Pengujian Keamanan Website XYZ Menggunakan Metode Vulnerability Assessment & Penetration Testing

Silalahi, Ian Vemas (2025) Pengujian Keamanan Website XYZ Menggunakan Metode Vulnerability Assessment & Penetration Testing. Other thesis, Politeknik Negeri Bengkalis.

[thumbnail of Abstrak] Text (Abstrak)
REPO ABSTRAK.pdf - Submitted Version
Available under License Creative Commons Attribution Share Alike.

Download (201kB)
[thumbnail of Bab I Pendahuluan] Text (Bab I Pendahuluan)
REPO BAB I PENDAHULUAN.pdf - Submitted Version
Available under License Creative Commons Attribution Share Alike.

Download (224kB)
[thumbnail of Daftar Pustaka] Text (Daftar Pustaka)
REPO DAFTAR PUSTAKA.pdf - Submitted Version
Available under License Creative Commons Attribution Non-commercial Share Alike.

Download (161kB)
[thumbnail of Full Text] Text (Full Text)
REPO FULLL TEXT.pdf - Submitted Version
Restricted to Registered users only
Available under License Creative Commons Attribution Non-commercial Share Alike.

Download (3MB) | Request a copy

Abstract

Website security especially in the e-commerce sector, is an aspect that needs to be considered in implementing Cloudflare and Strict-Transport-Security Header to maintain data availability to increase customer or supplier trust. This study aims to test the security of the XYZ website using the Vulnerability Assessment Penetration Testing (VAPT) method. The implementation of the VAPT method has 4 stages starting from information gathering, vulnerability scanning, penetration testing, and report and result. The testing method used is the Disributed Denial of Service (DDoS), Clickjacking and Cross Site Request Forgery (CSRF) techniques. The results of the study showed that the website was not safe from DDoS attacks found on port 80 based on the results of scanning open ports using nmap, and with the CSRF technique on login elements that did not use CSRF anti-tokens. To avoid DDoS and CSRF attacks, the prevention is to use Cloudflare, the Laravel framework, the X-Frame-Option-Header configuration, implementing Content Security Policy (CSP) and HTTP Strict-Transport-Security (HSTS).

Item Type: Thesis (Other)
Uncontrolled Keywords: Keamanan Website, VAPT, DDoS, Clickjacking, CSRF Attack.
Subjects: 000 – UMUM, ILMU KOMPUTER, DAN INFORMASI > 005 – Pemrograman, Perangkat Lunak > 005.8 Keamanan dan Perlindungan Sistem
Divisions: Jurusan Teknik Informatika > Sarjana Terapan (D-IV) Keamanan Sistem Informasi > SKRIPSI
Depositing User: D-IV Keamanan Sistem Informasi Kelas A
Date Deposited: 08 Aug 2025 04:12
Last Modified: 08 Aug 2025 04:12
URI: https://eprints.polbeng.ac.id/id/eprint/1143

Actions (login required)

View Item
View Item