格林学校高中网站安全检测使用Owasp方法进行XSS测试

Putri Charly, Kadek Erik Diatmika, I. Prayoga, I. Listartha
{"title":"格林学校高中网站安全检测使用Owasp方法进行XSS测试","authors":"Putri Charly, Kadek Erik Diatmika, I. Prayoga, I. Listartha","doi":"10.22441/10.22441/format.2022.v11.i1.008","DOIUrl":null,"url":null,"abstract":"Information security is an important thing that must be considered for every individual and agency, because if information can accessed by unauthorized people then accuracy of the information can be doubted, becoming misleading information and even various problems will be found.  Such problems can be malware attacks, exploits, or database injections. In this study, the mechanism of risk assessment methods was carried out on the website information system of greenschool high school. As the name implies XSS or stands for Cross Site Scripting is one form of interference in the form of Code Injection Attack or code injection attack. Where attackers or outsiders insert malicious code that is usually in the form of Javascript. This’s because the main purpose of using XSS is to retrieve important data and send a program that can damage the user but as if the cause is from the web itself. Web security solutions from hacker interference or attacks can be done by means of self-test, namely testing conducted on the web legally with activities such as hackers. Therefore, an analysis of the vulnerability of  system that refers to the standardization of open web application security project (OWASP) security with combination of several security tools.","PeriodicalId":381291,"journal":{"name":"Format : Jurnal Ilmiah Teknik Informatika","volume":"34 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-02-09","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Pendeteksian Keamanan Website SMA Greenschool Menggunakan Metode Owasp dengan Pengujian XSS\",\"authors\":\"Putri Charly, Kadek Erik Diatmika, I. Prayoga, I. Listartha\",\"doi\":\"10.22441/10.22441/format.2022.v11.i1.008\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Information security is an important thing that must be considered for every individual and agency, because if information can accessed by unauthorized people then accuracy of the information can be doubted, becoming misleading information and even various problems will be found.  Such problems can be malware attacks, exploits, or database injections. In this study, the mechanism of risk assessment methods was carried out on the website information system of greenschool high school. As the name implies XSS or stands for Cross Site Scripting is one form of interference in the form of Code Injection Attack or code injection attack. Where attackers or outsiders insert malicious code that is usually in the form of Javascript. This’s because the main purpose of using XSS is to retrieve important data and send a program that can damage the user but as if the cause is from the web itself. Web security solutions from hacker interference or attacks can be done by means of self-test, namely testing conducted on the web legally with activities such as hackers. Therefore, an analysis of the vulnerability of  system that refers to the standardization of open web application security project (OWASP) security with combination of several security tools.\",\"PeriodicalId\":381291,\"journal\":{\"name\":\"Format : Jurnal Ilmiah Teknik Informatika\",\"volume\":\"34 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2022-02-09\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Format : Jurnal Ilmiah Teknik Informatika\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.22441/10.22441/format.2022.v11.i1.008\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Format : Jurnal Ilmiah Teknik Informatika","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.22441/10.22441/format.2022.v11.i1.008","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

摘要

信息安全是每个个人和机构必须考虑的一件重要的事情,因为如果信息可以被未经授权的人访问,那么信息的准确性就会受到怀疑,成为误导信息,甚至会发现各种问题。这些问题可能是恶意软件攻击、漏洞利用或数据库注入。本研究在绿校高中网站信息系统上进行了风险评估方法的机制研究。顾名思义,XSS或跨站脚本是代码注入攻击或代码注入攻击形式的一种干扰形式。攻击者或外部人员通常以Javascript的形式插入恶意代码。这是因为使用XSS的主要目的是检索重要数据并发送可能损害用户的程序,但似乎原因是来自web本身。Web安全解决方案不受黑客干扰或攻击,可以通过自测的方式来解决,即在网络上合法地进行黑客等活动的测试。因此,分析系统的漏洞,指的是将开放式web应用程序安全项目(OWASP)的安全标准化与几种安全工具相结合。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
Pendeteksian Keamanan Website SMA Greenschool Menggunakan Metode Owasp dengan Pengujian XSS
Information security is an important thing that must be considered for every individual and agency, because if information can accessed by unauthorized people then accuracy of the information can be doubted, becoming misleading information and even various problems will be found.  Such problems can be malware attacks, exploits, or database injections. In this study, the mechanism of risk assessment methods was carried out on the website information system of greenschool high school. As the name implies XSS or stands for Cross Site Scripting is one form of interference in the form of Code Injection Attack or code injection attack. Where attackers or outsiders insert malicious code that is usually in the form of Javascript. This’s because the main purpose of using XSS is to retrieve important data and send a program that can damage the user but as if the cause is from the web itself. Web security solutions from hacker interference or attacks can be done by means of self-test, namely testing conducted on the web legally with activities such as hackers. Therefore, an analysis of the vulnerability of  system that refers to the standardization of open web application security project (OWASP) security with combination of several security tools.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Analisis Fitur Pada Citra Gestur Tangan Sistem Isyarat Bahasa Indonesia Emotional Text Detection dengan Long Short Term Memory (LSTM) Penerapan Metode Cosine Similarity Dalam Mendeteksi Plagiarisme Pada Jurnal Implementasi Algoritma Searching Untuk Pencarian Produk dan SMTP Sistem Pengiriman Email pada Toko Ono Celluler Optimalisasi Overload Traffic Dan Request Cloud Environment Menggunakan Metode Content Delivery Network Dan Private Zone Di RCTI+
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1