99爱在线视频这里只有精品_窝窝午夜看片成人精品_日韩精品久久久毛片一区二区_亚洲一区二区久久

合肥生活安徽新聞合肥交通合肥房產生活服務合肥教育合肥招聘合肥旅游文化藝術合肥美食合肥地圖合肥社保合肥醫院企業服務合肥法律

代做 FIT3173、代寫 SQL 編程設計
代做 FIT3173、代寫 SQL 編程設計

時間:2025-05-05  來源:合肥網hfw.cc  作者:hfw.cc 我要糾錯



FIT3173 Software Security Assignment-2 (S1 2025)

Total Marks 100

Please see Moodle for the due date.

1 Overview

The primary learning objective of this assignment is to provide you with firsthand experience in exploiting

SQL Injection, Cross-site Scripting and Cross-site Request Forgery vulnerabilities. Additionally, it aims

to deepen your understanding of these vulnerabilities. This assessment does not require a specific virtual

machine (VM) and can be executed on any operating system. You can utilize the same setup as the Lab07

and Lab08.

2 Submission

For this assignment, you need to submit two files using a single submission link on Moodle:

? A PDF file with relevant screenshots, and

? a singlevideo filecontaining the recording of you carrying out all tasks.

Typeset your report into .pdf format (make sure it can be opened with Adobe Reader) and name it as the

format:[Your Name]-[Student ID]-FIT3173-Assignment.pdf.

All payloads, if required, should be embedded in your report. In addition, if a demonstration video is

required, you should record your screen demonstration with your voice explanation. You can use this free

tool to make the video:https://monash-panopto.aarnet.edu.au/ ; other tools, such as Zoom, are also fine.

Important notes and penalties:

? A part of the submitted video (at a corner) must clearly show your face at all times. Penalties may

apply when that’s not the case.

? Video demonstration should be a live exploitation of the vulnerabilities.

? Late submissions incur a 5-point deduction per day. For example, if you submit 2 days and 1 hour

late, that incurs 15-point deduction. Submissions more than 7 days late will receive a zero mark.

? If you require extension or special consideration, refer tohttps://www.monash.edu/students/

admin/assessments/extensions-special-consideration. No teaching team mem-

ber is allowed to give you extension or special consideration, so please do not reach out to a teaching

team member about this. Follow the guidelines in the aforementioned link.

? The maximum allowed duration for the recorded video is 15 mins in total. Therefore, only the first

15:00 mins of your submitted video will be marked. Any exceeding video components will be ignored.

? If your device does not have a camera (or for whatever reason you can’t use your device), you can

borrow a device from Monash Connect or Library. It’s your responsibility to plan ahead for this.

Monash Connect or Library not having available devices for loan at a particular point in time is not a

valid excuse.

? You can create multiple video parts at different times, and combine and submit a single video at the

end. Make sure that the final video is clear and understandable.

1

? You can do (online) research in advance, take notes and make use of them during your video recording.

You may also prepare exploit scripts in advance. But you cannot simply copy-paste commands to carry

out the tasks without any explanations. Explanations (of what the code does) while completing the

tasks are particularly important.

? Zero tolerance on plagiarism and academic integrity violations: If you are found cheating, penalties

will apply, e.g., a zero grade for the unit. The demonstration video is also used to detect/avoid plagia-

rism. University policies can be found athttps://www.monash.edu/students/academic/

policies/academic-integrity.

3 Web Application Vulnerabilities

Q1: Complete three labs fromPortSwigger Labs, one from SQL Injection, one from Cross-Site

Scripting, and one from Cross-Site Request Forgery section. Please select labs designated as PRAC-

TITIONER or EXPERT; APPRENTICE labs will not be accepted. You are permitted to utilize the

solutions and demonstrations available on the PortSwigger website for assistance. However, please

do not copy walkthroughs from the PortSwigger website. You will approach the labs as a penetration

tester, simulating a real-world scenario where you exploit each target as if you were doing it for the

first time. Your solution should include the logical steps that lead to the exploitation, which may not

be covered in the walkthroughs on the PortSwigger website.[60 Marks]

Record a video and write a report to answer the following questions for each lab. At the beginning

of each lab recording, please state your name, student ID, and the name of the lab you are solving;

no marks can be awarded without this information.

