moodle. Assume you are browsingmonash.edu, and

it is hypothetically vulnerable to various web attacks (although it is not).While navigating

monash.edu, assume you open another tab in the same browser, and visitattacker.com(as-

suming attacker convinced you to do that). You click theSubmitbutton on theattacker.com

webpage, which containsQ2.html, initiating attacks onmonash.edu. ExamineQ2.html(you

can open the file in the browser and intercept the request in BurpSuite if desired) and respond to the

following questions.No video is required for this question. The word limit for each sub-question

is 200 words, i.e. maximum 600 words are allowed for Q2. [20 Marks]

1. Which vulnerability/vulnerabilitiesattacker.comis trying to exploit onmonash.edu?

(please explain the scenario outlining how this exploitation could occur) (10 Marks)

2. If successful, what is the consequence of the attack(s)? (5 Marks)

3. What mitigation(s) would you suggest formonash.eduto counter attack(s) launched by

attacker.com? (5 Marks)

Note: The parameter values in the HTML file are URL encoded.

3

Q3: Assume you visitmonash.eduand it tries to talk tolms.monash.edu, the browser issues

an OPTIONS method tolms.monash.eduand gets a response, below is the HTTP request and

its response:

OPTIONS /doc HTTP/1.1

Host: lms.monash.edu

User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:71.0)

Accept: text/html,application/xhtml+xml,application/xml

Accept-Language: en-us,en;q=0.5

Accept-Encoding: gzip,deflate

Connection: keep-alive

Origin: monash.edu

Access-Control-Request-Method: POST

Access-Control-Request-Headers: x-requested-with

HTTP/1.1 204 No Content

Date: Mon, 01 Dec 2008 01:15:39 GMT

Server: Apache/2

Access-Control-Allow-Origin:

*

Access-Control-Allow-Methods: POST, GET, OPTIONS

Access-Control-Allow-Headers: x-requested-with

Access-Control-Allow-Credentials: true

Access-Control-Max-Age: 86400

Vary: Accept-Encoding, Origin

Keep-Alive: timeout=2, max=100

Connection: Keep-Alive

Explain the Cross-Origin Resource Sharing (CORS) HTTP headers in the above HTTP request and

response. Please avoid listing each header with an explanation; instead, gather the key information

and present it in a concise paragraph.

Would browser change future requests based on the above HTTP response?No video is required

for this question. The word limit for Q3 is 300 words. [10 Marks]

4 Report Completion and Quality of Presentation [10 Marks]

Marks are allocated to the quality and clarity of presentation in the report and the video.

請加QQ:99515681  郵箱:99515681@qq.com   WX:codinghelp


 

掃一掃在手機打開當前頁
  • 上一篇:代做 MATH2052編程、代寫 MATH2052設計程序
  • 下一篇:代做 EEB 504B、代寫 java/Python 程序
  • 無相關信息
    合肥生活資訊

    合肥圖文信息
    流體仿真外包多少錢_專業CFD分析代做_友商科技CAE仿真
    流體仿真外包多少錢_專業CFD分析代做_友商科
    CAE仿真分析代做公司 CFD流體仿真服務 管路流場仿真外包
    CAE仿真分析代做公司 CFD流體仿真服務 管路
    流體CFD仿真分析_代做咨詢服務_Fluent 仿真技術服務
    流體CFD仿真分析_代做咨詢服務_Fluent 仿真
    結構仿真分析服務_CAE代做咨詢外包_剛強度疲勞振動
    結構仿真分析服務_CAE代做咨詢外包_剛強度疲
    流體cfd仿真分析服務 7類仿真分析代做服務40個行業
    流體cfd仿真分析服務 7類仿真分析代做服務4
    超全面的拼多多電商運營技巧,多多開團助手,多多出評軟件徽y1698861
    超全面的拼多多電商運營技巧,多多開團助手
    CAE有限元仿真分析團隊,2026仿真代做咨詢服務平臺
    CAE有限元仿真分析團隊,2026仿真代做咨詢服
    釘釘簽到打卡位置修改神器,2026怎么修改定位在范圍內
    釘釘簽到打卡位置修改神器,2026怎么修改定
  • 短信驗證碼 寵物飼養 十大衛浴品牌排行 suno 豆包網頁版入口 目錄網 排行網

    關于我們 | 打賞支持 | 廣告服務 | 聯系我們 | 網站地圖 | 免責聲明 | 幫助中心 | 友情鏈接 |

    Copyright © 2025 hfw.cc Inc. All Rights Reserved. 合肥網 版權所有
    ICP備06013414號-3 公安備 42010502001045

