Analisis Keamanan Website E-Pinter terhadap Serangan SQL Injection dan XSS

Manuel, Josua Karlos (2025) Analisis Keamanan Website E-Pinter terhadap Serangan SQL Injection dan XSS. Other thesis, Politeknik Negeri Bengkalis.

[thumbnail of Abstract] Text (Abstract)
1. TA-6404211060-Abstract.pdf - Submitted Version
Available under License Creative Commons Attribution Share Alike.

Download (8kB)
[thumbnail of Bab I Pendahuluan] Text (Bab I Pendahuluan)
2. TA-6404211060-Bab I Pendahuluan.pdf - Submitted Version
Available under License Creative Commons Attribution Share Alike.

Download (24kB)
[thumbnail of Daftar Pustaka] Text (Daftar Pustaka)
3. TA-6404211060-Daftar Pustaka.pdf - Submitted Version
Available under License Creative Commons Attribution Share Alike.

Download (10kB)
[thumbnail of Full Text] Text (Full Text)
4. TA-6404211060-Full Text447.pdf - Submitted Version
Restricted to Registered users only
Available under License Creative Commons Attribution Share Alike.

Download (2MB) | Request a copy

Abstract

Website security is a crucial component in maintaining the integrity, confidentiality, and availability of data against various cyber threats. E-Pinter, which serves as an online licensing service platform, is potentially vulnerable to SQL Injection and Cross-Site Scripting (XSS) attacks that could compromise the system and the information stored within it. This study aims to evaluate the security level of the E-Pinter website against these two types of attacks. The methodology includes both manual and automated testing using penetration tools to identify security vulnerabilities. SQL Injection testing is conducted by injecting various payloads into input parameters to assess the possibility of database manipulation, while XSS testing involves inserting malicious scripts into unvalidated inputs to evaluate the potential exploitation of the user interface. The test results reveal several vulnerabilities that could be exploited by attackers, posing risks of data breaches and system disruptions. As a mitigation measure, this study recommends implementing prepared statements to prevent SQL Injection attacks and using the htmlspecialchars() function to counteract XSS attacks. The implementation of these strategies is expected to enhance the security of the E-Pinter website, protect user data, and reduce the risk of future exploitation.

Item Type: Thesis (Other)
Uncontrolled Keywords: SQL Injection, Cross-Site Scripting, Website Security, Penetration Testing
Subjects: 000 – UMUM, ILMU KOMPUTER, DAN INFORMASI > 005 – Pemrograman, Perangkat Lunak > 005.8 Keamanan dan Perlindungan Sistem
Divisions: Jurusan Teknik Informatika > Sarjana Terapan (D-IV) Keamanan Sistem Informasi > SKRIPSI
Depositing User: D-IV Keamanan Sistem Informasi Kelas B
Date Deposited: 22 Aug 2025 02:27
Last Modified: 22 Aug 2025 02:27
URI: https://eprints.polbeng.ac.id/id/eprint/2611

Actions (login required)

View Item
View Item