1. How did you identify the vulnerability? (5 Marks)

2. Which payload was chosen for exploitation and why? (5 Marks)

3. What an attacker could achieve using the vulnerability? (5 Marks)

4. How the vulnerability can be mitigated? (theoretically, no demonstration is required) (5 Marks)

The video submission must demonstrate solving the lab, addressing the questions outlined above. In

case time runs short during the video, you may use the report to address any unanswered questions,

making references to relevant sections of the video. However, it is important that the video includes,

at a minimum, a demonstration of the lab. The report does not need to be in detail, it should briefly

address the mentioned questions, i.e. it can contain one or two-line answer for each question, pay-

loads and important screenshots (if necessary). The marks mentioned above are for the videos and

report combined.The word limit for each sub-question is 200 words, i.e. maximum 800 words

are allowed for Q1 per lab.

2

Q2: Download theQ2.htmlfile from Moodle. Assume you are browsingmonash.edu, and

it is hypothetically vulnerable to various web attacks (although it is not).While navigating

monash.edu, assume you open another tab in the same browser, and visitattacker.com(as-

suming attacker convinced you to do that). You click theSubmitbutton on theattacker.com

webpage, which containsQ2.html, initiating attacks onmonash.edu. ExamineQ2.html(you

can open the file in the browser and intercept the request in BurpSuite if desired) and respond to the

following questions.No video is required for this question. The word limit for each sub-question

is 200 words, i.e. maximum 600 words are allowed for Q2. [20 Marks]

1. Which vulnerability/vulnerabilitiesattacker.comis trying to exploit onmonash.edu?

(please explain the scenario outlining how this exploitation could occur) (10 Marks)

2. If successful, what is the consequence of the attack(s)? (5 Marks)

3. What mitigation(s) would you suggest formonash.eduto counter attack(s) launched by

attacker.com? (5 Marks)

Note: The parameter values in the HTML file are URL encoded.

3

Q3: Assume you visitmonash.eduand it tries to talk tolms.monash.edu, the browser issues

an OPTIONS method tolms.monash.eduand gets a response, below is the HTTP request and

its response:

OPTIONS /doc HTTP/1.1

Host: lms.monash.edu

User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:71.0)

Accept: text/html,application/xhtml+xml,application/xml

Accept-Language: en-us,en;q=0.5

Accept-Encoding: gzip,deflate

Connection: keep-alive

Origin: monash.edu

Access-Control-Request-Method: POST

Access-Control-Request-Headers: x-requested-with

HTTP/1.1 204 No Content

Date: Mon, 01 Dec 2008 01:15:39 GMT

Server: Apache/2

Access-Control-Allow-Origin:

*

Access-Control-Allow-Methods: POST, GET, OPTIONS

Access-Control-Allow-Headers: x-requested-with

Access-Control-Allow-Credentials: true

Access-Control-Max-Age: 86400

Vary: Accept-Encoding, Origin

Keep-Alive: timeout=2, max=100

Connection: Keep-Alive

Explain the Cross-Origin Resource Sharing (CORS) HTTP headers in the above HTTP request and

response. Please avoid listing each header with an explanation; instead, gather the key information

and present it in a concise paragraph.

Would browser change future requests based on the above HTTP response?No video is required

for this question. The word limit for Q3 is 300 words. [10 Marks]

4 Report Completion and Quality of Presentation [10 Marks]

Marks are allocated to the quality and clarity of presentation in the report and the video.

