CTEC3410 Web Application Penetration Testing

CTEC3410 Web Application Penetration Testing
Penetration Test Coursework Specification
Web Application Penetration Testing
Please read all sections of this specification carefully before starting to work.


You may work on the pentest coursework in pairs. You must make it clear in your report who your partner is. I will assume that each partner has contributed equally unless you tell me otherwise. Include a brief appendix that describes how the work was divided. After reading this coursework specification, I strongly suggest you make yourself a check-list of the submission requirements.

Learning outcomes
On successful completion of this module the student will be able to:
1 Understand penetration testing strategies and methodologies
2 Implement penetration testing methodologies to perform a penetration test
3 Explain the role and importance of a scoping document
4 Craft a suitable technical report outlining discovered problems and suggest mitigation

Objectives
• Write a scoping document outlining what can and cannot be tested in the pentest. Include all information that is relevant.
• Analyse the given web application (via URL/port 80/port 443) for vulnerabilities.
• Produce a report describing and analysing the processes you used, the vulnerabilities you found and the exploits you used.
• Produce an executive summary summarising your findings.

Background
You have been approached by a nascent e-commerce business (BozBits PLC) who have had a web application created to support and facilitate their business. However, the business’ management has become suspicious of the quality of the application produced by a web development bureau, and have approached you, as a pentesting consultant, to conduct a web application penetration test. The business has no expertise in webtech and the CEO is technically illiterate.

Requirements

You will prepare, for signing, a scoping contract document, covering the above requirements (any other requirements you identify are for you to create).

You will then plan, execute and document a penetration test of the given web application, following a formal methodology. Which methodology you choose is up to you, but you must give a brief rationale as to why you have selected it. The report will also include details of both successful and unsuccessful tests. There should be sufficient detail for another tester to reproduce your findings.

CTEC3410 Web Application Penetration Testing Penetration Test Coursework Specification

Finally, you have to prepare an Executive Summary of your findings and the implications to the business, remembering that the target reader, the CEO, is not technically capable. Please note that the coursework is to assess your abilities in finding and documenting vulnerabilities using only port 80 and or port 443, ie via web-page forms or the address box. Platform You will need to download a compressed file (ctec3410_victim.vmware.zip) from the Lecturer drive – ie the same directory from which you downloaded the lab virtual machine. The compressed file contains a Virtual Machine which implements a complete operating system hosting a web-application accessible via a browser on port 80. You will need VM Player (or VM Workstation) to run the Virtual Machine containing the web-application. VM
Player is available to download from:
 http://downloads.vmware.com/d/info/desktop_end_user_computing/vmware_player/4_0
 https://vmware.dmu.ac.uk/

Sections
The workflow is divided into three main sections:
Process 1 – Planning
To aid in planning for the pentest, you will need to start by creating a scoping contract document that defines the shape and process of the pentest. This needs to briefly summarise the extent and limitations of the pentest. Remember that this is a legal document that gives you permission to perform the test. You will also need to select a pentest methodology. Process 2 – Implementation Your investigation may or may not discover any problems with the web-site. However, you must ensure that you have thoroughly documented all processes used in your investigations.
Process 3 – Reporting You have to submit (via Turnitin) a single PDF file containing three documents:

Scoping Contract
• Legal document outlining the expectations and limitations of the pentest. This should contain clauses that include all of the details discussed, and should be a maximum of 600 words.

Technical Report
• Brief rationale of the chosen methodology.
• The report of the implementation stage comprising:
 discussion of the processes undertaken to complete the investigation
 brief descriptions of the tools used and the commands implemented
©cfi/dmu 2
ctec3410_wapt_2021-2022_coursework-specification
CTEC3410 Web Application Penetration Testing
Penetration Test Coursework Specification
 discussion of the vulnerabilities discovered
 explanation as to how the vulnerabilities were exploited
• The technical report should be a maximum of 3000 words
 not including appendices.
 NB extra details can be included as appendices.

