Dirgantara, Rimba (2024) Uji Penetrasi Keamanan Website Dinas Komunikasi Dan Informatika. Other thesis, Politeknik Negeri Bengkalis.
![[thumbnail of Abstract]](https://eprints.polbeng.ac.id/style/images/fileicons/text.png)
SK-6404211035-Abstract.pdf - Submitted Version
Available under License Creative Commons Attribution Share Alike.
Download (255kB)
![[thumbnail of Bab 1 Pendahuluan]](https://eprints.polbeng.ac.id/style/images/fileicons/text.png)
SK-6404211035-Bab 1 Pendahuluan.pdf - Submitted Version
Available under License Creative Commons Attribution Share Alike.
Download (295kB)
![[thumbnail of Daftar Pustaka]](https://eprints.polbeng.ac.id/style/images/fileicons/text.png)
SK-6404211035-Daftar Pustaka.pdf - Submitted Version
Available under License Creative Commons Attribution Share Alike.
Download (191kB)
![[thumbnail of Full Text]](https://eprints.polbeng.ac.id/style/images/fileicons/text.png)
SK-6404211035-Full Text.pdf - Submitted Version
Restricted to Registered users only
Available under License Creative Commons Attribution Share Alike.
Download (3MB) | Request a copy
Abstract
The official website of the Department of Communication and Informatics of XYZ Regency serves as a medium for publication, interaction, and promotion of regional potential. This website plays a crucial role in disseminating government information to the public. However, its vulnerability to attacks such as SQL Injection, Brute Force, Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), and Distributed Denial of Service (DDoS) poses threats to data integrity and service availability. This research aims to identify security loopholes through automated and manual attacks. The results show that SQL Injection successfully extracted data, while Brute Force failed to obtain valid credentials. Existing protections were effective in preventing XSS and CSRF attacks. The DDoS attack had no significant impact due to mitigation services in place. Security recommendations include input validation and sanitization, the use of Query Builder and prepared statements, framework updates, as well as implementing CAPTCHA and login attempt restrictions. For real-time attack detection and response, Snort is recommended as an Intrusion Detection System (IDS). This study is expected to raise awareness of the importance of website security and provide practical measures to reduce the risk of attacks on the official website of the Department of Communication and Informatics of XYZ Regency.
Item Type: | Thesis (Other) |
---|---|
Uncontrolled Keywords: | Penetration testing, Website security, SQL Injection, Brute Force, XSS, CSRF, Snort, Intrusion Detection System |
Subjects: | 000 – UMUM, ILMU KOMPUTER, DAN INFORMASI > 005 – Pemrograman, Perangkat Lunak > 005.8 Keamanan dan Perlindungan Sistem |
Divisions: | Jurusan Teknik Informatika > Sarjana Terapan (D-IV) Keamanan Sistem Informasi > SKRIPSI |
Depositing User: | D-IV Keamanan Sistem Informasi Kelas A |
Date Deposited: | 15 Jul 2025 04:44 |
Last Modified: | 15 Jul 2025 04:44 |
URI: | https://eprints.polbeng.ac.id/id/eprint/634 |