Module COS7029-B
Ethical Hacking
Dr Amna Qureshi
Lecturer in Cyber Security
Faculty of Engineering and Informatics
University of Bradford
1. Coursework Overview
The module will be assessed by:
• Practical work that includes assessment of students’ weekly lab work (2% of the
assessment) and assessment of students' broader understanding of the hacking
concepts through lab tests taken at regular intervals (3% of the assessment).
• Lab exam (25% of the assessment) to be taken in the last week of the semester.
• A portfolio of work on designing and documenting a set of penetration tests using
appropriate methods, techniques and tools within the ethical framework (70% of the
assessment).
The coursework of this includes compulsory tasks 1, 2 and 3 for academic credit. The marking
criteria of COS7029-B will reflect the level-7 of study of the submitted work. The main
objective of this module is to enable students to develop the competence and knowledge
required to conduct ethical hacking for the information systems of an organisation. The
students will learn how attackers attack computers and networks and protect information
systems and networks from such attacks. Students will perform many hands-on experiments
in weekly lab sessions that will expose them to advanced hacking tools and techniques used
by hackers and information security professionals to break into an organisation. The students
will be taught the following five phases of Ethical Hacking to scan, test, hack and secure target
systems:
• Phase 1: Reconnaissance
• Phase 2: Gaining Access
• Phase 3: Enumeration
• Phase 4: Maintaining Access
• Phase 5: Covering Your Tracks
Task 1: Continuous assessment of students’ knowledge
• Part A: Every week, students have a 3-hour lab session, where they do practical and
lab exercises on the TryHackMe platform. The lab exercises are designed in a way that
allows students to follow detailed instructions, learn about specific pen testing
techniques using different hacking tools, and answer questions with the obtained
results. Each week’s lab exercises are directly relevant to the topic covered in that
week’s lecture. Each exercise contains different tasks with varying numbers of
questions covering both theoretical concepts and practical usage. The lab manuals
containing step-by-step instructions are provided to students (available on CANVAS).
Students are required to complete the lab exercises within the lab sessions. Some
activities are given to be completed at home.
• Part B: A lab test is taken every 2/3 weeks to evaluate students’ understanding of
hacking concepts, pen testing techniques and tools learnt within those lab sessions.
Students are required to complete the test in 30 minutes. The TryHackMe platform
automatically marks students’ tests against the set marking criteria.
Task 2: Evaluation of students’ practical understanding
• A 3-hour lab exam based on the concepts covered in the lab exercises will be taken in
the final week of the module using the TryHackMe platform.
Task 3: Development of EH Portfolio
The third task is to develop a portfolio covering the key aspects of ethical hacking and
developing a penetration test to mitigate the vulnerabilities identified in either the
following web applications or any computing areas (network, application or software)
selected by students.
• Web applications:
o The Buggy Web Application - bWAPP: Some of the flaws in this application
are Cross-site scripting (XSS), DoS (denial-of-service) attacks, Man-in-the-
middle attacks, Server-side request forgery (SSRF), SQL injection, etc.
o Damn Vulnerable Web Application – DVWA: Some of the flaws in this
application are Brute-Force, Command Execution, XSS, SSRF, SQL injection,
etc.
o WebGoat: Some of the flaws in this application are Buffer overflows,
Improper error handling, Injection flaws, insecure communication and
configuration, etc.
• Websites:
o [Link]
o [Link]
o [Link]
o [Link]
This portfolio includes the following tasks:
1. Strategic Penetration Testing (50%)
i. The first task within this assessment requires performing strategic penetration
testing to demonstrate an understanding of the tools and methods used in the
pre-defined domain.
Domains
Reconnaissance/Scanning/Enumeration Brute Force Attacks
Vulnerability Analysis Kill Chains
System Hacking Hacking Web Servers
Malware Analysis Session Hijacking
SQL Injection Hacking Mobile Platforms
DoS/DDoS Attacks IoT Hacking
Hacking Wireless Networks Hacking Web Applications
Sniffing Operational Technology Hacking
The students can choose 2 domains for their portfolio. For each chosen domain, they have
to provide a detailed description of vulnerabilities and provide evidence of how the
identified vulnerabilities might be exploited through well-labelled figures (obtained via
pen tests).
ii. In the second task, you will discuss the mitigation techniques applied to protect the
information system against the “Strategic Penetration Tests”. The students are
required to evaluate the effectiveness of these techniques by using the results
produced from pen tests as evidence for their discussion. The students are required
to provide reasoning for choices with underlying research.