Executive Summary
• a brief summary of the vulnerabilities you uncovered and recommendations for mitigation, together with likely cost areas and times, couched in non-technical terms, suitable for a busy MD or CEO who is technically illiterate. This summary should be a maximum of 400 words. Submission
You have to submit the three documents as a single PDF file via the Turnitin link. Each document should be standalone, ie there can be no cross referencing between the documents. You must display the word count for each on the cover page.
• Document 1: Scoping Contract – maximum 600 words
• Document 2: Technical Report – maximum 3000 words
• Document 3: Executive Summary – maximum 400 words
The Technical Report document will include (as a minimum) an introduction, summary and reference/bibliography. Ensure all imported/referenced material is correctly cross-referenced with a recognised methodology. Diagrams/screenshots should also be labelled and
referenced. See the Coursework Specification Coversheet document for date and time of submission.

Notes
• Read this specification in conjunction with the marking scheme, available as a
separate document.
• Always attempt to implement exploits against any vulnerability you discover.
• Make copious notes of everything that you do. It will make writing the report easier.
You should include these notes as an appendix to your report document.
• Take screenshots as you progress. Use these to illustrate your report.
• Credit will only be given for exploits accessed via ports 80 and/or 443.
• If you work as a pair, only one of you needs to submit a the report.
◦ However, you must make it very clear with whom you completed the work.
NB There is an assumption that each partner has contributed equally. If this is not the case,
please include an appendix to your report detailing who has done what.
After reading this coursework specification, I strongly suggest you make yourself a checklist of the submission requirements.
©cfi/dmu 3
ctec3410_wapt_2021-2022_coursework-specification

Order Now

Get expert help for CTEC3410 Web Application Penetration Testing Assignment and many more. 100% safe, Plag free, Order Online Now!

No Fields Found.
Universal Assignment (March 2, 2026) CTEC3410 Web Application Penetration Testing. Retrieved from https://universalassignment.com/ctec3410-web-application-penetration-testing/.
"CTEC3410 Web Application Penetration Testing." Universal Assignment - March 2, 2026, https://universalassignment.com/ctec3410-web-application-penetration-testing/
Universal Assignment July 9, 2022 CTEC3410 Web Application Penetration Testing., viewed March 2, 2026,<https://universalassignment.com/ctec3410-web-application-penetration-testing/>
Universal Assignment - CTEC3410 Web Application Penetration Testing. [Internet]. [Accessed March 2, 2026]. Available from: https://universalassignment.com/ctec3410-web-application-penetration-testing/
"CTEC3410 Web Application Penetration Testing." Universal Assignment - Accessed March 2, 2026. https://universalassignment.com/ctec3410-web-application-penetration-testing/
"CTEC3410 Web Application Penetration Testing." Universal Assignment [Online]. Available: https://universalassignment.com/ctec3410-web-application-penetration-testing/. [Accessed: March 2, 2026]

Please note along with our service, we will provide you with the following deliverables:

Please do not hesitate to put forward any queries regarding the service provision.

We look forward to having you on board with us.

Most Frequent Questions & Answers

Universal Assignment Services is the best place to get help in your all kind of assignment help. We have 172+ experts available, who can help you to get HD+ grades. We also provide Free Plag report, Free Revisions,Best Price in the industry guaranteed.

We provide all kinds of assignmednt help, Report writing, Essay Writing, Dissertations, Thesis writing, Research Proposal, Research Report, Home work help, Question Answers help, Case studies, mathematical and Statistical tasks, Website development, Android application, Resume/CV writing, SOP(Statement of Purpose) Writing, Blog/Article, Poster making and so on.

We are available round the clock, 24X7, 365 days. You can appach us to our Whatsapp number +1 (613)778 8542 or email to info@universalassignment.com . We provide Free revision policy, if you need and revisions to be done on the task, we will do the same for you as soon as possible.

We provide services mainly to all major institutes and Universities in Australia, Canada, China, Malaysia, India, South Africa, New Zealand, Singapore, the United Arab Emirates, the United Kingdom, and the United States.

We provide lucrative discounts from 28% to 70% as per the wordcount, Technicality, Deadline and the number of your previous assignments done with us.

