Security Evaluation of the TIF Dashboard Using the Penetration Testing Execution Standard (PTES) Methodology

Penetration Testing, PTES, OWASP Top 10 2025, Web Application Security, Security Misconfiguration, Authentication Failures

Authors

  • Muhammad Aditya Rinaldi Department of Informatics Engineering, Faculty of Science and Technology, Universitas Islam Negeri Sultan Syarif Kasim Riau, Indonesia
  • Rahmad Abdillah Department of Informatics Engineering, Faculty of Science and Technology, Universitas Islam Negeri Sultan Syarif Kasim Riau, Indonesia
  • Novriyanto Department of Informatics Engineering, Faculty of Science and Technology, Universitas Islam Negeri Sultan Syarif Kasim Riau, Indonesia
  • Pizaini Department of Informatics Engineering, Faculty of Science and Technology, Universitas Islam Negeri Sultan Syarif Kasim Riau, Indonesia
April 30, 2026
May 1, 2026

Downloads

The Dashboard TIF of UIN Suska Riau is an academic information system used to manage memorization submission data, murojaah history, and administrative processes of the Informatics Engineering Study Program. This system stores sensitive data such as student identification numbers (NIM), lecturer identification numbers (NIP), and students’ memorization records, making its security highly critical. This study aims to evaluate the security level of the Dashboard TIF using the Penetration Testing Execution Standard (PTES) method combined with the OWASP Top 10 2025 framework. The assessment is carried out using a black-box approach with a combination of automated scanning tools and manual testing to discover, validate, and exploit relevant vulnerabilities. The results show that no critical vulnerabilities such as Remote Code Execution (RCE), SQL Injection, or Cross-Site Scripting (XSS) were found that could be directly exploited, but four categories of vulnerabilities requiring immediate remediation were identified, namely Security Misconfiguration (A02:2025), Software Supply Chain Failures (A03:2025), Insecure Design (A06:2025), and Authentication Failures (A07:2025). The most significant finding is an authentication weakness that allows brute-force attack against student accounts, which can be abused to access and modify academic data. The recommended improvements include strengthening security configurations, updating software components, and implementing authentication protection mechanisms to enhance the resilience of the Dashboard TIF against cyber attacks.