Halil, M. Isma (2026) Analisis Dan Perbaikan Keamanan Sistem Informasi Pencatatan Hasil Panen Sawit Menggunakan Metode Penetration Testing. Other thesis, Politeknik Negeri Bengkalis.
1. SK-6404221114-Abstrack.pdf - Submitted Version
Available under License Creative Commons Attribution Share Alike.
Download (353kB)
2. SK-6404221114-Bab I Pendahuluan.pdf - Submitted Version
Available under License Creative Commons Attribution Share Alike.
Download (274kB)
3. SK-6404221114-Daftar Pustaka.pdf - Submitted Version
Available under License Creative Commons Attribution Share Alike.
Download (366kB)
4. SK-6404221114-Full Text.pdf - Submitted Version
Restricted to Registered users only
Available under License Creative Commons Attribution Share Alike.
Download (3MB)
Abstract
Web application security has become a critical issue in the agribusiness sector due to the increasing digitalization of harvest recording systems, including the Palm Oil Harvest Recording Information System (SawitGoDigi) in Bengkalis District, which had never undergone a comprehensive security assessment and faced risks of data leakage, unauthorized access, and service disruption. This study analyzes and improves system security using a penetration testing approach based on OWASP Top 10, combining grey-box testing for identification and white-box testing for remediation, covering vulnerability identification, remediation, and retesting. Risk evaluation used the OWASP Risk Rating Methodology with a likelihood-impact scale of 1–9. Four vulnerabilities were identified: SQL Injection (score 9, High), Broken Authentication including OTP weaknesses and brute force login (score 9, High), Weak Session Management (score 9, High), and Security Misconfiguration in HTTP security headers (score 2, Low). After remediation, all vulnerabilities were closed and could not be exploited under the same scenarios. This study contributes an integrated security testing model combining identification, remediation, and verification within a single cycle.
| Item Type: | Thesis (Other) |
|---|---|
| Uncontrolled Keywords: | penetration testing, OWASP Top 10, web application security, risk evaluation, palm oil information system. |
| Subjects: | 000 – UMUM, ILMU KOMPUTER, DAN INFORMASI > 005 – Pemrograman, Perangkat Lunak > 005.8 Keamanan dan Perlindungan Sistem |
| Divisions: | Jurusan Teknik Informatika > Sarjana Terapan (D-IV) Keamanan Sistem Informasi > SKRIPSI |
| Depositing User: | D-IV Keamanan Sistem Informasi Kelas A |
| Date Deposited: | 06 Jul 2026 01:35 |
| Last Modified: | 06 Jul 2026 01:35 |
| URI: | https://eprints.polbeng.ac.id/id/eprint/5156 |
