<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Web-Security on Ravxy1337 Tech</title>
    <link>https://edu.ravxytech.my.id/tags/web-security/</link>
    <description>Recent content in Web-Security on Ravxy1337 Tech</description>
    <generator>Hugo</generator>
    <language>id</language>
    <lastBuildDate>Tue, 30 Jun 2026 17:00:00 +0700</lastBuildDate>
    <atom:link href="https://edu.ravxytech.my.id/tags/web-security/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Membongkar Sisi Gelap Keamanan Web Kampus: Dari Google Dork hingga RCE</title>
      <link>https://edu.ravxytech.my.id/posts/kerentanan-keamanan-web-kampus/</link>
      <pubDate>Tue, 30 Jun 2026 17:00:00 +0700</pubDate>
      <guid>https://edu.ravxytech.my.id/posts/kerentanan-keamanan-web-kampus/</guid>
      <description>Analisis komprehensif tentang celah keamanan web kampus, mulai dari target subdomain terlantar, exploit CMS (OJS, SLiMS, Balitbang), kerentanan file manager, hingga eksekusi RCE.</description>
    </item>
    <item>
      <title>Git Exposed: Ketika Folder .git Terbuka untuk Umum</title>
      <link>https://edu.ravxytech.my.id/posts/git-exposed-directory-disclosure/</link>
      <pubDate>Thu, 25 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://edu.ravxytech.my.id/posts/git-exposed-directory-disclosure/</guid>
      <description>Folder .git yang tidak sengaja terbuka di server bisa mengekspos source code, kredensial database, API key, sampai riwayat seluruh perubahan kode. Artikel ini membahas cara menemukannya dan apa yang bisa didapat dari sana.</description>
    </item>
    <item>
      <title>XSS Bukan Sekadar script alert 1 script: Ini yang Sebenarnya Membuat Payload Berjalan</title>
      <link>https://edu.ravxytech.my.id/posts/xss-bukan-hanya-script-alert/</link>
      <pubDate>Thu, 25 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://edu.ravxytech.my.id/posts/xss-bukan-hanya-script-alert/</guid>
      <description>Pembahasan mendalam tentang anatomi XSS, dari memahami tag, event, dan atribut, sampai teknik bypass WAF, CSP, DOMPurify, dan postMessage XSS yang masih relevan di 2026.</description>
    </item>
    <item>
      <title>CVE-2026-10795 — UpdraftPlus RPC Authentication Bypass Chained to Plugin Installation</title>
      <link>https://edu.ravxytech.my.id/posts/cve-2026-10795-exploited/</link>
      <pubDate>Tue, 23 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://edu.ravxytech.my.id/posts/cve-2026-10795-exploited/</guid>
      <description>Breakdown lengkap CVE-2026-10795, celah authentication bypass pada UpdraftPlus yang bisa dirantai jadi RCE melalui UpdraftCentral RPC layer</description>
    </item>
  </channel>
</rss>
