Academic Integrity: tutoring, explanations, and feedback — we don’t complete graded work or submit on a student’s behalf.

Attack Preparation: Search the web for two (2) local business websites (not nati

ID: 3874706 • Letter: A

Question

Attack Preparation: Search the web for two (2) local business websites (not national chains). Run a port scan on each of them. For each, determine which ones have HTTP, HTTPS, FTP, SMTP, SMTPS running. List these and any other interesting things you find in a few sentences for each web site. Use the web-based free port scanning software available at https://pentest-tools.com/network-vulnerability- (Note: If the link doesn't work for some reason, be resourceful That is, search Google for "Pentest port scan" and it should come right up) Once you have gathered this information, suggest potential security flaws that may be present on the server you scanned.

Explanation / Answer

As per the question requirement we are considering here two local business websites:

elocal.com: it is website to search requirement of your man help in your own locality. You need to provide the zip code / city and the need. And they will help you with your requirement. After the port scan through pentest-tool, we have come up with.

It’s using the service of HTTP, having port number 80 and 443. The service product is marked as nginx. It detects the operating system Linux. The host which is connected with it is also mentioned with the respective ip addresses.

Some of the security flaws can be considered as: security is misconfigured, sensitive data is been exposed.

go4worldbusiness.com: Again it is a trading website. It helps to find any specific services, where it can work both in terms of as a buyer or as a supplier.

It’s using the service of HTTP and ssh which is termed close state. Rests of them are in open state. Service product is of Apache httpd and service extra info is also provided with the specific language. Here it is a major flaw for the website. Again in this scan also all the connected host with its ip addresses are mentioned.