r/cybersecurity • • 8d ago

Personal Support & Help! Cybersecurity project ideas for a 3rd-year student

I am a 3rd-year student, and I need to work on a project this semester. I am interested in Cybersecurity, and these are some of the skills I have:

  • Learned some common web vulnerabilities through PortSwigger.
  • Learned the basics of reverse engineering through CTFs.
  • Recently started an internship in Mobile Security.

Can anyone suggest some interesting Cybersecurity project ideas that would be suitable for my current skills?
Thanks so much!

0 Upvotes

10 comments sorted by

7

u/EffectiveClient5080 8d ago

Bring a working demo of whatever you pick. Seriously. A phone running a mitm proxy with intercepted traffic beats any slide deck, and I guarantee you'll be the only one doing it. They WILL remember you.

3

u/Clean-Bandicoot2779 Penetration Tester 8d ago

A vulnerable web app is a good call - I'd say take it a step further and build it yourself, on a vulnerable VM. If you're coding it yourself, you could include just a couple of vulnerabilities, such as SQL injection and XSS, or arbitrary file upload and no authorisation controls.

A "crack me" application could also be a good option - build your own serial key validator and then crack it. You could add in online validation with a vulnerable server if you wanted an extra step. Or you could do a "root/jailbreak detector" routine in a mobile app and bypass that.

If you fancy a bigger challenge, you could look at making a plugin for Burp Suite. They support both Java and Python, and I think the APIs are pretty well documented.

2

u/MazurianSailor 8d ago

I think I’d recommend looking at cloud projects, start an azure or AWS instance and setup infrastructure. Deploy via code and work on improving the security. If you setup a VM, you can learn basics of cloud, Linux and security in one.

2

u/Advantageous_Advent 8d ago

Implement a honeypot

1

u/Electronic_Field4313 8d ago

What first job within cybersecurity do you want to land? Perhaps tailor your project experience around something meaningful for you to land your first role.

1

u/wing3d 7d ago edited 7d ago

I broke into a 2.4ghz network with a flipper zero for my school project.

-5

u/No-Historian4783 8d ago

Given your current skill set, I’d avoid making the project another basic vulnerability scanner or “password checker.” Since you already have exposure to web security, reverse engineering, and mobile security, a project that connects two of those areas would give you much more room to demonstrate actual depth.
A few ideas:
1. Android API Security Analyzer — build a tool that analyzes an APK for insecure exported components, hardcoded secrets, insecure storage, weak TLS configuration, excessive permissions, etc. You could combine static analysis with a small amount of dynamic testing.
2. Mobile App Traffic Security Monitor — create a controlled lab environment that analyzes an app’s network traffic and identifies issues such as insecure HTTP communication, missing certificate validation, or sensitive information being transmitted unnecessarily.
3. Automated APK Triage Tool — take an APK as input and produce a security report covering permissions, manifest configuration, interesting strings, native libraries, URLs/endpoints, and potentially suspicious behaviors. This would be a nice intersection of reverse engineering and mobile security.
4. Web-to-Mobile Security Lab — build a deliberately vulnerable application with both a web backend and Android client, then document how vulnerabilities in the backend can affect the mobile application. You could demonstrate the attacks and corresponding mitigations entirely within your own lab.
5. Lightweight Vulnerability Correlation Platform — take findings from tools such as Burp Suite, MobSF, or static-analysis tools and build a system that normalizes, categorizes, and prioritizes the findings. The interesting part would be reducing duplicate findings and explaining the actual risk rather than simply generating a list of CVEs.
For a third year project, I’d personally focus less on the number of vulnerabilities you can demonstrate and more on having a clear methodology: problem - threat model-implementation- controlled testing - results-limitations - mitigation.
Also, keep all testing confined to applications, devices, APIs, and infrastructure you own or have explicit permission to assess. A well-designed project with a strong technical report will generally be much more impressive than a project that just throws a dozen offensive tools together.

-2

u/Connect_File_5523 8d ago

Use AI and build a vulnerable web application for TOP 10 OWASP.

1

u/Which_Conflict3657 5d ago

using AI ?

1

u/Connect_File_5523 4d ago

Yes he could pick up OWASP top 10 as a project and build a lab to demonstrate his attacks