In this project I conducted research by running active scanners and cyber attacks on running versions of Drupal and Wordpress. I was able to document security vunlerabilities in a timeline to see severity as well as fixes that were applied in major releases. I conducted this project under the mentorship of Dr. Anthony Peruma of UH Manoa. However all security testing and documentation was done by me.
For a report that showcases more methodology and a summary of findings see this presentation: Security Vulnerabilities Across CMS Platforms
My role in this project encompassed running versions of CMS platforms locally and running tests on them. I accomplished this using Docker containerization of different CMS versions using pre-packaged images. I chose Zed Attack Proxy (ZAP) as the active tool to conduct testing on these systems. I used spiders and active attacks, then generated reports with ZAP to create findings.
This project showcases hands-on experience in cybersurity, vulnerability analysation, as well as containerization tools. As a developer with interest in the software and information technology fields, I found this project to be very helpful to see how poorly written code and old dependencies can cause serious security issues.