CSCI 632
Vulnerability Assessment Report
Target
April 12, 2024
Fouty-Round Consulting Services, LLC
TABLE OF CONTENTS
1. Executive Summary..................................................................................................................3
Page 1 of 10
CSCI 632
1.1 Vulnerability Assessment Summary of Results................................................................3
2. Vulnerability Assessment..........................................................................................................4
2.1 Purpose..............................................................................................................................4
2.2 Scope.................................................................................................................................4
2.3 Methodology.....................................................................................................................4
2.4 Vulnerability Ranking.......................................................................................................4
3. External Publicly Available Information (OSINT)...................................................................5
3.1 Search Engine Results.......................................................................................................5
3.2 LinkedIn Results...............................................................................................................6
4. Vulnerability Assessment Findings...........................................................................................6
4.1 Target from Openvas report.............................................................................................6
4.2 Target from Openvas report..............................................................................................7
4.3 Target from Openvas report..............................................................................................7
4.4 Target from Openvas report..............................................................................................8
4.5 Target from Openvas report..............................................................................................8
Appendix A – References................................................................................................................9
Page 2 of 10
CSCI 632
1. EXECUTIVE SUMMARY
Forty-Rounds was engaged by Target to perform an internal and external vulnerability
assessment and presents the business and technical findings in this report. The assessment was
conducted from April to July, 2024.
1.1 VULNERABILITY ASSESSMENT SUMMARY OF RESULTS
The following was identified by Forty-Rounds during the course of the vulnerability assessment
as the greatest risks to the organization’s information and systems.
The first top risk is LinkedIn, which is high due to the fact that a user is able to join the
website and create a fake account with the company information.
The second top risk is when using service email, it is high due to the fact that the hacker
can use any email to gain access to the system.
The third top risk is using Maltego due to the fact when hackers are inputting the IP and
information. They can work around what is required.
2. VULNERABILITY ASSESSMENT
2.1 PURPOSE
The purpose of performing a vulnerability assessment is to identify and classify the
security as a whole which will help protect Target from having a high-risk level of being
hacked to a lower level of security. This process will be a footprint of vulnerability
assessment and way to lower the risk.
2.2 SCOPE
OSINT conducted on the following Target external URLs:
• www.target.com
Internal IP addresses scanned for vulnerabilities
IP 10.0.10.1
2.3 METHODOLOGY
Target assessment methodology for Target is the same for the other different types of
companies. Before one can look at how to protect itself. The first step is to identify what
needs to be changed. In most cases it comes from social media, for example LinkedIn.
Users are able to create an account and put false details such as their name and saying they
are the CEO. Most users do not check out the information is correct or not. The second
step of this is what methods can be used to break this habit and what should be changed
Page 3 of 10
CSCI 632
when it comes to things like this. Having some type of checkmark or something that user
will know the difference between what is real and what is not real. Also having the website
secured page where when a hacker is looking up an IP address or finding some type of
backdoor way. Target will get some type of alert that will go off, so customers’
information is secure. This goes with step three having a phase that only the company
understand and know when it is something real and when it is something fake. This will go
hand-held with what type of systems hackers mostly use does will help to come up with
some type of plan that the company can use to keep hacking low. Some of these systems
are DSN Spoofing, Virus, and Cookie Theft. Having knowledge of these systems will help
Target be able to lower its risk of users using their information and creating other pages.
To lower this risk of hacking having some of these tools will help. Clearing logs that will
have hacker be able to backdoor the company. Escalating Privileges this will service as a
blocker to be able to filter out what should be going through and what should not be going
through. Having a system that is focused on bypass access to be control and this could be
something that will stick out like someone is not noticing it. The other part is having a
hidden attack that will service has a wall that hackers would think they got access to
information however it is fake information. Covering Tracks is what most hackers will be
trying to do. That being said, having some type of way to hide documents that should not
be seen, or other people are user should know anything about.F One suggestion is rootkits
which will hide the documents the users do not see, and it is helping to protect the
information and data of other people. This will go with executing applications which
Target can use to create and maintain any type of access that maybe showing up. It is just
like having someone watching what someone is doing or if information is being leaked or
hacked it will alert them. And this is normally used by Trojan or some type of spyware
system. These are broken down into six-part Reconnaissance, scanning, gaining access,
maintaining access, and covering tracks. By Target having knowledge of these six parts
and understanding how they all go together it is a fore sure way of making sure that Target
is being taken care of. These steps are what most hackers are going to steal from the
company. If Target can get in front of these six parts, then it will be less information being
stolen. As well as Target will be in a better place when it comes to hackers stealing
information and creating fake accounts. Providing ways to block hacker from stealing
information is the goal that the company going for.
