“These courses expects a high standard of professionalism from its students with regard to how security testing is conducted. We expect all students to act in good faith at all times […]”
TL;DR Don’t be mean
How are you finding the challenges?

There are bonus marks available for this course.
Free Credits
‘Example’ report * cough *
authentication!= authorisation
SMS isn’t a very secure system…
(at all)
Website that use 2FA SMS are bad.
But other 2FA methods can be inconvenient…
inconvenient ~= sorta safer…
Last week: DNS recon
DNS recon isn’t the only way of reconnaissance…

You don’t see everything that your browser receives!
⚠️ Warning ⚠️
Write your own enumeration script!
Demo: A basic GET/POST repeater
Word List? github:danielmiessler/SecLists
Some automated tools…
again. pls pls plssss rate limit
Just a note…
“N.B. Both sub-domain enumeration and sub-directory brute-forcing are discouraged and will not assist you in these challenges. However, you may be find it useful to enumerate IDs or passwords."
Source: Topic 2 Challenge Outline
10 minutes to create a 3-5 presentation
- what, why, how, etc -
Topics
(This doesn’t count towards bonus marks btw)