Publication Search

80,083 articles from 753 journals · 2,111 citations tracked

Showing 1-6 of 6

Analytics

Mochammad Fadilah; Nur Nawaningtyas

Merkurius : Jurnal Riset Sistem Informasi dan Teknik Informatika 2024 Asosiasi Riset Teknik Elektro dan Informatika Indonesia

This study aims to analyze security vulnerabilities and mitigation on the crowdo.co.id website using the OWASP Zed Attack Proxy (ZAP) tool, which is a web application security testing tool. High-level security attacks have increasingly risen alongside the advancement of information technology, making vulnerability testing crucial to ensure the integrity and security of information systems. This research involved scanning the crowdo.co.id website to identify various vulnerabilities, including those listed in the OWASP Top 10. The research process encompassed active and passive scanning, data analysis from the scans, and the formulation of mitigation strategies for each identified vulnerability. The findings revealed that the website had 14 detected vulnerabilities, consisting of 1 high-priority vulnerability, 3 medium-priority vulnerabilities, 7 low-priority vulnerabilities, and 3 additional informational alerts. The security dimensions tested included potential XSS attacks, SQL Injection, and other deficiencies that could jeopardize user data. Based on these results, recommended mitigations include code improvements, enhanced security configurations, and the implementation of additional preventive measures. This study concludes that while the website’s security is in the medium category, further improvements are necessary to reduce vulnerability risks. Through this approach, the study provides significant contributions to enhancing web application security.

Muhammad Tengku Sadewa; Tata Sutabri

Switch : Jurnal Sains dan Teknologi Informasi 2024 Asosiasi Profesi Telekomunikasi Dan Informatika Indonesia

During this time, the development of technology has progressed rapidly.  In this sense, many companies have followed this technological development and introduced it into the collection of inventory data of assets, goods, and their financial reports. To obtain accurate and precise data, an inventory data collection system is required. Manual accounting calculations mean that Depot Kayu Kusen Laris III often records inventory incorrectly, which affects the resulting financial reports. Therefore, this study aims to develop an inventory information system that will support accurate data collection at Kayu Kusen Laris III Depot. The conclusion of this study is that the inventory data information system is designed using Access and SQL database.

Angga Putrawansyah PB; Tata Sutabri

Router : Jurnal Teknik Informatika dan Terapan 2024 Asosiasi Profesi Telekomunikasi dan Informatika Indonesia

Security of electronic medical records (EMR) data is very important in maintaining the confidentiality, integrity, and availability of sensitive patient information. This study aims to conduct a security analysis of the EMR application used at UPTD RSD Besemah Pagar Alam City using the Penetration Testing method. This method is carried out to identify, exploit, and provide solutions to potential vulnerabilities in the EMR application system. Penetration Testing is carried out through several stages, namely information collection, scanning, exploitation, and post-exploitation, using tools such as Nmap, and OWASP ZAP. The results of the study showed several vulnerabilities in the application, including SQL Injection, Cross-Site Scripting (XSS), and weaknesses in authentication management that could allow unauthorized access to patient data. In addition, exposure to sensitive data that was not properly protected was also found. Based on the results of this test, several recommendations were made to improve system security, such as updating security patches, implementing encryption on all sensitive data. By implementing the recommended mitigation steps, the security of the EMR system at UPTD RSD Besemah is expected to be significantly improved, so that the risk of data leakage can be minimized. This research provides a real contribution in strengthening the security of electronic medical record applications. and is expected to be a reference in improving security systems in other health care institutions.    

Nanda Betris Dea Maretta; Abdul Rahim; Khanisa Octavia; Alvinalia Alvinalia; Aprilian Habar

Router : Jurnal Teknik Informatika dan Terapan 2024 Asosiasi Profesi Telekomunikasi dan Informatika Indonesia

Archiving is nothing new for agencies. The movement of documents and other documents in and out of government agencies certainly requires filing. The storage carried out at the Samarinda City Regional Civil Service Agency Office has not been fully effective for the existing archives, because some of the archives carried out are still done manually. As a result, archives can easily be lost before archiving or data management is done, often requiring manual intervention. Storage usage causes errors in storing data and retrieving data. This website-based archive system is indispensable, this is because it can be used to make changes to data, such as reducing the amount of paper used and changing the way data is stored (going paperless). This archive website system was created using the Vscode application. Where the Programming Language used is PHP and SQL, with Xampp used for web server operations and SQL for database management, by sending letters paperlessly will minimize errors that have occurred so far. While the software development method or system design uses the Waterfall method. Waterfall methodology is a type of application development model that is integrated into the classic life cycle. The purpose of making this website is to create a website system that processes email archive data in an easy-to-use way.

Deski Ari Sandi; Agus Tedyyana

Repeater : Publikasi Teknik Informatika dan Jaringan 2024 Asosiasi Riset Teknik Elektro dan Informatika Indonesia

In the era of information technology advancement, web applications have become a means of seeking information. However, with technological progress, they have become increasingly vulnerable to cyber attacks such as SQL Injection and Cross-Site Scripting (XSS). This research aims to implement the Teler-waf Web Application Firewall (WAF) to protect web applications from such attacks. The research methodology includes the implementation of the Teler-waf WAF, analysis of web application security, and testing the speed of attack detection. The results show that Teler-waf is effective in preventing attacks, and its integration with Telegram bots provides real-time notifications to system administrators, enhancing security responsiveness. This research contributes to strengthening web application security and understanding the role of the Teler-waf WAF in addressing cyber threats.

Danar Hadi Bachtiar; Paniran Paniran; I Made Budi Suksmadana

Mars: Jurnal Teknik Mesin, Industri, Elektro Dan Ilmu Komputer 2024 Asosiasi Riset Teknik Elektro dan Informatika Indonesia

Increasing fruit consumption is one of the challenges of public health. To address this, the authors developed a mobile application that allows users to scan and find information related to fruit. FruityFit is an application that can help users to get nutritional and processed information related to certain fruits that can increase users' interest in fruit consumption. This research focuses on constructing the back-end component of the FruityFit application. The design adheres to the REST architectural, leveraging the well-established ExpressJS framework for developmen. To realize the system, we implemented it using a suite of Google Cloud Platform (GCP) services. These services include Cloud Run, App Engine, Cloud Storage, and Cloud SQL, providing a scalable foundation for the back-end infrastructure.. The final result of this research is a REST API that has been running well and documented to help the front-end consume the API.