JUTEI (Jurnal Terapan Teknologi Informasi)
Vol 6 No 2 (2022): Jurnal Terapan Teknologi Informasi

ANALISIS KEAMANAN JARINGAN UNIVERSITAS KRISTEN DUTA WACANA DENGAN SERANGAN SSL/TLS

Nathanael Dharmawan (Universitas Kristen Duta Wacana)
Gani Indriyanta (Universitas Kristen Duta Wacana)
I Kadek Dendy Senapartha (Universitas Kristen Duta Wacana)



Article Info

Publish Date
31 Oct 2022

Abstract

The security of data communication over the network has become an obligation that needs to be considered in a technology ecosystem. Data security has various layers, one layer that needs to be protected is the presentation layer where SSL/TLS is located. If at this layer there are vulnerabilities where sensitive data such as cookies, usernames, and passwords are present, then data leakage will have a major impact on all stakeholders in the technology sector using SSL/TLS technology. In order to research and improve data security in Duta Wacana Christian University (DWCU) campus network, the researchers conducted SSL/TLS vulnerability testing on the  SSAT and E-Class websites using the SSL Test from Qualys and a script from testssl.sh, the author also conducted Checking Mixed Content with GeekFlare and checking HSTS Preload using the HSTS Preload website provided by Google. Researchers also conducted SSL Strip penetration tests at 12 points of the DWCU building and also in Lab D. Based on the results of the study, there were several results found. The results on the SSL Test using Qualys found that the SSAT and E-Class websites already use HTTP Strict Transport Security (HSTS) rules with Max-Age 31536000 (1 year) but HSTS Preload has not been implemented, Mixed Content testing with GeekFlare shows that all transactions on SSAT and E-Class already uses HTTPS paths, then in tests using the testssl.sh script there are vulnerabilities that are read, and SSL Strip attacks are possible in Duta Wacana Christian University network under several conditions.

Copyrights © 2022






Journal Info

Abbrev

jurnal

Publisher

Subject

Computer Science & IT

Description

Jurnal Terapan Teknologi Informasi (JUTEI) is a journal focusing on theory, practice, and methodology of all aspects in Information Technology and Computer Science, as well as productive and innovative ideas related to new technology and applied sciences. This journal is managed by the Faculty of ...