Improving Webserver Security for Local Tax Reporting Applications Using Standard Penetration Testing Execution Methods

  • Pohan Y
  • Yunus Y
  • Sumijan S
N/ACitations
Citations of this article
21Readers
Mendeley users who have this article in their library.

Abstract

Regional Tax Reporting Application Webserver is one of the public services for taxpayers to report their sales transactions. This application can be accessed on the domain http://sptpd.payakumbuhkota.go.id. This application is public, so the principles of information security must be applied to prevent cyber attacks. The principles of information security include confidentiality, integrity, and availability. To apply this information security principle, it is necessary to conduct vulnerability assesment of the application webserver. This study aims to improve the security of the application webserver so that the data and information in it is secure. The method used in this study is the Penetration Testing Execution Standard which is one of the methods developed by the Pentest Organization to become a standard in analyzing or auditing security systems. The results of vulnerability testing using software Acunetix, Nikto, BurpSuite and Owasp, there are seven types of vulnerabilities, namely: X-Frame Header Options is Missing, CSRF Attack, Cookie Without Only Flash, DNS Vulnerability, Ddos Attack, Bruteforce Page Login and Open Port. The vulnerability can be exploited, where the level of application vulnerability is in the medium category. The recommendations for fixing vulnerabilities can be applied by the developer, so that after repairs are made, the vulnerability level of the application webserver is in the low category and there is only one type of vulnerability, namely BruteForce Page

Cite

CITATION STYLE

APA

Pohan, Y. A., Yunus, Y., & Sumijan, S. (2020). Improving Webserver Security for Local Tax Reporting Applications Using Standard Penetration Testing Execution Methods. Jurnal Sistim Informasi Dan Teknologi. https://doi.org/10.37034/jsisfotek.v3i1.83

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free