Rohmaniah, Diana
Unknown Affiliation

Published : 2 Documents Claim Missing Document
Claim Missing Document
Check
Articles

Found 2 Documents
Search

Enhancing Website Security Using Vulnerability Assessment and Penetration Testing (VAPT) Based on OWASP Top Ten Rohmaniah, Diana; Ashari, Wahid Miftahul; Lukman, Lukman; Putra, Andriyan Dwi
Journal of Applied Informatics and Computing Vol. 9 No. 2 (2025): April 2025
Publisher : Politeknik Negeri Batam

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.30871/jaic.v9i2.9069

Abstract

Website security is one of the main concerns in the digital era, given the increasing potential for cyber threats. This research aims to improve website security by using the Vulnerability Assessment and Penetration Testing (VAPT) method that refers to the OWASP Top Ten standard. The applied method includes four main stages: information gathering, vulnerability scanning, exploitation, and reporting. The results showed that there were several successfully exploited vulnerabilities, such as Clickjacking, Improper HTTP to HTTPS Redirection, Directory Listing, and Sensitive Information Disclosure, which were classified based on the OWASP Top Ten. The severity of the vulnerabilities was analyzed using Common Vulnerabilities and Exposures (CVE), Common Weakness Enumeration (CWE), and Common Vulnerability Scoring System (CVSS). The analysis results show that some vulnerabilities have high severity after considering the factual conditions of the system. This research provides specific remediation recommendations to address these vulnerabilities, such as the implementation of security headers, deletion of sensitive configuration files, and dependency updates. With this approach, the research is expected to contribute to improving website security and provide effective mitigation guidelines.
ANALYSIS OF THE NEED FOR AN INFORMATION SYSTEM ON PRICES AND AVAILABILITY OF BASIC MATERIALS Putra, Andriyan Dwi; Rohmaniah, Diana
Jurnal Pilar Nusa Mandiri Vol. 21 No. 2 (2025): Pilar Nusa Mandiri : Journal of Computing and Information System Publishing Pe
Publisher : LPPM Universitas Nusa Mandiri

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.33480/pilar.v21i2.7240

Abstract

The development of information technology has driven digital transformation in various sectors, including the economic sector. Managing data on the prices and availability of basic commodities is crucial for maintaining community economic resilience. This study applies a design thinking approach to analyze the need for an information system on the prices and availability of basic commodities in Yogyakarta City, with a testing plan prepared using black box, white box, and security methods. The analysis produced three main findings: the need for Single Sign-On (SSO) with role-based access, real-time monitoring of commodity prices, and cross-agency integration in agenda and program management. The proposed system design consists of four main modules: administration, agenda, services, and programs/activities. Since this study is limited to the needs analysis and prototype design stage, empirical test results are not yet available. Nevertheless, the study provides an initial framework and foundation for cross-agency integration in the Yogyakarta City Government to support transparency, coordination, and control of basic commodity prices.