PENGUJIAN CELAH KEAMANAN WEBSITE MENGGUNAKAN TEKNIK PENETRATION TESTING DENGAN METODE OWASP (STUDI KASUS : WEBSITE RAPOR ONLINE SMP MUHAMMADIYAH 1 MALANG)

Fandy, Adilla Ihza (2024) PENGUJIAN CELAH KEAMANAN WEBSITE MENGGUNAKAN TEKNIK PENETRATION TESTING DENGAN METODE OWASP (STUDI KASUS : WEBSITE RAPOR ONLINE SMP MUHAMMADIYAH 1 MALANG). Undergraduate thesis, Universitas Muhammadiyah Malang.

[thumbnail of PENDAHULUAN.pdf]
Preview
Text
PENDAHULUAN.pdf

Download (1MB) | Preview
[thumbnail of BAB I.pdf] Text
BAB I.pdf
Restricted to Registered users only

Download (121kB) | Request a copy
[thumbnail of BAB II.pdf] Text
BAB II.pdf
Restricted to Registered users only

Download (1MB) | Request a copy
[thumbnail of BAB III.pdf] Text
BAB III.pdf
Restricted to Registered users only

Download (211kB) | Request a copy
[thumbnail of BAB IV.pdf] Text
BAB IV.pdf
Restricted to Registered users only

Download (1MB) | Request a copy
[thumbnail of BAB V.pdf] Text
BAB V.pdf
Restricted to Registered users only

Download (119kB) | Request a copy
[thumbnail of LAMPIRAN.pdf] Text
LAMPIRAN.pdf
Restricted to Registered users only

Download (241kB) | Request a copy
[thumbnail of POSTER.pdf] Text
POSTER.pdf
Restricted to Registered users only

Download (4MB) | Request a copy

Abstract

Along with technological advances, the importance of security for a website is the main thing because if security is ignored, it allows data theft or changes the appearance of a website. This research aims to test the security gap on the Online Report Card website of SMP Muhammadiyah 1 Malang using penetration testing techniques with the OWASP TOP 10 method. Researchers detect security gaps using the OWASP TOP 10 version 2021 method on the target website. After detection, then test the vulnerabilities that have been found, whether the vulnerabilities found can be exploited or not. Researchers tried to conduct further tests because it was confirmed that the error message referred to the SQL Injection vulnerability, researchers tried to dump the database and related information on the MySQL service. There is a Security Misconfiguration vulnerability in the system that can be accessed, in this case the lack of handlers in the system configuration has an impact on errors in the system when making requests. Overall, a systematic process of identifying assets, detecting vulnerabilities, and testing exploits based on previous results was conducted. The main findings are included in the OWASP Top 10 category so they need attention for system security improvements.

Item Type: Thesis (Undergraduate)
Student ID: 201910370311060
Keywords: Penetration Testing, OWASP, Website, SQL Injection
Subjects: T Technology > T Technology (General)
Divisions: Faculty of Engineering > Department of Informatics (55201)
Depositing User: 201910370311060 adillaihzafandy
Date Deposited: 24 Oct 2024 10:33
Last Modified: 25 Oct 2024 03:08
URI: https://eprints.umm.ac.id/id/eprint/11704

Actions (login required)

View Item
View Item