Implementasi Keamanan Website Alfarouq Tour Travel Berdasarkan Temuan Kerentanan Owasp Zap

Authors

  • Ahmad Suhenri Lubis Universitas Negeri Medan
  • Nurmi Hidayasari Politeknik Negeri Bengkalis
  • Zuliar Efendi Politeknik Negeri Bengkalis

DOI:

https://doi.org/10.59061/jentik.v4i2.1547

Abstract

Websites used for tourism services process personal and transaction information, making security evaluation important to reduce the risk of misuse and data exposure. This study implements security improvements on the Alfarouq Tour Travel website based on vulnerability findings identified using OWASP Zed Attack Proxy (ZAP). The research uses an applied experimental approach consisting of an initial security scan, classification and analysis of findings, planning and implementation of remediation, re-scanning, and comparison of conditions before and after remediation. The initial scan using OWASP ZAP 2.16.1 on 25 April 2025 found no High-risk alerts, but identified three Medium-risk alert types with 57 instances: Absence of Anti-CSRF Tokens (1), Content Security Policy Header Not Set (30), and Missing Anti-clickjacking Header (26). Remediation was implemented through CSRF token protection and request-flow adjustment, Content Security Policy configuration, and X-Frame-Options together with the frame-ancestors directive. The re-scan on 30 December 2025 showed that all three Medium-risk alert types were no longer detected, reducing Medium instances from 57 to 0. Six Low-risk and six Informational alert types remained. The findings indicate that remediation based on ZAP results met the study’s success indicator for the three targeted Medium-risk findings within the tested scope, while further assessment is still required for residual findings and system areas not reached by the scan.

References

Fauzi, R. M., Hermawan, R., Adhy, D. R., & Maesaroh, S. (2024). Analisis Kerentanan Keamanan Web Menggunakan Metode OWASP dan PTES di Web Pemerintahan Desa XYZ. Power Elektronik: Jurnal Orang Elektro, 13(2), 225–228.

Kaleli, B., Egele, M., & Stringhini, G. (2020). EasyCSPeasy: A Server-side and Language-agnostic XSS Mitigation by Devising and Ensuring Compliance with CSP. Proceedings of the Workshop on Privacy in the Electronic Society (WPES), ACM, 1–13.

Jha, S. K., & Raghavendra, R. (2021). CSRF Attacks and Its Defence Using Middleware. International Journal of Trend in Scientific Research and Development (IJTSRD), 5(4), 1085–1088.

I. D. N. H., A. R. W., N. S. Fatimah, & I. Afrianto. (2021). Penerapan Teknologi Keamanan Enkripsi, SQL Injection, XSS Prevention, CSRF Prevention pada Aplikasi Manajemen Stok Barang. Jurnal Teknik Informatika UNIKOM.

Rohmah, N., Nugroho, A., & Sugiharto, D. (2022). Analisis Kerentanan Keamanan Sistem Informasi Akademik Universitas Bina Darma Menggunakan OWASP. Jurnal Sistem Informasi.

Ashari, I. F., Rakhmat, D. A., & Irnanda, D. (2023). Analisis Kerentanan Keamanan Website kuliah.itera.ac.id Menggunakan OWASP ZAP. Jurnal Teknologi Informasi.

Golinelli, M., Mainardi, S., & Nardelli, G. (2023). The Danger of Reused Nonces in CSP: A Measurement Study. Proceedings of the ACM Conference on Computer and Communications Security (CCS).

Lahmadi, A., Khalfallah, M., & Festor, O. (2020). Fingerprinting and Detecting Script Bypass in Content Security Policy Using HashCSP. Journal of Cybersecurity, 6(2), 102–114.

Shar, L. K., Poskitt, C. M., & Bhowmik, A. A. (2022). XSS for the Masses: Integrating Security in a Web Programming Course Using a Security Scanner. arXiv preprint, arXiv:2204.12416.

Gunawan, A., & Hartanto, D. (2022). Analisis Keamanan Website Sekolah Menggunakan Penetration Testing Metode Blackbox. Jurnal Sistem dan Teknologi Informasi, 11(1), 33–41.

Febriansyah, R., Rahman, M., & Yusuf, R. (2023). Analisis Kerentanan Keamanan Website Sistem Informasi Akademik STMIK Menggunakan OWASP ZAP. Jurnal Sistem Keamanan Digital, 6(2), 77–84.

Maniraj, S. P., Ranganathan, C. S., & Sekar, S. (2024). Securing Web Applications with OWASP ZAP for Comprehensive Security Testing. International Journal of Advanced Science and Information Systems, 10(2), 12–23. doi:10.29284/ijasis.10.2.2024.12-23.

Fanani, G. P. I., Mu’min, M. A., & Tristanti, N. (2025). Analisis dan Pengujian Kerentanan Website Menggunakan OWASP ZAP. Jurnal Riset Sistem dan Teknologi Informasi, 3(1), 36–50. doi:10.30787/restia.v3i1.1886.

Putra, F. P. E., Ubaidi, U., Hamzah, A., Pramadi, W. A., & Nuraini, A. (2024). Systematic Literature Review: Security Gap Detection on Websites Using OWASP ZAP. Brilliance Research on Artificial Intelligence, 4(1), 348–355. doi:10.47709/brilliance.v4i1.4227.

Potti, U.-S., Huang, H.-S., Chen, H.-T., & Sun, H.-M. (2025). Security Testing Framework for Web Applications: Benchmarking OWASP ZAP. University Academic Cluster International Conference, Tokyo/Kyoto.

Permana, A. (2020). Analisis Kerentanan Website terhadap Serangan Cross-Site Scripting (XSS) dengan Metode Penetration Testing. Jurnal Informatika dan Teknologi Komputer, 6(1), 15–22.

OWASP Foundation. (n.d.). Clickjacking Defense Cheat Sheet. OWASP Cheat Sheet Series.

MITRE. (n.d.). About CWE – Common Weakness Enumeration. Common Weakness Enumeration (CWE).

OWASP Foundation. (2021). OWASP Top 10:2021. OWASP Foundation.

Downloads

Published

2026-06-30

How to Cite

Suhenri Lubis, A., Nurmi Hidayasari, & Zuliar Efendi. (2026). Implementasi Keamanan Website Alfarouq Tour Travel Berdasarkan Temuan Kerentanan Owasp Zap. Jurnal Elektronika Dan Teknik Informatika Terapan ( JENTIK ), 4(2), 159–175. https://doi.org/10.59061/jentik.v4i2.1547