SEC 435 Assignment (incident related to either a successful or failed penetration testing effort, or a successful or unsuccessful hacking attempt against an organization)

profilegulugstayinam
mulugetaenginoDIONACHPENTESTCASEStudysec435.docx

RUNNING HEADER: CASE STUDY

RUNNING HEADER: CASE STUDY 2

NAME: Mulugeta Engino

COURSE: SEC 435- Assignment 9 Case Study

INSTRUCTOR: Dr. GIDEON, JEROME

Strayer University

DATE: 06/03/2019

Introduction

See my corrections page found in the writing folder for the numbers in blue.

Your paper long enough or complex enough for subtitles. These only detract from the quality of the paper if one does not have true subsections which are used in papers in which one must fully develop related issues to reach a comprehensive conclusion. Thus one must have good introductory paragraphs, and some sort of concluding paragraph or sub-conclusion, then a good transition to the next subsection. (2) Penetration testing also known as Pen testing is the practice that many organizations carry out to test the web application and computer system to find how vulnerable the system is that an attacker could take advantage to access the system and conduct illegal practices. The practice is practical and accredited whose aim is to measure how an IT infrastructure is secure. New ⁋ Systems established in many organizations are subject to vulnerabilities which are as a result of many factors. During designing, it is common that the designers may make mistakes when developing the system during the development phases (Rehim, 2016). I hope you explain this in the body. The configuration of the system may not be proper and this contributes more to the system failure. New ⁋ Since the systems are developed and operated by human beings, errors are not inevitable from the activities that human being carry out. The activity aims at ensuring the system is secure from the most common incidents through intelligently ensuring susceptibilities are taken care of. The cost associated with the network down time is huge which may lead to massive destruction and losses. This makes the penetration test important in order to reduce the vulnerability of the system. And?

This has many of the core elements of an introduction, but it has background not found in the body. Revise last so it reflects the completed paper. Put background in the body, and just use what you need to set the tone and scope of the paper up front. An introduction does not have documentation as you are using what you have already presented and documented in the body.

Have a strong introductory paragraph which sets the tone for the paper. Then follow it with a paragraph or two, or as needed, to lay out the key issues or points, and then what the paper accomplished, transitioning finally to the body.

A good introduction sets the tone, scope, direction of the paper, and what the paper will accomplish. Otherwise the reader does not know what he or she needs to be considering as he or she progresses towards the conclusion.

Case

(2) Selecting a suitable strategy for the Pen test is important in order to have a successful practice that balances of the costs incurred and the benefits realized. Pen test usually engage third party security experts whereby they stimulate attacks in the system and the people using real intruders. This provides a clear analysis of the security of the organization. This is the most thorough analysis of the security of the system since vulnerabilities are found and exploited to have an understanding of how the organization can be compromised. New ⁋ This improves the security awareness for the organization. In this task we We means, in writing, you and I the reader, you and someone else you have identified in the paper, or you and another author. We does not mean people in general with you have some perceived commonality with.

You means only the reader. It does not mean people in general. Unless the paper is a general information paper written specifically for readers who one can assume want the information, which generally does not apply to academic writing or most professional writing, don’t use you, either. Use the generic one, or a noun. focus on an incident where an external penetration test was carried out by (10) this person does not have a first name? or, is this a company, it is not clear? Dionach which was carried out in one of the largest organizations in the United Kingdom (Careers. 2019). In this case, the client’s servers were contained in one single office whereby they intended to gain information regarding how secure their systems are externally. New The organization permitted Dionach to access the external systems. They (43) Be careful with pronouns, you know what you mean when you are writing, but the reader has context and rules of grammar. If the context is not clear, and that is often the case, one has to rely on the rules. So do not use pronouns if there are words that can agree in number and gender between the pronoun and the intended antecedent.

Review pronouns. A pronoun must agree with its intended antecedent in number and gender. Collective nouns are usually first person. If you do not want to use it, then you need to use a synonym or repeat the original noun, or use an appropriate plural such as the Chinese vice China, or committee members, vice the committee. While context helps, if there is ambiguity the reader must rely on the rules of grammar.

