School project
Pentesting | Black-box
Context
A black-box assessment, meaning I started without any inside knowledge of the target, just like a real external attacker would. The goal was to find out how well the system held up and to report back in a way that a client could act on.
What I did
Mapped the target, investigated vulnerabilities and applied exploitation techniques to gain access, guided by the OWASP Top 10. Every step was documented, from reconnaissance to exploitation, and the findings were written up together with concrete security measures.
Security focus
Findings were rated with the Common Vulnerability Scoring System (CVSS) so that risks could be prioritised, and each one came with a countermeasure. Working within a clear scope and reporting honestly were part of the method.