請加QQ:99515681  郵箱:99515681@qq.com   WX:codinghelp


 

掃一掃在手機打開當前頁
  • 上一篇:代做 MATH2052編程、代寫 MATH2052設計程序
  • 下一篇:代做 EEB 504B、代寫 java/Python 程序
  • 無相關信息
    合肥生活資訊

    合肥圖文信息
    2025年10月份更新拼多多改銷助手小象助手多多出評軟件
    2025年10月份更新拼多多改銷助手小象助手多
    有限元分析 CAE仿真分析服務-企業/產品研發/客戶要求/設計優化
    有限元分析 CAE仿真分析服務-企業/產品研發
    急尋熱仿真分析?代做熱仿真服務+熱設計優化
    急尋熱仿真分析?代做熱仿真服務+熱設計優化
    出評 開團工具
    出評 開團工具
    挖掘機濾芯提升發動機性能
    挖掘機濾芯提升發動機性能
    海信羅馬假日洗衣機亮相AWE  復古美學與現代科技完美結合
    海信羅馬假日洗衣機亮相AWE 復古美學與現代
    合肥機場巴士4號線
    合肥機場巴士4號線
    合肥機場巴士3號線
    合肥機場巴士3號線
  • 短信驗證碼 trae 豆包網頁版入口 目錄網 排行網

    關于我們 | 打賞支持 | 廣告服務 | 聯系我們 | 網站地圖 | 免責聲明 | 幫助中心 | 友情鏈接 |

    Copyright © 2025 hfw.cc Inc. All Rights Reserved. 合肥網 版權所有
    ICP備06013414號-3 公安備 42010502001045

