Implementasi Penetration Testing Execution Standard Untuk Uji Penetrasi Pada Layanan Single Sign-On

Implementasi Penetration Testing Execution Standard Untuk Uji Penetrasi Pada Layanan Single Sign-On
复制标题

实施渗透测试执行标准 Untuk Uji Penetrasi Pada Layanan 单点登录

DOI:
10.15294/edukomputika.v8i1.47179
复制
发表时间:
2021
影响因子:
--
通讯作者:
Djodi Surya Prayoga
Djodi Surya Prayoga
中科院分区:
--
文献类型:
--
作者:
Septia Ulfa Sunaringtyas;Djodi Surya Prayoga

文献摘要

被引文献

相似文献

电子服务提供商越来越多地使用单点登录技术,除了提供好处外,也造成了脆弱性。渗透测试需要通过利用这些漏洞来识别漏洞并测试系统安全性。本研究实现了渗透测试执行标准(PTES)的渗透测试的单一单点服务。经过七个阶段的渗透测试,共识别出12个漏洞,其中3个中等漏洞,6个低漏洞和3个信息漏洞。已经进行了六次网络攻击来利用该漏洞,结果是3次成功攻击和3次失败攻击。根据漏洞和攻击分析的结果,给出了建议,包括定期更新和修补工作,在Web服务器和应用服务器上配置CSP头和内容类型选项头,验证主机头配置,x-content-type-options头和停用。x-forwarded- hosted在每个网页上,在cookie上配置“安全”标志,在源代码中添加元字符过滤功能,并限制登录尝试。PTES的实施结果证明,测试人员可以更容易地进行渗透测试,并有效地防止测试人员和客户之间由于测试范围的差异而产生的纠纷。
Increasing the use of single sign-on technology by electronic-based service providers in addition to providing benefits also creates vulnerability. Penetration testing needed to identify vulnerabilities and test system security by exploiting those vulnerabilities. This research implements the Penetration Testing Execution Standard (PTES) for penetration testing of single singn-on services. Seven stages of the penetration test had done and 12 vulnerabilities were identified, consisting of 3 medium vulnerabilities, 6 low vulnerabilities and 3 information vulnerabilities. Six cyberattacks have been carried out to exploit the vulnerability with the result of 3 successful attacks and 3 failed attacks. Based on the results of the vulnerability and exploitation analysis, recommendations are given consist of regular updating and patching efforts, configuration of the CSP header and content-type-option header on the web server and application server, validation of the host header configuration, x-content-type-options header and deactivation. x-forwarded- hosted on every web page, configure 'secure' flag on cookies, add metacharacter filter feature in source code, and limit login attempts. The results of the PTES’s implementation are proven to make it easier for testers to carry out penetration tests and effectively prevent disputes between testers and clients due to differences in the scope of testing.