AbstractThe development of human potential is greatly facilitated by education, which enables individuals to enhance their abilities through acquired learning experiences. However, a prominent issue within the Indonesian education system is the considerable cost associated with academic activities. In response to this challenge, the Fakfak Regional Government has implemented a financial assistance program, providing support to 1,500 students pursuing education both within Fakfak Regency and in external locations. Currently, the application and administration procedures for these educational grants are managed manually by the Welfare Department. This conventional approach, encompassing tasks such as the verification, archiving, and validation of documents, is notably time-consuming, primarily due to the large volume of accumulated data. This research has two main objectives: firstly, to simplify the process used by local governments in managing education fund assistance, thereby promoting greater transparency and accountability; secondly, to enhance the security of the online platform against cyber threats. For the website development, a waterfall methodology was adopted, with security enhancements implemented through the utilization of the Damn Vulnerable Web App (DVWA) framework, considering cost-effectiveness and temporal efficiency. The application's resilience was rigorously evaluated through a series of penetration tests. These assessments involved examining the efficacy of the Web Application Firewall (WAF) in both active and inactive conditions, as well as simulating various cyber-attacks, including SQL injection, Cross-Site Scripting (XSS), command injection, and brute-force exploits. The results obtained from this research indicate that the integration of a WAF significantly enhances the application's resilience against cyber attacks. It was observed that vulnerabilities that could be successfully exploited in the absence of an active WAF, such as SQL Injection and XSS, were effectively identified and mitigated once the WAF was enabled. Further analytical examination, utilizing frameworks such as attack trees, has substantiated the WAF's capacity to provide comprehensive protection against various attack methodologies targeting web-based applications. Therefore, the web-based portal designed for the Fakfak Regional Government's education assistance initiative is expected to simplify the experience for prospective grant recipients, enabling them to access relevant information and submit their applications with greater ease. AbstrakPendidikan merupakan suatu cara bagi manusia untuk mengembangkan potensi dirinya melalui proses pembelajaran yang diperolehnya. Namun salah satu permasalahan dalam dunia pendidikan Indonesia adalah biaya pendidikan. Pemerintah Daerah Fakfak memberikan bantuan dana pendidikan kepada 1.500 mahasiswa baik yang kuliah di luar Fakfak maupun yang kuliah di dalam Kabupaten Fakfak. Proses pengajuan dan pengelolaan dana bantuan pendidikan saat ini dilakukan secara manual oleh bidang Kesra yaitu pengecekan, penyimpanan, dan validasi berkas yang memakan banyak waktu karena penumpukan data. Penelitian ini memiliki 2 tujuan utama: 1) untuk memudahkan pemerintah daerah dalam mengelola bantuan dana pendidikan secara transparan dan akuntabel. 2) Untuk menjamin keamanan website dari serangan. Metode yang penulis gunakan dalam pengembangan website adalah waterfall, optimalisasi keamanan menggunakan Damn Vulnerable Web App (DVWA) cost dan metric time. Untuk mengukur ketangguhan aplikasi, dilakukan beberapa kali pengujian yaitu melakukan eksploitasi dengan kondisi Web Application Firewall (WAF) nonaktif/aktif, eksploitasi sql injection, eksploitasi XSS, command injection dan eksploitasi brute force. Hasil penelitian menunjukkan bahwa WAF secara signifikan dapat meningkatkan kemampuan aplikasi terhadap serangan. Eksploitasi yang berhasil dilakukan saat WAF nonaktif, seperti SQL Injection dan XSS, terbukti dapat dideteksi dan dicegah ketika WAF diaktifkan. Analisis lebih lanjut menggunakan kerangka kerja seperti attack tree mengkonfirmasi bahwa WAF memberikan perlindungan yang efektif terhadap berbagai model serangan yang pada aplikasi web. Aplikasi penerimaan bantuan dana pendidikan PEMDA Fakfak Berbasis Web dapat memudahkan calon penerima bantuan pendidikan untuk menerima informasi dan mengajukan bantuan pendidikan dengan lebih mudah.