Claim Missing Document
Check
Articles

Found 1 Documents
Search

Information Security Valuation on the Bakpia Tamansari Website and Semakar Adventure Shop Using Penetration Testing and Vulnerability Assessment Approaches Abel Kusuma; Joko Dwi Santoso; Hastari Utama; Ahlihi Masruro; Sudarmanto
BHATARA: Jurnal Multidisiplin Ilmu Vol 3 No 3 (2026): Juli
Publisher : Hemispheres Press

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.59095/jmb.v3i3.263

Abstract

This study aims to evaluate the level of information security on two local e-commerce platforms, namely Bakpia Tamansari and Semakar Adventure Shop, through penetration testing and vulnerability assessment. The method used is a case study by applying a set of security tools such as Metasploit, Nmap, Nikto, SQLMap, and OWASP ZAP to identify security vulnerabilities in aspects of the network, server, web application, and database. The results show that both websites have similar vulnerabilities in security configurations, especially in the absence of critical security headers (X-Frame-Options, X-Content-Type-Options), open service ports without adequate protection, and potential for Cross-Site Request Forgery (CSRF) attacks. Bakpia Tamansari showed a slightly better security posture with no leakage of sensitive files, while Semakar Adventure Shop was identified as having a publicly accessible configuration file (composer.lock). Based on these findings, this study provides recommendations for improvement in the form of implementing multi-factor authentication, adding security headers, closing ports is not required, and improving incident monitoring and response systems. The implications of this research are expected to be a reference for local e-commerce platform managers in improving information security readiness according to industry standards.