After your assignment request our team will check and update you the best suitable service for you alongwith the charges for the task. After confirmation and payment team will start the work and provide the task as per the deadline.

Yes, we will provide Plagirism free task and a free turnitin report along with the task without any extra cost.

No, if the main requirement is same, you don’t have to pay any additional amount. But it there is a additional requirement, then you have to pay the balance amount in order to get the revised solution.

The Fees are as minimum as $10 per page(1 page=250 words) and in case of a big task, we provide huge discounts.

We accept all the major Credit and Debit Cards for the payment. We do accept Paypal also.

Popular Assignments

Assignment Quantitative CASP RCT Checklist

CASP Randomised Controlled Trial Standard Checklist:11 questions to help you make sense of a randomised controlled trial (RCT)Main issues for consideration: Several aspects need to be considered when appraising arandomised controlled trial:Is the basic study design valid for a randomisedcontrolled trial? (Section A)Was the study methodologically sound? (Section B)What are

Read More »

Assignment Qualitative CASP Qualitative Checklist

CASP Checklist: 10 questions to help you make sense of a Qualitative researchHow to use this appraisal tool: Three broad issues need to be considered when appraising a qualitative study:Are the results of the study valid? (Section A)What are the results? (Section B)Will the results help locally? (Section C) The

Read More »

Assignment Topics

PS3002 Assignment TopicsDear studentsPlease choose one of the topics below. Please note that if you are repeating this subject, you cannot choose the same topic that you did previously in this subject.patellar tendinopathyinstability of the lumbar spinehamstring strainperoneal tendinopathyhip – labral tear.hip osteoarthritispatellofemoral instabilityankylosing spondylitisanterior cruciate ligament rupture (conservative management)quadriceps

Read More »

Assessment 2 – Report

Assessment 2 – Report (1200 words, 30%)PurposeTo demonstrate an understanding of the purpose and application of evidence-based dietary advice and guidelinesLearning objectives1.Review and analyse the role and function of macronutrients, micronutrients and functional components of food in maintaining health2.Understand digestion, absorption and metabolism of food in the human body and

Read More »

Assessment 2 – Individual Case Study Analysis Report

Southern Cross Institute,Level 2, 1-3 Fitzwilliam Street, PARRAMATTA NSW 2150 & Level 1, 37 George Street PARRAMATTA NSW 2150Tel: +61 2 9066 6902 Website: www.sci.edu.auTEQSA Provider No: PRV14353 CRICOS Provider No: 04078ªPage 1 of 16HRM201 Human Resources ManagementSemester 1, 2026Assessment 2 – Individual Case Study Analysis ReportSubmission Deadline: This Week,

Read More »

ASSESSMENT 2 BRIEF HPSYSD101 The Evolution of Psychology

HPSYSD101_Assessment 2_20240603 Page 1 of 7ASSESSMENT 2 BRIEFSubject Code and TitleHPSYSD101 The Evolution of PsychologyAssessment TaskAnnotated BibliographyIndividual/GroupIndividualLength2,000 words (+/- 10%)Learning OutcomesThe Subject Learning Outcomes demonstrated by successful completion of the task below include:b) Examine the significant figures, events and ideas present in the history of psychology.c) Identify and relate the

Read More »

Assessment 1 – Individual Case Study Analysis Report

HOS203 Contemporary Accommodation ManagementSemester 1, 2026Assessment 1 – Individual Case Study Analysis Report (10%)Submission Deadline: This Week, at 11:59 pm (Week 4)Overview of this AssignmentFor this assessment, students are required to analyse an assigned case study about hospitality industry relevant regulations and/or operational and accreditation failures of a hospitality organisation.

