Implementasi Metode PTES dan NIST dalam Evaluasi Kerentanan Keamanan Website Resmi Pemerintah Kota Tarakan

Paembonan, Seprianto (2025) Implementasi Metode PTES dan NIST dalam Evaluasi Kerentanan Keamanan Website Resmi Pemerintah Kota Tarakan. Undergraduate thesis, Universitas Muhammadiyah Malang.

[thumbnail of PENDAHULUAN.pdf]
Preview
Text
PENDAHULUAN.pdf

Download (1MB) | Preview
[thumbnail of BAB I.pdf]
Preview
Text
BAB I.pdf

Download (429kB) | Preview
[thumbnail of BAB II.pdf]
Preview
Text
BAB II.pdf

Download (599kB) | Preview
[thumbnail of BAB III.pdf] Text
BAB III.pdf
Restricted to Registered users only

Download (335kB) | Request a copy
[thumbnail of BAB IV.pdf] Text
BAB IV.pdf
Restricted to Registered users only

Download (1MB) | Request a copy
[thumbnail of BAB V.pdf] Text
BAB V.pdf
Restricted to Registered users only

Download (270kB) | Request a copy
[thumbnail of LAMPIRAN.pdf] Text
LAMPIRAN.pdf
Restricted to Registered users only

Download (252kB) | Request a copy
[thumbnail of POSTER.pdf] Text
POSTER.pdf
Restricted to Registered users only

Download (91kB) | Request a copy

Abstract

The increasing use of digital services by the government has made public service websites a potential target for cyber attacks. This study aims to assess security vulnerabilities on the Tarakan City Government Official Website (portal.tarakankota.go.id) using two approaches, namely the Penetration Testing Execution Standard (PTES) and NIST SP 800-115. The testing process includes the steps of planning, information gathering, vulnerability analysis, exploitation, and reporting. The findings from this evaluation indicate several important vulnerabilities, such as the non-use of the HTTPS protocol and HSTS header, which makes data communication vulnerable to man-in-the-middle attacks, Host Header Injection vulnerabilities that allow for dangerous redirection, and Clickjacking due to the absence of the X-Frame-Options header. In addition, one SQL Injection vulnerability was found in the early stages, but could not be exploited because the input was well monitored. The PTES approach proved effective in the technical exploitation phase, while NIST SP 800-115 was effective in planning, documentation, and reporting. The combination of these two methods resulted in a more comprehensive assessment, covering technical and managerial elements, and offering security improvement recommendations, such as the implementation of SSL/TLS, security header settings, and strict validation of input parameters. This research emphasizes the importance of routine evaluation to strengthen cybersecurity in web-based public services.

Item Type: Thesis (Undergraduate)
Student ID: 202110370311005
Keywords: Website Security, Penetration Testing Execution Standard (PTES), NIST SP 800-115, Vulnerability Assessment
Subjects: T Technology > T Technology (General)
Divisions: Faculty of Engineering > Department of Informatics (55201)
Depositing User: 202110370311005 seprypaembonan
Date Deposited: 03 Feb 2026 06:21
Last Modified: 03 Feb 2026 06:21
URI: https://eprints.umm.ac.id/id/eprint/26945

Actions (login required)

View Item
View Item