Internship Final Report
Student Name: AKASH SANJAY SK
University: SRM INSTITUTE OF SCIENCE AND TECHNOLOGY RAMAPURAM, CHENNAI
Major: [Link](cse specialization with cyber security
Internship Duration: February 1st to February 28th
Company: ShadowFox
Domain: Cyber Security
Mentor: Mr. Surendharan
Assistant Mentor: Mr. Pranshu
Coordinator: Mr. Aakash
Objectives:
The primary objective of this internship at ShadowFox was to gain practical, hands-on
experience in various domains of cybersecurity. The program aimed to transition the
intern from foundational concepts to advanced penetration testing techniques. Key
goals included:
Mastering network reconnaissance and traffic analysis.
Understanding and executing web application vulnerability assessments, such as
directory brute-forcing.
Developing proficiency in digital forensics tools like VeraCrypt and PE Explorer.
Simulating real-world exploitation scenarios and privilege escalation using
industry-standard platforms like Metasploit and TryHackMe
Tasks and Responsibilities:
The internship was structured into three levels, each with specific technical responsibilities:
Beginner Level (Network & Web Basics): Identifying open ports on target websites using
Nmap, performing directory brute-forcing with Dirb, and intercepting login credentials via
Wireshark.
Intermediate Level (Forensics & Exploitation): Decrypting files by cracking MD5 hashes,
using PE Explorer to identify executable entry points, and creating reverse shell
payloads with Metasploit.
Advanced Level (Penetration Testing): Completing the Basic Pentesting Room on
TryHackMe, which involved full-chain exploitation: reconnaissance, enumeration
(SMB/HTTP), brute-forcing SSH, and performing privilege escalation to root
Learning Outcomes:
Through the completion of these tasks, the intern achieved several key competencies:
Reconnaissance & Enumeration: Learned to use Nmap, Gobuster, and Enum4linux to
map attack surfaces.
Vulnerability Exploitation: Gained the ability to generate and deploy payloads using
msfvenom and catch connections with multi-handler.
Forensics & Cracking: Acquired skills in identifying file headers with PE Explorer and
cracking password-protected SSH keys using John the Ripper and the [Link]
wordlist.
Professional Reporting: Developed the ability to document technical processes, from
initial scans to final flags, in a detailed penetration testing report
Challenges and Solutions:
[Link]: Encountering password-protected SSH private keys during penetration testing.
Solution: Utilized [Link] to convert the key into a crackable format and successfully
recovered the password (beeswax) using John the Ripper.
2. Challenge: Bypassing security software while executing reverse shells.
Solution: Identified the need to disable antivirus/Windows Defender in a controlled lab
environment for testing purposes to ensure the Meterpreter session could be
established.
[Link]: Restricted access to files due to incorrect permissions.
Solution: Applied the chmod 400 command to secure the private key file, satisfying SSH
security requirements for authentication
Conclusion:
The internship successfully provided a comprehensive overview of the cybersecurity landscape.
By progressing through beginner to advanced tasks, the intern demonstrated the ability to
identify, exploit, and document various security vulnerabilities. The culmination of the program
with a Jr. Penetration Tester certificate from TryHackMe confirms the intern’s readiness to
pursue a professional career in cybersecurity and penetration testing.
Acknowledgments:
The intern acknowledges the guidance and support provided by the ShadowFox team during
the February 2026 B1 batch. Special thanks are extended to:
Mentor: Mr. Surendharan.
Assistant Mentor: Mr. Pranshu.
Coordinator: Mr. Aakash.