Find projects

Discover and match with projects from real companies

Agora Tutoring
Edmonton, Alberta, Canada
Dylan Zingle
Founder
(40)
6
Project
Academic experience
60 hours of work total
Learner
Anywhere
Intermediate level

Project scope

Categories
Cloud technologies Website development Security (cybersecurity and IT security) Software development Databases
Skills
cryptography code review nosql multi-factor authentication server-side role-based access control (rbac) authorization (computing) algorithms encryption mongodb
Details

Project Overview

This project is designed to help Agora Tutoring improve its cybersecurity posture by addressing key vulnerabilities identified in a recent security assessment. Students will work to evaluate, recommend, and implement specific repairs in alignment with the OWASP Top 10 vulnerabilities, enhancing Agora's ability to protect sensitive data and prevent unauthorized access.

Project Goal

The main objective of this project is to guide students through real-world cybersecurity repair processes, focusing on areas like access control, cryptography, injection prevention, and logging. By the end of this project, students will have contributed to a safer and more robust platform for Agora Tutoring.

Deliverables

Project Tasks and Activities

1. Broken Access Control

  • Issues: Insufficient role-based access controls allow unauthorized access to sensitive data.
  • Repairs: Implement stricter role-based access controls (RBAC), enforce mandatory access verification, and audit access logs for unauthorized attempts.

2. Cryptographic Failures

  • Issues: Weak encryption practices, such as insecure algorithms or poor key management, could lead to data breaches.
  • Repairs: Upgrade to secure encryption standards, ensure encryption for data in transit and at rest, and implement strong key management practices.

3. Injection Attacks

  • Issues: Susceptibility to SQL, NoSQL, and other injection attacks through unsecured data inputs.
  • Repairs: Use parameterized queries, sanitize inputs, and conduct regular code reviews to prevent injection vulnerabilities.

4. Security Misconfiguration

  • Issues: Misconfigured servers, default passwords, and exposed configurations increase risk.
  • Repairs: Securely configure all servers, update default settings, restrict unnecessary features, and automate security patching.

5. Vulnerable and Outdated Components

  • Issues: Use of outdated or unsupported third-party libraries and dependencies.
  • Repairs: Regularly update libraries, use dependency-checking tools, and establish an upgrade policy for critical dependencies.

6. Identification and Authentication Failures

  • Issues: Weak authentication mechanisms, including lack of multi-factor authentication (MFA).
  • Repairs: Implement MFA, enforce password complexity requirements, enable session timeouts, and set account lockouts after failed login attempts.

7. Software and Data Integrity Failures

  • Issues: No integrity checks for software updates, increasing risk of tampered code.
  • Repairs: Use hashing for data integrity, verify software updates, and apply secure CI/CD processes.

8. Security Logging and Monitoring Failures

  • Issues: Insufficient logging of security events, leading to delayed incident detection.
  • Repairs: Enhance logging for custom events, automate alerting, and establish regular log reviews to detect suspicious activities.

9. Insecure Design

  • Issues: Lack of secure design practices, such as threat modeling, leading to overlooked security weaknesses.
  • Repairs: Adopt a secure SDLC with built-in threat modeling and regular security assessments in the design phase.

10. Cross-Domain JavaScript Source File Inclusion

  • Issues: Inclusion of third-party JavaScript files from external sources, which may introduce malicious code.
  • Repairs: Apply Subresource Integrity (SRI) checks, download critical scripts to local servers, and minimize third-party dependencies.

11. Console Logging of Sensitive Information

  • Issues: Console logs reveal sensitive information that can aid attackers.
  • Repairs: Remove sensitive information from logs, avoid console.log() in production, and enforce logging policies to protect data.

12. Insufficient Logging for Custom Events

  • Issues: Missing detailed logs for custom events like changes in user roles, authentication settings, and critical system activities.
  • Repairs: Expand logging for key events and monitor authentication and authorization activities to track unusual patterns.

13. Server-Side Request Forgery (SSRF)

  • Issues: SSRF vulnerabilities could allow attackers to manipulate server requests to gain unauthorized internal access.
  • Repairs: Validate and restrict URLs or server requests, employ network segmentation, and use firewalls to prevent unauthorized internal access.

14. Backup and Data Recovery

  • Issues: Insufficient backup strategy for critical databases (e.g., MongoDB), risking data loss.
  • Repairs: Implement regular, automated backups with verification checks, store backups securely, and routinely test recovery processes.


Mentorship
Domain expertise and knowledge

Providing specialized, in-depth knowledge and general industry insights for a comprehensive understanding.

Tools and/or resources

Providing access to necessary tools, software, and resources required for project completion.

Regular meetings

Scheduled check-ins to discuss progress, address challenges, and provide feedback.

Supported causes

The global challenges this project addresses, aligning with the United Nations Sustainable Development Goals (SDGs). Learn more about all 17 SDGs here.

