The Experts below are selected from a list of 60 Experts worldwide ranked by ideXlab platform

Joanna Domanska - One of the best experts on this subject based on the ideXlab platform.

  • local and remote file inclusion
    2012
    Co-Authors: Michal Hubczyk, Adam Domanski, Joanna Domanska
    Abstract:

    In this paper we have examined Local and remote file inclusion vulnerabilities in details. It is proven that these security flaws may lead to variety of problems including generation of big load to the server as well as disclosure of files which should not be accessible by the clients. These attacks are not so popular as SQL injection or Cross-Site Scripting but still they are subject of serious threat because of their consequences.

Ibnu Gunawan - One of the best experts on this subject based on the ideXlab platform.

  • Website Application Security Scanner Using Local file inclusion and remote file inclusion
    2012
    Co-Authors: Agustinus Noertjahyana, Ibnu Gunawan
    Abstract:

    Today many web-based applications developed to be accessible via the internet. The problem that often occurs is commonly found on web application vulnerabilities. Many application developers often ignore security issues when developing applications that can cause substantial losses if a hacker manages to gain access to the system. A hacker can replace web pages, obtain sensitive information, or even take over control of the website. For that reason there is a need for applications that can help developers to overcome these problems. This application is expected to detect the vulnerabilities that exist on a website. Existing processes include: The process of crawling to get the whole link from target websites, attacking process is useful for testing the attacks, and the last is the process of displaying a report about the security hole on the website. This application is developed using Microsoft Visual C # 2010. Based on the results of tests made on this application, it can be concluded that the application can detect vulnerabilities in the website and report any form of link that has a security hole on the website.

Dikka Wardhana - One of the best experts on this subject based on the ideXlab platform.

  • IMPLEMENTASI SISTEM KEAMANAN HONEYPOT PADA LAYANAN WEBSITE
    Universitas Telkom, 2014
    Co-Authors: Dikka Wardhana
    Abstract:

    Saat ini, perkembangan teknologi semakin lama semakin pesat . Diawali dengan munculnya berbagai teknologi – teknologi di bidang ICT, khususnya pada website/ aplikasi web yang telah banyak berkembang, baik dari segi komppleksitas maupun fungsionalitasnya. Namun perkembangan pada website ini juga mengakibatkan peningkatan serangan yang dilakukan oleh attacker. Sampai sekarang, 60 % dari semua serangan yang ada di internet merupakan serangan yang ditujukan pada website . Hal ini seiirng dengan meningkatnya peng e tahuan , teknik, dan tool ya ng dipakai dalam melakukan penyerangan.Honeypot merupakan suatu s i stem yang sengaja dirancang untu k di susupi oleh penyusup . H a l ini dimaksudkan untuk mengelabui penyusup sehingga akan men ghabiskan sumber dayanya pada s i stem honeypot tersebut. Tujuan d ari pembuatan honeypot ini untuk mendapatkan informasi yang akurat dari piha k penyusup. Nantinya informasi yang didapat dari honeypot akan dijadikan acuan untuk meningkatkan sistem keamanan yang telah ada, seperti IDS Snort .Hasil dari tugas akhir ini ada lah Honeypot Glastopf memiliki kemampuan dalam mengemulasikan celah – celah keamanan seperti LFI, RFI, SQL Injection (serangan yang terdeteksi 92,08%) dan memiliki kemampuan logging informasi – informasi serangan / penyerang yang nantinya dapat digunakan u ntuk meningkatkan sistem keamanan yang telah ada. Dari sisi success rate, performansi Honeypot Glastopf dapat menyamai hasil yang dimiliki server web pada pengujian dari 10 - 1.000 request dengan memiliki persentase sebesar 100%, tapi pada pengujian 10.000 request mengalami penurunan menjadi 55,93%. Honeypot , SQL Injection, remote file inclusion, local file inclusion , IDS , success rat

Hasan Sharif - One of the best experts on this subject based on the ideXlab platform.

  • RFI and SQLi based local file inclusion vulnerabilities in web applications of Bangladesh
    2016 International Workshop on Computational Intelligence (IWCI), 2016
    Co-Authors: Afsana Begum, Maruf Hassan, Touhid Bhuiyan, Hasan Sharif
    Abstract:

    People nowadays cannot think of even a single moment without the internet. Doubtlessly, web applications are currently the key to all change in the world. The features and facilities of web applications make our lives easier and also demonstrate different channels of communication and exchange of data. The number of internet user is increasing day by day in Bangladesh. Web applications are not only encouraging internet users to easily receive diversified services, but also creating new opportunities in every business sector. With the help of web applications, businesses can easily enhance the quality of their services to consumers with minimal effort. However, at the same time, many threats have arisen as a result of the misuse of this technology. Cyber attacks could emerge as a major threat to the digital transformation of Bangladesh, given the vulnerability in web applications caused by careless coding during the development of such applications. During our review, we observed that the existence of Local file inclusion (LFI) vulnerability in the web applications of Bangladesh was very critical. This paper explores in detail the harmful web application vulnerability attack, Local file inclusion (LFI) based on remote file inclusion (RFI) as well as Structured Query Language Injection (SQLi), and their impact on the applications of Bangladesh.

Sasongko Luhur - One of the best experts on this subject based on the ideXlab platform.

  • aplikasi deteksi kelemahan website dengan menggunakanmetode injeksi remote file inclusion dan local file
    2012
    Co-Authors: Sasongko Luhur
    Abstract:

    ABSTRAK Dalam pembuatan Aplikasi Analisis Kelemahan Website Dengang Menggunakan Metode Injeksi remote file inclusion dan Local file Incluison ini dapat menscanning website dimana website tersebut mempunyai kerentaan terhadap injeksi remote file inclusion dan local file inclusion sehingga website tersebut dapat diperbaiki. Aplikasi ini menggunakan bahasa pemrograman perl dimana hanya tampilan text yang ditampilkan dalam pembuatan aplikasi ini. Tampilan pada aplikasi ini hanya sekedar text tanpa ada form-form karena menscanning vulnerable pada website target yang dituju. Dengan adanya aplikasi analisis kelemahan website menggunkaan metode injeksi remote file inclusion dan local file inclusion dapat memberikan informasi tentang bagaimana sebuah website target rentan terhadap injeksi remote file inclusion dan local file inclusion . Kata Kunci : remote file inclusion dan local file inclusion, Perl.