CD Skripsi
Analisis Celah Keamanan Dan Strategi Perbaikan Pada Website Universitas Riau
ABSTRACT
This thesis analyzes security vulnerabilities on the Riau University website, unri.ac.id, which is generally exposed to backdoor attacks, resulting in changes in content to online gambling sites. The research used the Google Dorking method to identify infected domains, such as psil.postgraduate.unri.ac.id and feb.unri.ac.id, which showed modification of index files by the attacker. This attack utilizes various vulnerabilities, including Remote Code Execution, Cross-Site Scripting, SQL Injection, Server-Side Request Forgery, Directory Traversal, and Authentication Bypass. For simulation, researchers built a replica WordPress website and embedded the backdoor in vulnerable directories such as wp-content, wp-includes, and public_html. Two remediation strategies were tested: blocking PHP execution using .htaccess files and automatic scanning with the Wordfence plugin. Results showed that PHP blocking effectively prevented backdoor execution in wp-content and wp-includes, while Wordfence successfully detected and repaired hidden backdoors in default files in public_html such as wp-activates. This research recommends a combination of .htaccess technical approaches, security plugins, and increased security awareness for backdoor mitigation. These findings can serve as a guide for educational institutions in securing Content Management System-based systems such as WordPress.
Keywords: Backdoor, Website Security, Google Dorking, WordPress, RCE, XSS,
SQL Injection, SSRF, Wordfence.
Tidak tersedia versi lain