Quality education

About the company

Company
Edmonton, Alberta, Canada
2 - 10 employees
Academic association, Education, Technology
Representation
Small Business Social Enterprise Community-Focused

Executive Summary:
Agora Tutoring is an online marketplace akin to Kijiji, equipped with a map function similar to Uber, specializing in connecting students with local tutors for in-person educational sessions.

Company Overview:
Agora Tutoring is an online dedicated platform that connects students with local tutors for in-person educational sessions. By focusing exclusively on face-to-face interactions, Agora Tutoring aims to foster a more personalized and effective learning experience. The platform serves as a bridge between students seeking tailored educational support and independent tutors looking for meaningful teaching opportunities in their local areas.

Services:
Agora Tutoring provides a user-friendly web platform where students can search for and connect with tutors across a variety of subjects and educational levels. The service is designed to facilitate in-person tutoring engagements, enabling direct interaction and hands-on learning that virtual platforms cannot replicate.

Business Model:
Agora operates on a subscription-based model where users pay a monthly fee to access the platform and connect with tutors. Tutors, as independent contractors, set their own rates and schedules by connecting through Agora Tutoring. This model ensures a steady revenue stream for the platform while also providing tutors with a consistent flow of potential students.

Target Market:
The platform primarily targets students at all academic levels who prefer or require in-person tutoring to achieve their educational goals. This includes K-12 students, college students, and adult learners seeking professional development or personal enrichment in specific subjects. Parents looking for reliable and accessible tutors for their children are also a key demographic.

Strategic Goals:
Agora Tutoring aims to become the leading provider of in-person tutoring services within local communities. Strategic objectives include expanding its user base, increasing the number of tutors on the platform, and enhancing the overall user experience with features that make scheduling and session management more efficient for both students and tutors.

Competitive Advantage:
Agora Tutoring’s commitment to exclusively in-person tutoring sessions sets it apart in an era where virtual platforms are prevalent. This focus on local, face-to-face interactions not only improves learning outcomes but also builds a sense of community and trust among users. Additionally, the subscription model offers users unlimited access to potential tutoring, providing flexibility and value that single-session fees cannot match.

Business strategy
Communications
Competitive analysis
Market expansion
Market research
Operations
Product management
Product or service launch
Project management
Sales strategy
Computer science & IT
Artificial intelligence
Cloud technologies
Databases
Hardware
Information technology
Machine learning
Mobile app development
Networking
Security (cybersecurity and IT security)
Software development
Website development
Data
Data analysis
Data modelling
Data science
Data visualization
Design & creative
Architecture & design
Branding & style guides
Fashion design
Graphic design
Illustration
Interior design
UI design
UX design
Videography
Engineering & manufacturing
Chemical engineering
Civil engineering
Electrical engineering
Engineering project management
Hardware product design
Mechanical engineering
Robotics
Supply chain optimization
Finance
Accounting
Economics
Financial modeling
Financial services
Investment
Risk, audit and compliance
Human resources
Change management
Compensation analysis
Employee benefits
Employee retention
Internal communications
Leadership
Organizational structure
Talent recruitment
Training & development
Workplace culture
Workplace health/wellness
Marketing
Advertising
Customer segmentation
Digital marketing
Lead generation
Marketing analytics
Marketing strategy
Public relations
Search engine optimization
Medicine & health
Biotechnology
Healthcare
Public health
Social impact
Writing
Copy writing
Creative writing
Grant writing
Translation
Other
Education
Gender studies
History
Hospitality, tourism & culinary arts
Humanities
Law and policy
Media
Scientific research
Visual arts
Beginner
Intermediate
Advanced
Very flexible
Moderately flexible
Not flexible
No poverty
Zero hunger
Good health and well-being
Quality education
Gender equality
Clean water and sanitation
Affordable and clean energy
Decent work and economic growth
Industry, innovation and infrastructure
Reduced inequalities
Sustainable cities and communities
Responsible consumption and production
Climate action
Life below water
Life on land
Peace, justice and strong institutions
Partnerships for the goals
0 - 1 employees
2 - 10 employees
11 - 50 employees
51 - 200 employees
201 - 500 employees
501 - 999 employees
1000+ employees
advanced manufacturing
academic association
agriculture
airlines, aviation & aerospace
apparel & fashion
arts
automotive
banking & finance
business & management
business services
construction, engineering & trades
consumer goods & services
cosmetics & beauty
defense & security
education
energy
entertainment
environment
events services
food & beverage
government
hospitality
hospital, health, wellness & medical
human resources & recruitment
individual & family services
insurance
it & computing
legal
liquor, wine & spirits
manufacturing
marketing & advertising
media & production
mining, forestry & fishery
non-profit, philanthropic & civil society
public relations & communications
publishing & printing
real estate
retail
sales
science
sports & fitness
technology
telecommunications
trade & international business
transport, trucking & railroad
travel & tourism
clean technology
Any
English
French (Canada)
Yes
No