Be sure that no other noun that can agree in number and gender comes between your pronoun and antecedent. While the context may be clear, many times the context is ambiguous and then real problems of understanding can follow. gave the IP addresses to the company where they external systems? wanted the test to be carried out. The company carried out the test in a procedural manner whereby they who? External systems is still the antecedent? followed a well-established procedure. These steps included, gathering information, external services, Identification of the vulnerabilities and exploiting them and then producing the report on the issues and the recommendations they found to enhance security.

Information gathering

(2) Dionach initial activity was to verify all the IP addresses they were given by the organization. This was the initial stage of gathering the relevant information through the use of relevant means such a emails, telephones numbers and addresses available in RIPE. (9) The querying of the DNS server was done to gather more information which included the registration information and the mail servers. New ⁋ The internet and newsgroup searches were not rich in information and the information gathered from the forums was not sufficient and useful in the process of penetrating the network. This included the technology that the organization has used and the individual skills (Porup, 2017).

(2) An internal tool that had been developed was used on the search engine to identify the DNS names with the IP addresses within the range. This turned various web sites on five 5 different IP addresses. The assumption in this case was that there were some other web sites that the organization hosted which had not been indexed by the search engines. A point to note in this case is that the information was publicly available and the discovery involved little contact with the network of the organization. New ⁋ and why does this matter then New ⁋

External services scanning

(2) The IP range was then scanned for common TCP and UDP services such as mail, web and the remote control services. More scanning was also carried out over the course during the test week. Various tools were used in scanning the information whereby the scanning traffic was near zero and detection of any intrusion was evaded. New ⁋ In this case, the TCP port scanning revealed that no host replied to the pings. There were SMTP gateways, DNS server, FTP server and a host with port 264 open which indicated a checkpoint firewall. The services banners showed that web and the FTP were Microsoft IIS based with a mixture of IIS 4.0 and IIS 4.0. You assume your reader will know what all this means, maybe, maybe not. Spell out why this data is important to know in the context of the lesson or lessons of this paper, and if any takeaway may apply.

Identification and exploitation of the vulnerabilities

(2) The mail relay was one of the areas where the attempt was carried out on the mail server and in this case there was no success. The downloading of the firewall topology was not successful and this may have revealed some information relating to the internal network information. New ⁋ The DNS server and zone were also not successful which would have been a major source of internal network information. And?

(2) A commercial web server vulnerability tools for scanning and the open source vulnerability scanning tools were used in checking the vulnerabilities on the host services. In this case, one of the FTP servers was identified to have allowed access and also some of the servers of the web had not been locked down which had services that were vulnerable to remote execution. Such as? New ⁋ The automated scans were reported by whom? to have more vulnerability whereby manual check revealed a lot of information. It was also reported by whom? that one of the hosts allowed execution through remote command. New ⁋ The explanation in this case was that the organization has a compromised host that was very critical. Some credentials could also be retrieved for the administration level users. This means? New ⁋ Common issues were also identified in the web sites whereby some pages were vulnerable to the SQL injection which allowed statements of arbitrary SQL to be executed giving full control of the server. New ⁋ The proxy server in the port scan was also reported to allow the intranet access although some information that is internal was not available. You try and cover too much here. Good paragraph recognition will help you realize when you are asserting statements, that may or may not be of kind, into a block of text, not a paragraph. Thus you assert something and move, you don’t discuss the topic, or lay a good foundation for building upon it.

Reporting

(2) At this stage, Dionach gave a comprehensive report of the finding out of the test. The information above was compiled to be part of the final report. The issues reported were categorized into various classes depending on how strong or weak they were in posing threat to the system. New ⁋ The overall security was at risk and highlighted the configuration of the firewall was maintained. New ⁋ The intruders what intruders? The pen testers? could access the remote control of the system whereby they could gain the access to various servers. This would follow massive effects that were likely to cause great harm to the organization. Huh? It is clear the company had issues, which the pen testers identified. Did the testers not recommend mitigation, did the company not begin to correct these problems? You wrote likely to cause harm, did harm follow? You never mention the company or the time frame of the case.