Read More »

Assessment Brief PBHL1003FOUNDATIONS OF HEALTH AND HEALTH CARE SYSTEMS

Assessment BriefPBHL1003FOUNDATIONS OF HEALTH AND HEALTH CARE SYSTEMSTitleAssessment 2 TypeEssay Due DateWeek 6 Monday 14 April 2025, 11:59pm AEST Length1000 words Weighting60% Academic IntegrityNO AI SubmissionUse Word Document – submit to Blackboard / Assessments Tasks & Submission / Assessment 2 Unit Learning OutcomesThis assessment task maps to the following Unit

Read More »

Assignment 4 – Intersection Upgrades and Interchange Station Design

CIVL5550: Civil Infrastructure DesignAssignment 4 – Intersection Upgrades and Interchange Station DesignDue: This WeekSubmission Instructions:1.Submit a report of approximately 10 pages, covering the following:Part 1: Intersection Upgrade Design•Propose upgrade schemes for two sign-controlled intersections and one signalized intersection•Use SIDRA to evaluate the performance of both the original and upgraded intersections•Use

Read More »

Assessment Brief 1

1 of 14Assessment Brief 1Assessment DetailsUnit Code Title NURS2018 Building Healthy Communities through Impactful PartnershipsAssessment Title A1: Foundations of Community Health Promotions ProjectAssessment Type ProjectDue Date Week 4, Monday, 22nd of September 2025, 11:59pm AESTWeight 40%Length / Duration 1200 wordsIndividual / Group IndividualUnit Learning Outcomes(ULOS)This assessment evaluates your achievement of

Read More »

Assignment 1 – Digital Stopwatch

Assignment 1 – Digital StopwatchThis assessment is an individual assignment. For this assignment, you are going to implement the functionality for a simple stopwatch interface as shown above. The interface itself is already provided as a Logisim file named main.circ . Your assignment must be built using this file as

Read More »

Assessment Background Country Profile

BackgroundCountry ProfileKiribati is an island nation situated in the central Pacific Ocean, consisting of 33 atolls2 and reef islands spread out over an area roughly the size of India (see Figure 1).i Yet, Kiribati is also one of the world’s smallest and most isolated country. A summary of Kiribati’s key

Read More »

Assessment 3: PHAR2001 INTRODUCTORY PHARMACOLOGY

PHAR2001 INTRODUCTORY PHARMACOLOGYAssessment 3: Case StudyASSESSMENT 1 BRIEFAssessment Summary Assessment titleAssessment 3: Case study Due DateThursday Week 6, 17 April at 11:59 Length•The suggested number of words (not a word limit) for the individual questions within the case study is as indicated at the end of each individual question. Weighting50%

Read More »

Assessment Module 1 Healthcare Systems Handout

Module 1Healthcare Systems HandoutGroup AgendasHealth Professionals: You got into health to help people. However, as an owner and operator of a multidisciplinary practice, you need to see many patients to cover the cost of equipment, technology, office and consumables, and pay your staff. The Medicare benefit doesn’t cover the rising

Read More »

Assessment 2 – Case study analysis 

Assessment 2 – Case study analysis  Description  Case study analysis  Value  40%  Length  1000 words  Learning Outcomes  1, 2, 3, 4, 5, 6, 7  Due Date  Sunday Week 9 by 23:59 (ACST)  Task Overview  In this assessment, you will choose ONE case study presenting a patient’s medical history, symptoms, and relevant test

Read More »

Assessment NURS2018: BUILDING HEALTH COMMUNITIES

NURS2018: BUILDING HEALTHCOMMUNITIES THROUGH IMPACTFULPARTNERSHIPSAssessment 1 Template: Foundation of Community Health Promotion projectOverall word count excluding the template wording (63 words) and reference list:Introduction to health issue:The case study, increase breast screening in Muslim women living in Broadmeadows,Melbourne, focuses on addressing the low participation rates in breast cancer screening amongMuslim

Read More »

Assessment EGB272: Traffic and Transport Engineering (2025-s1)

EGB272: Traffic and Transport Engineering (2025-s1)ashish.bhaskar@qut.edu.auPage 1 of 8Assessment 1A (15%) Cover PageIndividual component: 5%Group component: 10%You are expected to submit two separate submissions:Individual Submission (5%): Each student must submit their own individual report. Details of the individual report are provided in Section 3.1, and the marking rubric is in

Read More »

