Cyber Security

about this Project...

Introduction –

In my third year at the University of Westminster, I embarked on a 11-week long project as part of the “Cyber Security” module. This intensive module was conducted in the university’s state-of-the-art cyber security computer labs. We utilised the OWASP vulnerable machine, Kali Linux, and a Windows vulnerable virtual machine for hands-on exercises and simulations. All these environments were set up using VM Box. The module provided a blend of theoretical knowledge and practical skills, equipping me to tackle real-world cybersecurity challenges.

Mark Awarded –

94 / 100 – High First Class

Project Specification –
Skills Developed –
  • Security Architecture Evaluation: Assessed and evaluated security architectures to enhance operational security.
  • Cryptography Protocols: Analysed various cryptography protocols, understanding their vulnerabilities and potential attack vectors.
  • Penetration Testing: Conducted comprehensive penetration tests, identifying system vulnerabilities and documenting findings.
  • Server-side Exploits: Gained expertise in identifying and mitigating vulnerabilities such as data tampering, SQL injection, and XSS scripting.
  • Client-side Defense: Developed skills in defending against client-side attacks like Man in the Middle (MiTM) and social engineering.
  • DoS Attack Prevention: Learned techniques to prevent and mitigate Denial of Service attacks.
  • Cybersecurity Recommendations: Provided actionable recommendations to enhance system security, including firewall configurations and intrusion detection.
  •  
Some Examples from Project –
  • Penetration Testing Scenario: Conducted a penetration test for a medium-sized car rental service with a web app, identifying vulnerabilities in storing personal information and managing vehicle listings.
  • OSINT Activities: Utilised tools like TheHarvester, SpiderFoot, and Recon-ng for Open Source Intelligence gathering, aiding in the identification of potential vulnerabilities.
  • SQL Injection: Demonstrated proficiency in identifying and exploiting SQL injection vulnerabilities in web applications, understanding the risks and potential damages.
  • XSS Scripting: Identified vulnerabilities related to Cross-Site Scripting, understanding the potential risks associated with malicious scripts.
  •