(2) In this test, it is clear that the test was successful and the results were promising. This statement directly contradicts what you ended the last paragraph with. The identification of the vulnerability of the system is the main objective in order to propose the recommendations to be followed in addressing the challenges identified. The test was carried out on the external part of the organization which is the most common part of the organization that hacker usually try to attack.

(2) The penetration test can be said to be a successful one which addressed the challenge the organization would have faced in case an attacker gained access to the system. What would have been done differently in this test was to carry out the external and internal penetration test together. By doing this, it would be easier to track the entire system and address the issues altogether. Based on what that was presented in the body? At best this is only implied. New ⁋ The attack on the system can either be externally or internally which both poses great threat to the organization. In this case, it would be a good opportunity to have a solution for the entire system and establish long lasting solution to the areas identified to create chances for the attackers to gain access to the system.

Conclusion

In conclusion, pen test have become one of the requirements in organizations in order to reduce the risk level of organizations. Cases of hackers have been reported in many countries whereby large multinational organizations have been facing great challenges in dealing with massive losses as a result of system hacking (Rehim, 2016). New ⁋ Penetration testing offers insight to organization’s effectiveness on security, together with strategies that can be implemented to enhancing the security level. Through the experts who offer the services, it becomes easier to identify the vulnerabilities and the correction carried out before they are exploited by the malicious insiders and the hackers who access the system. This is at best a summary of a closing statement, it is not a conclusion or concluding statement? The purpose of the paper is not the information in the body, but how the body supports specific lessons and any recommendations or other takeaway based solely on what is presented and documented in the body, hence, like the introduction, there is not documentation in the conclusion.

Mulugeta,

You had a good paper and some very good insights. There were some developmental issues, to include that your introduction, body, and conclusion were mostly independent from one another, and did not work as one.

Work on developing an outline which lays out the problem, the arguments you want to make, and in the context of the lessons and takeaway you will have, and thus outline up front, in the conclusion. This way your body and conclusion will work as one, and you can then outline your introduction to reflect what the paper accomplished, by revising the introduction as the last thing you do.

This will further allow you to develop your arguments better, have better paragraphs, transitions and assure that you have the detail and depth to lay out lessons and takeaway at the end. All three parts of the paper need to work as one.

I will address my concerns in turn. A paper should be focused on the conclusion you want to draw. A paper is not about providing a lot of information, but developing argument using specific events, examples, arguments, etc. Think through your paper to the lessons and takeaway you want to leave the reader, and then outline what you need to develop to support those lessons.

While one can bring in additional ideas, they must directly support the key issues that are necessary and directly relate to the conclusion you will reach. Your conclusion must be fully supported by the body of the paper. All issues and problems laid out in the body, must apply to some lesson and conclusion you raise in the paper. While one can have background related to material needed not for the conclusion but for the material supporting the conclusion, it still has to be relevant to the focus of the paper.

Your conclusion must be fully supported by the body of the paper. All issues and problems laid out in the body, must apply to some lesson and conclusion you raise in the paper. While one can have background related to material needed not for the conclusion but for the material supporting the conclusion, it still has to be relevant to the focus of the paper.

You need to proof your pronouns. You know what you mean when you write, but the reader needs proper grammar to assure the context is correct.

You need to learn how to identify one idea paragraphs, transitional words and sentences, and overall have strong paragraph structure. Clarity is important, and one does not want to bury ideas in mounds of text, or multiple asserted statements.

You need to develop strong instincts on when to use quotes and use them effectively. This will help you with paragraph development, and to better argue your points. I will add some examples near the end of my comments below.

Facts are building blocks to the conclusion, but using only facts is like building a house with only wood slats and not having any paint, eaves, molding, etc. to make the house stand out. One uses fact to lay out the basic information, then one uses direct quotes tied to the discussion, preferably from other sources than those used for the basic information, examples, or alternative data to discuss the reasons why something is true or possibly not true, or an alternative view or all three over several paragraphs. This helps build a strong case and developed argument that provided the specific data one uses to reach the conclusion. When one only provides facts, one is not giving the reader the benefit of your research, or your originality that would come from your discussion.