Students can use the TryHackMe platform, or a virtual machine installed in their computers
(with Kali, Parrot, or any LINUX distribution and Windows OSs) to perform pen tests.
The students are required to use academic references to support discussion (where
appropriate).
2. Bug Bounty (50%)
You are tasked with conducting an ethical hacking assessment on one of the given Bug Bounty
Platforms:
o HackerOne
o Intigriti
o Open Bug Bounty
o Google Dorking
o Synack
o Cobalt
o Hackrate
o Bugcrowd
o Huntr
As a cybersecurity student with expertise in ethical hacking and penetration testing, you are
responsible for carrying out the following tasks:
1. Identify a target:
o Research about the chosen target:
▪ Understand the functionality of the target.
2. Reconnaissance:
o Conduct active and passive reconnaissance on your target.
o Document any useful information that could be used in later stages.
3. Vulnerability Assessment:
o Use a combination of manual testing and automated scanning tools to scan for
vulnerabilities.
o Identify and prioritise potential vulnerabilities based on their severity and impact on
the application's security using any threat model.
4. Exploitation:
o Plan the attack based on the information gathered from the previous stages.
o Execute the attack.
o Document the results and any evidence of the attack.
5. Ethical Considerations:
o Discuss the importance of ethical considerations and responsible disclosure when
participating in bug bounty programs. How would you ensure that your actions adhere
to ethical guidelines?
6. Reporting:
o Write a detailed report about the vulnerability you exploited.
o What vulnerability did you find, and how did you find it?
o How did you exploit the vulnerability?
o The impact of the vulnerability.
o Suggested mitigation measures.
Instructions for Submission of Portfolio:
• The portfolio should be written on A4, double-spaced, with normal margins.
• The title should be on the front page with the student’s name, UB number and
programme of study.
• A Table of Contents page should be included.
• Pages and sections should be numbered.
• Appendices can be used where appropriate.
• Your work will be submitted via Turnitin on submission.
• Your work must be your own work. If your work is found to be authored by another
person, it will be investigated!
• The portfolio should be properly referenced using the Harvard referencing style.
• The final date to submit the Portfolio is 10th May by 16:00 via CANVAS. Failure to meet
this deadline will result in a mark of zero being awarded for this part of the assessment
(as per University of Bradford Regulations).
Summary:
External examiners rigorously review the complete assessment documentation to ensure that
each aligns with the QAA and the Framework for Higher Education Qualification (FHEQ)
guidelines and other similar programs in other institutions. The FHEQ Framework identifies
what students must achieve if they are to receive a qualification at Level 7 (Master’s
Qualification). The pass mark at the University of Bradford is 40%, and to achieve a pass, all
students must demonstrate the skills outlined by the FHEQ if they are to be awarded a degree
at this level.
Students undertake the work for this module via 11 weeks of study. There are 1 hour of
tutorials per week (11 hours in total) and 3 hours of practical classes (33 hours in total).
Furthermore, students are expected to do a further 156 hours of private independent study.
Marking criteria:
• Task 1:
o TryHackMe platform’s dashboard is used to record students’ lab participation. In
order to obtain a mark for the lab exercise, students are required to complete
each question given in separate tasks of the lab exercise. Students receive 1 point
for completing all lab exercises each week.
o The TryHackMe platform’s dashboard is used to record students’ test and exam
results.
▪ Students receive 4.75 points for each lab test completed with all correct
answers. Students with partially completed tests receive marks
between 0.5 – 4.5.
• Task 2:
o The lab exam will consist of five activities that cover various topics of ethical
hacking. Students will earn five points for each activity with all correct answers.
• Marking criteria of Task 3:
o Task 3 is assessed via the “EH Portfolio Marking [Link]” provided as a
separate document.