
Практические кейсы по информационной безопасности: развёртывание SIEM Wazuh и эксплуатация CVE-2021-41773
Second-year student, Institute of Computer Science and Cybersecurity, Peter the Great St. Petersburg Polytechnic University, field of study 10.03.01 «Information Security».
As part of the educational (introductory) practice at Positive Technologies JSC, two practical cases were completed. Below are their descriptions in the format of technical materials, without the formatting typical of an educational report.
The practical works were performed as part of a study group: Bandurko V. V., Usoltsev G. V., Ustyantsev A. S.
Deploying Wazuh, creating a custom detection rule, configuring an index template, connecting an agent, and building a visualization of attacks on the server.
Stack: Ubuntu Server, Wazuh (Server / Indexer / Dashboard), OpenSearch DSL, Wazuh XML rules.
Building the vulnerable Apache 2.4.49 from source code, reproducing Path Traversal with escalation to RCE, validating remediation measures, and analyzing why the first official patch did not fully close the vulnerability.
Stack: Apache HTTP Server, mod_cgid, curl, PowerShell.
In the original training reports, the screenshots contained the real IP address of the test server, the auto-generated administrator password, and the agent authentication key. Before publication, this data was removed from the images and replaced with placeholders in the text.