By finding multiple sources for all data you assure you are fully covering the topic, and have more sources upon which to draw from in both writing the paper, and supporting it. By looking for primary, or original documentation, and you can do this by seeing what sources your secondary source used, and by corroborating all data, you then build a body of knowledge in your own data base. Then when you write, you write mostly from your head which is an amalgam of all the material you read,

Then you know when you are writing something that is unique to only once source and can document that idea or concept. And you will bring in various quotes, and examples, to support your writing. But you can only do so if you do focused, not general research.

Be sure to go back after you finish the draft of the paper and rewrite your working introduction/proposal to reflect what the paper actually did, not what you originally hoped it would do. This way you can double check that you have the three parts of a paper working together.

The introduction should be the last thing you revise so it reflects what the paper does. The conclusion should drive the outline. There are several ways to do this. One common way is think the paper through to what you want to leave the reader with. Have the initial ideas for the lessons clear before you start. Then outline the paper, and conclusion.

The second is to do the first draft, then follow the process by outlining, again as hopefully you had an outline to start, the key points and identifying the lessons that you make while developing those points. Then craft the lessons and finalize the conclusion.

Sleep on the paper, then with fresh eyes review and revise one last time and proofread for paragraph development, proper quote and pronoun usage, etc. Learn to use proper quotes, I provide the primer and the PowerPoint in the student center, and gave examples in the first paper’s feedback.

I want to iterate this point as well. When proofreading your paper, the last thing you write, or redraft, is the introduction. This way you can lay out for the reader what the paper does, and accomplishes. It will serve as a review that the body and the conclusion did work together.

You might try a reverse outline when you proof your work. After you finish your first draft, outline the key point and sub arguments you make in the paper. And the points you have in both your introduction and conclusion. Then evaluate them.

Are they in logical order, are you going back on yourself and discussing information that is overlapping? Are you raising issues or problems that you are not bringing to some fruition or are laying a foundation for information that is relevant to the conclusion? Are all the points in the conclusion well supported? And does the introduction introduce what follows, and what will be later developed in the paper?

Here are with some examples on using quotes. For example, quotes add credibility. If you wrote: The president assured the people he would fight to the last man. In his speech the president said: “I will fight to the last man.” That would be redundant. And this would not be a good quote.

However, note the following two uses.

The president addressed the Congress pointing out that he took personal responsibility for the action. In defense of the decision, the president stated flatly: “Sometimes when one sits behind the desk, there are no clear answers. I have an obligation to make the best decision I can with what information I have. It is my obligation and my duty to the people.”

Or,

The president addressed the Congress pointing out that he took personal responsibility for the action. Former President Bill Clinton gave credence to the President Bush's words when, after the speech, Clinton pointed out: “Whether one agrees or disagrees with the president, at times it is only the president and his conscious. It is his call and it is the president that was elected to make that call.”

This quote is used to corroborate an idea.

This should give you an idea of using a quote for credibility and one for corroboration.

References/Bibliography

If the bibliography and footnotes/reference page have a 1:1 ratio then one is not doing research. It is like building a home project and using just what one finds in one’s back yard. Good research, especially as one should be finding multiple source for credibility and corroboration, and assure that all ideas are being explored, is more like deciding to build a project and going from store to store to find the best material. But one notes not only what one eventually buys, but all the items one looked at to help one to decide what to buy.

100.8

Works cited I see no sources related to any specific case, so it must be based on one of these four sources. When one limits one’s research, one limits how well you can support your paper.

Porup, J. (2017, September 13). What is penetration testing? 10 hacking tools the pros use. Retrieved from https://www.csoonline.com/article/2943524/17-penetration-testing-tools-the-pros-use.html

Careers. (2019, May 24). Retrieved from https://www.dionach.com/careers

Penetration Testing Guidance - PCI Security Standards. (n.d.). Retrieved from https://www.pcisecuritystandards.org/documents/Penetration_Testing_Guidance_March_2015.pdf

Rehim, R. (2016). Effective Python penetration testing: Pen test your system like a pro and overcome vulnerabilities by leveraging Python scripts, libraries, and tools. Birmingham: Packt Pub.