Penetration Testing and Exploit Development Lab Series
University of Guelph · Jan 2026 – Apr 2026
A hands-on lab series covering exploit development, reconnaissance, vulnerability assessment, exploitation, post-exploitation, authentication attacks, man-in-the-middle simulation, and web application security testing in a controlled VM lab. Exploit Development Basics: used GDB to inspect vulnerable programs, analyze memory behavior, and understand buffer overflow/logic-bypass outcomes. Reconnaissance and Enumeration: Maltego, Nmap, and Wireshark for DNS enumeration, host discovery, OS detection, and packet capture analysis. Vulnerability Assessment: OpenVAS/GVM and Nessus scans against Windows targets, with before/after comparison across system and firewall changes. Exploitation and Post-Exploitation: privilege escalation, process migration, persistence testing, hash dumping, and event log analysis in Windows lab environments. Authentication Attacks: Metasploit/Meterpreter, Kiwi, Cain & Abel, John the Ripper, Hashcat, and Hydra. Network Attack Simulation: Ettercap for ARP poisoning, DNS spoofing, and traffic redirection. Web Application Security Testing: SQL injection, authentication bypass, UNION-based extraction, XSS, CSRF, and IDOR-style access-control weaknesses against vulnerable web applications.
Tools: Kali Linux, GDB, Maltego, Nmap, Wireshark, OpenVAS/GVM, Nessus, Metasploit/Meterpreter, Cain & Abel, John the Ripper, Hashcat, Hydra, Ettercap
Skills demonstrated: penetration testing methodology, exploit development fundamentals, network reconnaissance and enumeration, vulnerability scanning and assessment, post-exploitation technique, web application security testing (SQLi, XSS, CSRF, IDOR)