This repository presents a comprehensive Vulnerability Assessment and Penetration Testing (VAPT) project. It demonstrates a structured approach to identifying, analyzing, and mitigating security vulnerabilities within a target system using industry-standard tools and methodologies.
This task was completed as a part of my Vulnerability Assessment and Penetration Testing (VAPT) Internship at Cyart Technologies in March 2026.
- Perform end-to-end security assessment
- Identify vulnerabilities across multiple layers
- Demonstrate real-world exploitation techniques
- Provide effective remediation strategies
- Target: Web Application / Testing Environment
- Testing Type: Black-box / Grey-box
- Environment: Controlled and authorized setup
The assessment follows standard VAPT phases:
- 🔎 Reconnaissance
- 📡 Scanning & Enumeration
- 🧪 Vulnerability Analysis
- 💣 Exploitation
- 🔐 Post-Exploitation
- 📄 Reporting
- Nmap
- Burp Suite
- OpenVAS
- Nikto
- OWASP ZAP
- Multiple vulnerabilities identified (Low to High severity)
- Successful demonstration of exploitation techniques
- Detection of misconfigurations and insecure endpoints
- Chained vulnerabilities can significantly increase attack impact
- Proper configuration of tools is critical for accurate results
- Practical exposure to real-world attack methodologies
- Importance of risk prioritization and structured reporting
- Tool configuration and setup issues
- False positives in automated scanning tools
- Limited scope and environment constraints
- Implementation of input validation and sanitization
- Strengthening authentication and session management
- Secure server and application configurations
- Regular vulnerability assessments and patch management
This project highlights the importance of proactive security testing in modern systems. By following a structured VAPT methodology, it becomes possible to identify critical vulnerabilities, understand their impact, and apply effective remediation strategies to enhance overall system security.
This project is intended for educational purposes only. All testing activities were conducted in a controlled and authorized environment. Unauthorized testing on systems without permission is strictly prohibited.
Aditya Mehta
Cybersecurity Enthusiast