scholarly journals Website Security Gap Analysis Using WEBPWN3R Tools at Kali Linux

2020 ◽  
Vol 4 (2) ◽  
pp. 69-76
Author(s):  
Andria Andria

  Abstrak— Website sebagai media informasi dan komunikasi tentunya memiliki peran yang sangat penting. Seiring perkembangannya, tidak bisa dipungkiri bahwa terdapat ancaman terkait dengan celah keamanan dari suatu website. Adanya celah keamanan (bug) pada suatu website tentu memerlukan perhatian serius agar tidak dieksploitasi oleh pihak yang tidak bertanggung jawab. Berdasarkan hal tersebut, tentunya diperlukan adanya upaya preventif diantaranya dengan melakukan analisis terhadap kemungkinan adanya celah keamanan pada suatu website.  Pada penelitian ini, tools yang digunakan adalah WEBPWN3R yang merupakan Web Applications Security Scanner, tool open source ini dapat menganalisa, mendeteksi adanya bug dari suatu website. Pengujian dilakukan menggunakan perangkat komputer bersistem operasi Kali Linux. Penelitian ini bertujuan untuk menganalisa adanya celah keamanan pada suatu website dan membantu administrator atau pengelola web untuk dapat mengetahui adanya kemungkinan celah keamanan pada suatu website, sehingga dapat segera dilakukan perbaikan dengan tepat berdasarkan temuan kerentanan atau celah keamanan yang terdapat pada website tersebut.

Author(s):  
Faried Effendy ◽  
Taufik ◽  
Bramantyo Adhilaksono

: Substantial research has been conducted to compare web servers or to compare databases, but very limited research combines the two. Node.js and Golang (Go) are popular platforms for both web and mobile application back-ends, whereas MySQL and Go are among the best open source databases with different characters. Using MySQL and MongoDB as databases, this study aims to compare the performance of Go and Node.js as web applications back-end regarding response time, CPU utilization, and memory usage. To simulate the actual web server workload, the flow of data traffic on the server follows the Poisson distribution. The result shows that the combination of Go and MySQL is superior in CPU utilization and memory usage, while the Node.js and MySQL combination is superior in response time.


2010 ◽  
Vol 2 (3) ◽  
pp. 30-47 ◽  
Author(s):  
Michael G. Leahy ◽  
G. Brent Hall

This paper discusses the research-based origins and modular architecture of an open source geospatial tool that facilitates synchronous individual and group discussions using the medium of a Web map service. The software draws on existing open source geospatial projects and associated libraries and techniques that have evolved as part of the new generation of Web applications. The purpose of the software is discussed, highlighting the fusion of existing open source projects to produce new tools. Two case studies are briefly discussed to illustrate the value an open source approach brings to communities who would remain otherwise outside the reach of proprietary software tools. The paper concludes with comments on the project’s future evolution as an open source participatory mapping platform.


2011 ◽  
Vol 2 (3) ◽  
pp. 42-62
Author(s):  
Afonso Araújo Neto ◽  
Marco Vieira

When deploying database-centric web applications, administrators should pay special attention to database security requirements. Acknowledging this, Database Management Systems (DBMS) implement several security mechanisms that help Database Administrators (DBAs) making their installations secure. However, different software products offer different sets of mechanisms, making the task of selecting the adequate package for a given installation quite hard. This paper proposes a methodology for detecting database security gaps. This methodology is based on a comprehensive list of security mechanisms (derived from widely accepted security best practices), which was used to perform a gap analysis of the security features of seven software packages composed by widely used products, including four DBMS engines and two Operating Systems (OS). The goal is to understand how much each software package helps developers and administrators to actually accomplish the security tasks that are expected from them. Results show that while there is a common set of security mechanisms that is implemented by most packages, there is another set of security tasks that have no support at all in any of the packages.


2020 ◽  
Vol 3 (1) ◽  
pp. 11-16
Author(s):  
Mihăiță Rădoi ◽  
◽  
Petrică Ciotîrnae ◽  

Under the current global conditions, strong emphasis is put on saving resources and reducing costs, migrating to collaborative unified communications solutions and developing open-source Web applications. The secure video-conferencing system will mainly use VoIP and WebRTC technologies to make multimedia calls, allowing end-users mobile and remote access (MRA) and therefore to facilitate communication between different networks, as well as the accessibility and the interoperability with any type of technology and device. This article will analyze the scalable implementation of the real-time communications network, providing redundancy and load balancing, therefore ensuring the high availability of the entire collaborative communications system. The call control and the dial plan are done through the Unified Call Manager software and WebRTC videoconferencing external access functionality is provided by configuring Traversal Using Relays around NAT (TURN) service across the Expressway Series server pair (Core & Edge). The ability to manage and monitor virtual meetings remains the responsibility of the open-source management tools.


2020 ◽  
Vol 8 (4) ◽  
pp. 154-159
Author(s):  
Kamaran H.A Faraj ◽  
Asan B. Kanbar ◽  
Jaza Gul-Mohammed ◽  
Wafaa M. Hmeed ◽  
Shagul F. Karim

Since the traditional time loading (TTL) very primitive before the era of information communication technology (ICT) and it was really not depended on the result of time-loading due to the old version of computer architecture (i.e. serial processing). Nevertheless, the parallel processing systems open a wide area of researching for electronic time loading (ETL) over different operating systems by programing languages (i.e. python or private home page (Php)). The electronic time loading (ETL) for cloud Computing (CC) is a hot experimental topic.  ETL for CC is not only one parameter (i.e. a web technologies type or a web applications type or an infrastructures type or an architectures type). Moderately, the term CC refers to the evolution of the information technology (IT). As we realized the ETL is very important for reducing time wasting. The reducing time-waste loading over different web operating systems or CC is a target in this paper.  Finally, this paper test the Electronic Loading Time of CC over different operating systems with different types of network (i.e. public and private) discovering the least ETL. Hence the benchmarking TTL is not applicable (N/A) due to the activity from a person to others is very changeable and not depended on it at all.  This paper shows the total time and load time over different OS in seconds, and find out the least time loading required this work is a good solution of the response time over different operating system in open source-LOS and non-open source WOS.


2019 ◽  
Author(s):  
Ayman Yousif ◽  
Nizar Drou ◽  
Jillian Rowe ◽  
Mohammed Khalfan ◽  
Kristin C Gunsalus

AbstractBackgroundAs high-throughput sequencing applications continue to evolve, the rapid growth in quantity and variety of sequence-based data calls for the development of new software libraries and tools for data analysis and visualization. Often, effective use of these tools requires computational skills beyond those of many researchers. To ease this computational barrier, we have created a dynamic web-based platform, NASQAR (Nucleic Acid SeQuence Analysis Resource).ResultsNASQAR offers a collection of custom and publicly available open-source web applications that make extensive use of a variety of R packages to provide interactive data analysis and visualization. The platform is publicly accessible at http://nasqar.abudhabi.nyu.edu/. Open-source code is on GitHub at https://github.com/nasqar/NASQAR, and the system is also available as a Docker image at https://hub.docker.com/r/aymanm/nasqarall. NASQAR is a collaboration between the core bioinformatics teams of the NYU Abu Dhabi and NYU New York Centers for Genomics and Systems Biology.ConclusionsNASQAR empowers non-programming experts with a versatile and intuitive toolbox to easily and efficiently explore, analyze, and visualize their Transcriptomics data interactively. Popular tools for a variety of applications are currently available, including Transcriptome Data Preprocessing, RNA-seq Analysis (including Single-cell RNA-seq), Metagenomics, and Gene Enrichment.


Sign in / Sign up

Export Citation Format

Share Document