ANALISIS DAN PENANGANAN INSIDEN KEAMANAN SIBER: SERANGAN SINDIKAT JUDI ONLINE PADA WEBSITE UNIVERSITAS UBUDIYAH INDONESIA
DOI:
https://doi.org/10.33143/Kata Kunci:
Keamanan Siber, Peretasan, Judi Online, Malware, Blackat SEOAbstrak
Kasus peretasan situs web akademik oleh sindikat judi online telah menjadi ancaman serius bagi institusi Pendidikan di Indonesia. Penelitian ini mendokumentasikan dan menganalisis insiden keamanan siber yang terjadi pada infrastruktur digital Universitas Ubudiyah Indonesia (UUI) pada periode tahun 2025. Hasil investigasi menunjukkan serangan bersifat masif dengan mengeksploitasi 18 subdomain aktif melalui kerentanan platform CMS WordPress yang sudah usang, penggunaan tema bajakan (nulled), dan celah file upload pada Open Journal System (OJS) versi 2.x. Penyerang menanamkan puluhan backdoor shell (seperti kobe.php, sc.php, jago.php, dan varian script ALFA/Rimuru) yang terobfuskasi menggunakan fungsi dinamis PHP seperti base_64_decode dan eval()[1][3]. Lebih lanjut, penyerang melakukan pembajakan hak kepemilikan pada Google Search Console (GSC) menggunakan akun luar (ilhamhidayat2522@gmail.com) untuk memanipulasi indeks pencarian melalui teknik Blackhat SEO, menghasilkan 123.000 klik ilegal dan 6.83 juta impresi untuk kueri-kueri tidak senonoh. Sebagai langkah remediasi, diimplementasikan isolasi subdomain, pembersihan massal otomatis, pemutakhiran sistem, dan penerapan Web Application Firewall(WAF).Referensi
H. M. Mansur and L. Sumanto, "Analisis Penegakan Hukum Peretasan Situs Website Oleh Sindikat Judi Online," Ensiklopedia Education Review, vol. 6, no. 3, pp. 132-138, 2024.
Direktorat Cyber Development Center (CDC), Laporan Insiden Keamanan Siber: Laporan Penanganan Insiden Peretasan Website oleh Konten Judi Online (Dokumen No: ICT-UUI/IS-REP/2025/IX/001), Universitas Ubudiyah Indonesia, Banda Aceh, 2025.
Pan, Z., Chen, Y., Chen, Y., Shen, Y., & Guo, X. (2021). Webshell Detection Based on Executable Data Characteristics of PHP Code. Wirel. Commun. Mob. Comput., 2021, 5533963:1-5533963:12. https://doi.org/10.1155/2021/5533963
Mesa, O., Vieira, R., Viana, M. L., Durelli, V. H. S., Cirilo, E., Kalinowski, M., & Lucena, C. (2018). Understanding vulnerabilities in plugin-based web systems: an exploratory study of wordpress. Proceedings of the 22nd International Systems and Software Product Line Conference - Volume 1.
Kabata, P. (2025). Analysis of vulnerabilities and consequences of missing hardening in WordPress-based CMS environments. Computer Science and Mathematical Modelling.
Riadi, I., Yudhana, A., & Yunanri, W. (2020). Analisis Keamanan Website Open Journal System Menggunakan Metode Vulnerability Assessment
Laksmiati, D. (2023). Vulnerability Assessment with Network-Based Scanner Method for Improving Website Security
Petrica, G. (2022). Cybersecurity of WordPress Platforms
Nurseno, M., et al. (2024). Detecting Hidden Illegal Online Gambling on .go.id Domains Using Web Scraping Algorithms
Unduhan
Diterbitkan
Terbitan
Bagian
Lisensi
COPYRIGHT TRANSFER FORM
The copyright to this article is transferred to Universitas Ubudiyah Indonesia (UUI) if and when the article is accepted for publication. The undersigned hereby transfers any and all rights in and to the paper including without limitation all copyrights to UUI. The undersigned hereby represents and warrants that the paper is original and that he/she is the author of the paper, except for material that is clearly identified as to its original source, with permission notices from the copyright owners where required. The undersigned represents that he/she has the power and authority to make and execute this assignment.
We declare that:
- This paper has not been published in the same form elsewhere.
- It will not be submitted anywhere else for publication prior to acceptance/rejection by this Journal.
- A copyright permission is obtained for materials published elsewhere and which require this permission for reproduction.
Furthermore, I/We hereby transfer the unlimited rights of publication of the above mentioned paper in whole to UUI. The copyright transfer covers the right to reproduce and distribute the article, including reprints, translations, photographic reproductions, microform, electronic form (offline, online) or any other reproductions of similar nature. The corresponding author signs for and accepts responsibility for releasing this material on behalf of any and all co-authors. After submission of this agreement signed by the corresponding author, changes of authorship or in the order of the authors listed will not be accepted.
Retained Rights/Terms and Conditions
- Authors retain all proprietary rights in any process, procedure, or article of manufacture described in the work.
- Authors may reproduce or authorize others to reproduce the work or derivative works for the author’s personal use or for company use, provided that the source and the UUI copyright notice are indicated, the copies are not used in any way that implies UUI endorsement of a product or service of any employer, and the copies themselves are not offered for sale.
- Although authors are permitted to re-use all or portions of the work in other works, this does not include granting third-party requests for reprinting, republishing, or other types of re-use.