Assessment 3 – Essay: Assessment 3 Essay rubric

Unit: NUR5327 – Management and leadership in healthcare practice – S1 2025 | 27 May 2025Assessment 3 – Essay: Assessment 3 Essay rubricLearning Objective 5:Differentiate drivers forchange and proactively leadhealth professionalresponses to changing anddynamic environmentsFails toidentify aclear plannedchange ordoes not linkit to thestrategic plan.0 to 7 pointsIdentifies aplannedchange, butthe link

Read More »

Assessment 2 – Case study analysis 

Assessment 2 – Case study analysis  Description  Case study analysis  Value  40%  Length  1000 words  Learning Outcomes  1, 2, 3, 4, 5, 6, 7  Due Date  Sunday Week 9 by 23:59 (ACST)  Task Overview  In this assessment, you will choose ONE case study presenting a patient’s medical history, symptoms, and relevant test

Read More »

Assessment 1 PPMP20009 (Leading Lean Projects)

Term 1, 2025PPMP20009 (Leading Lean Projects)1Assessment 1 – DescriptionAssessment title Case study reportAssessment weight 40% of the unit marksReport length 3000 wordsMaximum 8 pages excluding references and appendicesReport format MS Word or PDFSubmission type IndividualSubmission due by Friday, Week 6Assessment objectiveThe purpose of this assessment item is to help you

Read More »

Assignment Maternity – Paramedic Management

Title-Maternity – Paramedic ManagementCase Study – Home Birth Learning outcomes1. Understand the pathophysiology and prehospital management of a specific obstetric condition.2. Develop a management plan for a maternity patient.3. Examine models of care available for maternity patients.4. interpret evidence that supports paramedic care of the maternity patient and neonate.5. Demonstrate

Read More »

Assignment Guidelines for Cabinet Submissions

Guidelines for Cabinet SubmissionsGENERALThe purpose of a Cabinet submission is to obtain Cabinet’s approval for a course of action. Ministers may not have extensive technical knowledge of the subject matter -and may have competing calls on their time. It is, therefore, important that Cabinet submissions are presented in a consistent

Read More »

Assignment Secondary research structure

Dissertation – Secondary Research – Possible Structure and Content GuideA front cover stating: student name, module title, module code, Title of project moduleleader, supervising tutor and word count.Abstract (optional and does not contribute to your word count)This should be an overview of the aim of the critical review, the methodology

Read More »

Assignment E-Business and E-Marketing

Module HandbookFaculty of Business, Computing and DigitalIndustriesSchool of Business(On-campus)E-Business and E-MarketingModule.2025-26􀀀Contents Module Handbook 1Contents 2Module Introduction 3Module Leader Welcome 3Module Guide 5Module Code and Title 5Module Leader Contact Details and Availability 5Module Team Tutors Contact Details and Availability 5Module Teaching 5Module Intended Learning Outcomes 5Summary of Content 6Assessment and Deadlines

Read More »

Assignment II: Computational Fluid Dynamics (CFD) Analysis of

CRICOS Provider 00025B • TEQSA PRV12080 1MECH3780: Computational MechanicsAssignment II: Computational Fluid Dynamics (CFD) Analysis ofGeneralised Cardiovascular Medical DevicesIntroduction:In this assignment, you will develop your CFD capability by analysing a benchmark casefrom a validation study sponsored by the U.S. Food & Drug Administration (FDA) and fundedby the FDA’s Critical Path

Read More »

LCRM301 Researching criminology

LCRM301 Researching criminology Worksheet 1 This worksheet will be disseminated to students in Week 3 and will assist them in the planning and development of the second assessment task: literature review. PART 1: Refining your topic The topic I am interested in is: I am interested in this topic because:

Read More »

ASSESSMENT TASK 2 – COURT APPLICATION

APPENDIX B: ASSESSMENT TASK 2 – COURT APPLICATION (30% OF FINAL MARK)General informationThis Assessment task is worth 30 marks of your final mark.The task is either making (Applicant) or opposing (Respondent) an application before the Supreme Court in your respective state based on a fact scenario, which will be uploaded

Read More »

Can't Find Your Assignment?