Claim Missing Document
Check
Articles

Found 3 Documents
Search
Journal : Journal of Information Technology and Computer Engineering

Vulnerability Testing and Analysis on Websites and Web-Based Applications in the XYZ Faculty Environment Using Acunetix Vulnerability Rahmi, Mifthahul; Yunus, Yuhandri; Sumijan, Sumijan
JITCE (Journal of Information Technology and Computer Engineering) Vol 8 No 2 (2024): Journal of Information Technology and Computer Engineering
Publisher : Universitas Andalas

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.25077/jitce.8.2.83-96.2024

Abstract

The internet's continuous evolution has profoundly impacted society through the advancement of website technology and applications, reshaping contemporary ways of life. These digital platforms offer unrestricted information access, overcoming spatial and temporal limitations. In the realm of software development, Vulnerability Assessment is essential for producing high-quality products, as seemingly minor errors can create dangerous vulnerabilities that malicious actors may exploit to pilfer information from websites or applications. This study examines the security level of the Integrated website and application within the Faculty of Medicine, Universitas Andalas (Fakultas XYZ) environment, utilizing the Acunetix Web Vulnerability Scanner tool. The initial scan revealed a threat level of 3 (high) for the Fakultas XYZ website and level 2 (medium) for the Integrated application. Following a recapitulation process, several web alerts were identified for optimization, including Cross-Site Scripting (XSS), Blind SQL Injection, Application error message, HTML form without CSRF protection, Development configuration file, Directory listing, Error message on page, and User credentials sent in clear text. The optimization process involved source code review and enhancement to improve website features. A subsequent scan post-optimization demonstrated a reduction in threat levels for both the website and the UNAND FK Symphony application, with both achieving threat level 1 (low).
Vulnerability Testing and Analysis on Websites and Web-Based Applications in the XYZ Faculty Environment Using Acunetix Vulnerability Rahmi, Mifthahul; Yunus, Yuhandri; Sumijan, Sumijan
JITCE (Journal of Information Technology and Computer Engineering) Vol. 8 No. 2 (2024)
Publisher : Universitas Andalas

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.25077/jitce.8.2.83-96.2024

Abstract

The internet's continuous evolution has profoundly impacted society through the advancement of website technology and applications, reshaping contemporary ways of life. These digital platforms offer unrestricted information access, overcoming spatial and temporal limitations. In the realm of software development, Vulnerability Assessment is essential for producing high-quality products, as seemingly minor errors can create dangerous vulnerabilities that malicious actors may exploit to pilfer information from websites or applications. This study examines the security level of the Integrated website and application within the Faculty of Medicine, Universitas Andalas (Fakultas XYZ) environment, utilizing the Acunetix Web Vulnerability Scanner tool. The initial scan revealed a threat level of 3 (high) for the Fakultas XYZ website and level 2 (medium) for the Integrated application. Following a recapitulation process, several web alerts were identified for optimization, including Cross-Site Scripting (XSS), Blind SQL Injection, Application error message, HTML form without CSRF protection, Development configuration file, Directory listing, Error message on page, and User credentials sent in clear text. The optimization process involved source code review and enhancement to improve website features. A subsequent scan post-optimization demonstrated a reduction in threat levels for both the website and the UNAND FK Symphony application, with both achieving threat level 1 (low).
Sistem Pakar Metode Backward Chaining untuk Optimalisasi Pelayanan Pemberian Informasi Obat: Studi Kasus Puskesmas Lasi Kabupaten Agam Putra, Surya Dwi; Putri, Dhena Marichy; Defit, Sarjon; Sumijan, Sumijan
JITCE (Journal of Information Technology and Computer Engineering) Vol. 7 No. 01 (2023)
Publisher : Universitas Andalas

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.25077/jitce.7.01.1-7.2023

Abstract

Drug information service is an assistance service to handle the needs of pharmacists related to medicines consumed by patients at the Lasi Health Center, Agam Regency. Nowadays, most of drug information services always require pharmacists to carry out their services, although there is limited number of pharmacists for providing drug information services at the Lasi Health Center, Agam Regency. This study aims to optimize drug information services so that the services can be carried out without the direct presence of a pharmacist. The data used in this study were drug prescription data available at the Pharmacy of Lasi Health Center Agam for the last 12 months and drug information services provided by pharmacists at the Lasi Health Center Agam Regency. This study used the backward chaining method to identify the drugs prescribed to the patients. The result achieved by this study were 356 Rules that could be applied directly to drug information services, with an accuracy rate of 100%. The rules generated using the backward chaining method can be used to optimize drug information services at the Lasi Health Center in Agam Regency without having to be served directly by pharmacists.