    99爱在线视频这里只有精品_窝窝午夜看片成人精品_日韩精品久久久毛片一区二区_亚洲一区二区久久

          9000px;">

                亚洲午夜久久久久中文字幕久| 亚洲欧洲三级电影| 粉嫩aⅴ一区二区三区四区| 欧美私模裸体表演在线观看| 国产精品三级久久久久三级| 亚洲精品乱码久久久久| 在线视频欧美区| 亚洲制服欧美中文字幕中文字幕| 成人免费毛片a| 1区2区3区精品视频| 91麻豆精品国产91| 日本在线不卡一区| 久久一区二区三区国产精品| 国产一区二区三区电影在线观看 | 免费三级欧美电影| 欧美图片一区二区三区| 亚洲一区二区三区不卡国产欧美 | 色婷婷精品久久二区二区蜜臀av | 狠狠狠色丁香婷婷综合久久五月| 欧美大度的电影原声| 国产麻豆日韩欧美久久| 精品国偷自产国产一区| 成人v精品蜜桃久久一区| 一区二区在线免费| 91精品在线免费观看| 成人免费视频视频| 亚洲精品日日夜夜| 国产婷婷色一区二区三区 | 精品日韩欧美在线| 一本色道久久综合亚洲91| 精品午夜久久福利影院| 午夜精品久久久久| 日韩理论在线观看| 久久久国产一区二区三区四区小说 | 成人毛片老司机大片| 日韩国产在线一| 亚洲免费在线观看| 国产精品久久久久7777按摩 | 亚洲色欲色欲www在线观看| 国产视频一区二区在线| 亚洲欧美日韩精品久久久久| 久久久久97国产精华液好用吗| 欧美日韩激情在线| 91免费观看在线| 成人av免费网站| 成人免费毛片a| 精品亚洲成a人在线观看| 午夜精品爽啪视频| 亚洲成人777| 午夜精品一区二区三区三上悠亚| 亚洲精品国产一区二区精华液| 国产精品视频一二三| 盗摄精品av一区二区三区| 九九国产精品视频| 国产精品综合视频| 国内精品自线一区二区三区视频| 久久国产剧场电影| 久久精品国产精品亚洲红杏| 精品一区二区三区久久| 免费日韩伦理电影| 国产一区在线观看视频| 国精产品一区一区三区mba桃花 | 色综合天天狠狠| 91黄视频在线| 欧美日精品一区视频| 欧美精品色一区二区三区| 欧美日韩成人在线一区| 欧美日韩一级片在线观看| 欧美在线制服丝袜| 欧美性猛片aaaaaaa做受| 欧美精品乱码久久久久久| 欧美一区二区日韩| 国产午夜精品久久久久久久| 亚洲天堂a在线| 日本在线不卡一区| 国产成人av一区二区三区在线| 97se亚洲国产综合自在线不卡| 欧洲一区在线电影| 69久久夜色精品国产69蝌蚪网| 欧美成人精品高清在线播放 | 中文字幕一区日韩精品欧美| 亚洲va欧美va人人爽午夜| 久久成人羞羞网站| av亚洲精华国产精华精| 欧美一级国产精品| 亚洲天堂福利av| 久久99这里只有精品| 一本一道久久a久久精品综合蜜臀| 欧美一a一片一级一片| 精品国产乱码久久久久久久久| 中文字幕高清不卡| 日韩国产在线观看| 久久丁香综合五月国产三级网站| 色狠狠一区二区| 91麻豆精品国产91久久久久久| 久久五月婷婷丁香社区| 午夜在线成人av| 极品少妇xxxx精品少妇| 国产成人免费视频一区| 在线区一区二视频| 日韩欧美国产一区二区三区| 国产精品美女久久久久久久久| 国内精品在线播放| 欧美日韩中文字幕精品| 精品福利一区二区三区| 综合中文字幕亚洲| 日产精品久久久久久久性色| 成人一级片在线观看| 欧美韩国日本不卡| 日本不卡一区二区三区| 91影院在线免费观看| 日韩精品一区在线观看| 亚洲精品欧美在线| 亚洲国产综合在线| 欧美日韩国产一二三| 中文字幕精品综合| 精品伊人久久久久7777人| 91成人免费在线视频| 国产欧美精品在线观看| 亚洲日本在线观看| 91免费观看在线| 国产日韩欧美麻豆| 蜜桃视频免费观看一区| 色94色欧美sute亚洲线路一久| 久久久久青草大香线综合精品| 国产一区999| 日韩一级高清毛片| 亚洲第一成年网| 91浏览器入口在线观看| 国产精品免费久久久久| 久久99精品久久久久久动态图 | 日韩精品一区二区三区四区| 夜夜揉揉日日人人青青一国产精品| 国产主播一区二区三区| 日韩免费一区二区三区在线播放| 91成人在线观看喷潮| 五月激情六月综合| 欧美精品欧美精品系列| 亚洲gay无套男同| 欧美日韩欧美一区二区| 国产亚洲欧美中文| 在线一区二区视频| 亚洲久草在线视频| 色偷偷成人一区二区三区91| 欧美国产精品专区| 高清国产午夜精品久久久久久| 国产精品国产三级国产aⅴ中文 | 亚洲男女毛片无遮挡| 成人精品电影在线观看| 亚洲一区二区三区小说| 色综合久久综合网97色综合| 成人免费在线视频观看| 一本到不卡精品视频在线观看| 中文字幕一区二区三区在线播放| 99精品欧美一区| 一区二区免费视频| 欧美色图片你懂的| 丝袜美腿成人在线| 国产精品久久久久久久第一福利| 高清不卡在线观看av| 综合欧美一区二区三区| 欧美性大战xxxxx久久久| 日韩精品免费视频人成| 久久综合九色综合欧美就去吻| 色视频一区二区| 无吗不卡中文字幕| 久久精品一区二区三区不卡 | 欧美一区二区三区日韩| 麻豆国产91在线播放| 亚洲精选在线视频| 欧美一区二区三区不卡| 国产超碰在线一区| 亚洲伊人色欲综合网| 日韩免费视频一区| 久久精品国产亚洲一区二区三区| 亚洲午夜久久久久久久久电影网 | 91精品在线一区二区| 972aa.com艺术欧美| 蜜桃视频在线观看一区| 亚洲色图在线视频| 日韩一二三区不卡| 95精品视频在线| 成人app在线观看| 日本系列欧美系列| 亚洲三级视频在线观看| 日韩欧美一区二区不卡| 亚洲精品大片www| 成人欧美一区二区三区1314| 日韩一本二本av| 在线亚洲人成电影网站色www| 麻豆久久久久久久| 国产日韩欧美综合一区| 国产亚洲欧美激情| 91精品国产综合久久久蜜臀图片| 99久久伊人精品| 国产精品996| 亚洲精品亚洲人成人网| 亚洲一区二区三区免费视频| 国产欧美一区二区精品性| 日韩无一区二区|