2.4 VULNERABILITY RANKING
The vulnerabilities are identified and ranked according to their potential threat to the
Enterprise. The “risk factor” for each vulnerability identified is determined using the
Common Vulnerability Scoring System (CVSS)2:
Critical CVSS score of 10
High CVSS score ranges (7.0 - 9.9)
Medium CVSS score ranges (4.0 - 6.9)
Page 4 of 10
CSCI 632
Low CVSS score ranges (1.0 - 3.9)
It is recommend to immediately remediate any high or critical vulnerabilities due to the
potential threat. Although, exploiting multiple medium or low vulnerabilities may also lead
to a system compromise.
3. EXTERNAL PUBLICLY AVAILABLE INFORMATION (OSINT)
During external reconnaissance, Target was able to find the following publicly available
information using various reconnaissance tools.
3.1 SEARCH ENGINE RESULTS
Details
These servers
and email
addresses were
identified using
the Bing search
engine.
Page 5 of 10
CSCI 632
These servers
and email
addresses were
identified using
the Google
search engine.
The
information
shown was
identified using
the Maltego
tool.
Impact
Due to the information provided Target should have some restrictions when it comes to the
IP address.
Recommendation
Providing a secure lock on the IP address, also when it comes to users that have limited
access to the IP address. Running the IP address through systems only access to what is
being purchased.
Page 6 of 10
CSCI 632
3.2 LINKEDIN RESULTS
Details
These users
were identified
by manually
searching
through
LinkedIn
accounts.
Impact
Any user can create a CEO profile so if some is not knowledgeable of who is the current
CEO. Many users of the LinkedIn profile will be talking to anyone that has a CEO profile
page.
Recommendation
With the real and current CEO profile have a checkmark like Instagram of some type of
social media.
4. VULNERABILITY ASSESSMENT FINDINGS
During the vulnerability assessment Target was able to that it is easy to create by using easy
passwords.
4.1 TARGET REPORT
Reconnaisance
Host(s) CVSS Severity
10.0.1.10 CVSS score
ranges (7.0 - 9.9) High
Page 7 of 10
CSCI 632
Impact
Footprint of the scanning and enumeration grounds that hackers will be looking for.
Recommendation
Target should collected all the data from fake account and use this as a tool or as a
blueprint.
4.2 TARGET VULNERABILITY FINDING
Details
Scanning the IP or host should not be easy to get information from.
Host(s) CVSS Severity
10.0.1.10 CVSS score
ranges (4.0 - 6.9)
Medium
Impact
Hackers are able to scan IP host addresses to get information from the system.
Recommendation
Placing a lock or some type of security on the IP host address will help prevent hackers
from getting this information.
4.3 TARGET INPUT VULNERABILITY REPORT
Details
Gaining Access
Host(s) CVSS Severity
10.0.1.10 CVSS score
ranges (4.0 - 6.9)
Medium
Impact
System hacking, hacking passwords, and Generate Rainbow Tables
Recommendation
Target should maker employees, and user create a new password every six months in order
to protect itself from being hack.
Page 8 of 10
CSCI 632
4.4 TARGET VULNERABILITY TITLE FROM OPENVAS REPORT
Details
Maintaining Access
Host(s) CVSS Severity
10.0.1.10 CVSS score
ranges (4.0 - 6.9)
Medium
Impact
Having access to all systems and doing a regular system check-in.
Recommendation
Having someone do a remote check-in with the systems and if any changes need to be
made do as such.
4.5 TARGET VULNERABILITY TITLE FROM OPENVAS REPORT
Details
Covering Tracks
Host(s) CVSS Severity
10.0.1.10 CVSS score
ranges (1.0 - 3.9)
LOW
Impact
Documents or files that need to be hidden.
Recommendation
Those documents, or files that need to be hidden, making sure they are and for those who
need access to them. Having a lock or password on them.
Page 9 of 10
CSCI 632
APPENDIX A – REFERENCES
Alshodari, M. (2020, July 3). The Ultimate Ethical Hacking Methodology Explained.
https://www.linkedin.com/pulse/ultimate-ethical-hacking-methodology-explained-majed-
alshodari/
Ec-Council. (2024, March 26). What is Ethical Hacking. Cybersecurity Exchange.
https://www.eccouncil.org/cybersecurity-exchange/ethical-hacking/what-is-ethical-
hacking/
Page 10 of 10