科研速览 · Science Skim继续刷下去 · Keep skimming →
◆ JURNAL MULTIDISIPLIN BHATARA2026-07-31· Computer security

Information Security Valuation on the Bakpia Tamansari Website and Semakar Adventure Shop Using Penetration Testing and Vulnerability Assessment Approaches

Abel Kusuma, Joko Dwi Santoso, Hastari Utama, Ahlihi Masruro, Sudarmanto

原始摘要(英文原文)· Original abstract
This study aims to evaluate the level of information security on two local e-commerce platforms, namely Bakpia Tamansari and Semakar Adventure Shop, through penetration testing and vulnerability assessment. The method used is a case study by applying a set of security tools such as Metasploit, Nmap, Nikto, SQLMap, and OWASP ZAP to identify security vulnerabilities in aspects of the network, server, web application, and database. The results show that both websites have similar vulnerabilities in security configurations, especially in the absence of critical security headers (X-Frame-Options, X-Content-Type-Options), open service ports without adequate protection, and potential for Cross-Site Request Forgery (CSRF) attacks. Bakpia Tamansari showed a slightly better security posture with no leakage of sensitive files, while Semakar Adventure Shop was identified as having a publicly accessible configuration file (composer.lock). Based on these findings, this study provides recommendations for improvement in the form of implementing multi-factor authentication, adding security headers, closing ports is not required, and improving incident monitoring and response systems. The implications of this research are expected to be a reference for local e-commerce platform managers in improving information security readiness according to industry standards.
读原文 · Read the paper ↗

AI 追问PRO

登录后使用 AI 追问

讨论区

登录后参与讨论

相关论文 · Related

Information Security Valuation on the Bakpia Tamansari Website and Semakar Adventure Shop Using Penetration Testing and Vulnerability Assessment Approaches — 科研速览 Science Skim