    国产人妻人伦精品_欧美一区二区三区图_亚洲欧洲久久_日韩美女av在线免费观看
    美女啪啪无遮挡免费久久网站| 国产精品国产三级国产专播精品人| 国产精品久久久久久久7电影 | 熟妇人妻va精品中文字幕| 久久久久北条麻妃免费看| 国产福利久久| 久久国产精品久久精品国产| 91禁国产网站| 超碰免费在线公开| 欧美专区在线播放| 日本精品免费一区二区三区| 视频一区在线免费观看| 亚洲国产精品女人| 亚洲一区二区三区午夜| 国产精品激情av电影在线观看| www.日韩视频| 少妇精69xxtheporn| 国产高清免费在线| 深夜福利一区二区| 国产精品99一区| 91国产美女视频| 久久精品五月婷婷| 国产精品99蜜臀久久不卡二区| 久久久久久一区| 午夜一区二区三区| 日本精品一区二区三区四区| 欧洲精品亚洲精品| 国产欧美高清在线| 久久久亚洲精选| 久久精品国产综合精品| www.欧美精品一二三区| 欧美成人第一页| 日韩avxxx| 国产亚洲一区二区三区在线播放| 成人av网站观看| 久久人妻无码一区二区| 国产精品免费一区| 亚洲乱码一区二区三区三上悠亚| 日韩经典在线视频| 国产噜噜噜噜久久久久久久久| 国产成人一区二| 欧美成人在线影院| 热re99久久精品国99热蜜月 | 一级日韩一区在线观看| 日本中文字幕成人| 国产深夜精品福利| 国产成人午夜视频网址| 一区二区免费电影| 裸模一区二区三区免费| 国产成人精品av在线| 九九综合九九综合| 激情网站五月天| 久久久久久久久中文字幕| 亚洲一区二区三区乱码aⅴ蜜桃女| 免费在线观看日韩视频| 69av在线播放| 中文字幕av久久| 国产中文字幕免费观看| 国产国语videosex另类| 久久国产精品久久久久久久久久| 日韩欧美一区二区视频在线播放| www.久久草| 欧美精品在线免费观看| 欧美综合国产精品久久丁香| 91精品国产高清久久久久久91 | 国产精品久久久久久久久久ktv | 日韩一二区视频| av观看久久| 美女久久久久久久| 国内精品美女av在线播放| 久久久久久网站| 日本欧洲国产一区二区| 久久久欧美精品| 午夜啪啪福利视频| 国产精品av免费| 亚洲欧洲国产日韩精品| 国产日韩亚洲欧美| 久久av资源网站| 国产视频一区二区三区四区| 国产精品国产亚洲伊人久久| 欧美二区三区在线| 日韩网站免费观看| 欧美中文在线观看国产| 色婷婷av一区二区三区在线观看 | 日本10禁啪啪无遮挡免费一区二区 | 性一交一乱一伧国产女士spa| 国产欧美日韩免费看aⅴ视频| 国产精品美女黄网| 美女一区视频| 欧美成人精品三级在线观看| 国产欧美中文字幕| 久久久久久国产| 91精品国产综合久久香蕉最新版| 精品国产一区二区三区四区精华| 国产综合色香蕉精品| 精品免费二区三区三区高中清不卡| 欧美 日韩 国产 高清| 久久精品在线播放| 国内自拍在线观看| 久久亚洲国产成人| 成人国产精品久久久久久亚洲| 亚洲欧洲日韩精品| 久久精品国产sm调教网站演员| 日韩美女在线观看一区| 国产精品久久久久久久一区探花 | 99国精产品一二二线| 亚洲最大激情中文字幕| 91精品国产综合久久久久久丝袜| 日韩在线第一区| 日韩在线视频线视频免费网站| 欧美亚洲免费高清在线观看| 国产精品美女在线| 国产麻豆日韩| 性欧美在线看片a免费观看| 久久黄色免费看| 麻豆一区区三区四区产品精品蜜桃| 久久99精品国产99久久6尤物 | 国产日韩欧美自拍| 中文字幕日韩精品久久| 91精品91久久久久久| 日韩视频专区| 久久夜色精品亚洲噜噜国产mv| 波多野结衣精品久久| 日本一区二区在线视频| 国产精品美女av| 91九色在线视频| 男人的天堂狠狠干| 午夜精品久久久久久久久久久久久| 日韩在线欧美在线| 国产免费一区二区三区四在线播放 | 国产成人一区二区三区小说| 欧美视频在线观看视频| 久久99热这里只有精品国产| 国产成人精品久久二区二区91| 美媛馆国产精品一区二区| 亚洲在线欧美| 精品久久久91| 97精品免费视频| 国产综合免费视频| 日韩福利一区二区三区| 免费91麻豆精品国产自产在线观看 | 91精品国产九九九久久久亚洲 | 久久久久久久久久久成人| 国产日韩一区二区三区| 日本高清视频一区| 一区二区在线观| 国产精品入口夜色视频大尺度| 久久久亚洲精品无码| 国产又黄又大又粗视频| 天堂v在线视频| 欧美成人免费一级人片100| 国产mv久久久| 国产精品一区二区电影| 欧美日韩国产一二| 日韩av高清| 亚州av一区二区| 一区不卡字幕| 国产精品成人播放| 久久久久久久中文| 久久久欧美精品| www.国产二区| 国产在线视频91| 欧美日韩一区在线视频| 日本精品va在线观看| 亚洲欧洲精品在线| 一区二区三区在线视频看| 久久夜色精品国产欧美乱| 九色91视频| 欧美极品欧美精品欧美图片| 日本一区免费在线观看| 亚洲国产激情一区二区三区| 欧美激情a在线| 精品国产乱码久久久久| 国产精品久久久久久av福利软件 | 国产精品极品美女在线观看免费| 久久www视频| 久久精品日韩| 国产高清在线一区二区| 777午夜精品福利在线观看| 国产欧美精品一区二区三区| 女同一区二区| 欧美成人一区二区在线| 欧美日韩国产高清视频| 日韩久久不卡| 日本一区二区黄色| 日产精品高清视频免费| 午夜精品久久久久久99热软件| 亚洲图片在线观看| 亚洲综合中文字幕在线观看| 中文字幕日本最新乱码视频| 欧美激情xxxxx| 亚洲一区久久久| 午夜视频久久久| 日韩一二区视频| 欧美日韩大片一区二区三区| 日韩欧美一区二区三区久久婷婷| 亚洲va韩国va欧美va精四季| 色综合久久av| 欧美性大战久久久久| 男人舔女人下面高潮视频|