Javascript must be enabled to continue!
Implementasi Keamanan Website Alfarouq Tour Travel Berdasarkan Temuan Kerentanan Owasp Zap
View through CrossRef
Websites used for tourism services process personal and transaction information, making security evaluation important to reduce the risk of misuse and data exposure. This study implements security improvements on the Alfarouq Tour Travel website based on vulnerability findings identified using OWASP Zed Attack Proxy (ZAP). The research uses an applied experimental approach consisting of an initial security scan, classification and analysis of findings, planning and implementation of remediation, re-scanning, and comparison of conditions before and after remediation. The initial scan using OWASP ZAP 2.16.1 on 25 April 2025 found no High-risk alerts, but identified three Medium-risk alert types with 57 instances: Absence of Anti-CSRF Tokens (1), Content Security Policy Header Not Set (30), and Missing Anti-clickjacking Header (26). Remediation was implemented through CSRF token protection and request-flow adjustment, Content Security Policy configuration, and X-Frame-Options together with the frame-ancestors directive. The re-scan on 30 December 2025 showed that all three Medium-risk alert types were no longer detected, reducing Medium instances from 57 to 0. Six Low-risk and six Informational alert types remained. The findings indicate that remediation based on ZAP results met the study’s success indicator for the three targeted Medium-risk findings within the tested scope, while further assessment is still required for residual findings and system areas not reached by the scan.
Title: Implementasi Keamanan Website Alfarouq Tour Travel Berdasarkan Temuan Kerentanan Owasp Zap
Description:
Websites used for tourism services process personal and transaction information, making security evaluation important to reduce the risk of misuse and data exposure.
This study implements security improvements on the Alfarouq Tour Travel website based on vulnerability findings identified using OWASP Zed Attack Proxy (ZAP).
The research uses an applied experimental approach consisting of an initial security scan, classification and analysis of findings, planning and implementation of remediation, re-scanning, and comparison of conditions before and after remediation.
The initial scan using OWASP ZAP 2.
16.
1 on 25 April 2025 found no High-risk alerts, but identified three Medium-risk alert types with 57 instances: Absence of Anti-CSRF Tokens (1), Content Security Policy Header Not Set (30), and Missing Anti-clickjacking Header (26).
Remediation was implemented through CSRF token protection and request-flow adjustment, Content Security Policy configuration, and X-Frame-Options together with the frame-ancestors directive.
The re-scan on 30 December 2025 showed that all three Medium-risk alert types were no longer detected, reducing Medium instances from 57 to 0.
Six Low-risk and six Informational alert types remained.
The findings indicate that remediation based on ZAP results met the study’s success indicator for the three targeted Medium-risk findings within the tested scope, while further assessment is still required for residual findings and system areas not reached by the scan.
Related Results
Influence of ZAP-70 Expression On Migration of Chronic Lymphocytic Leukemia (CLL) and Lymphoma Cells.
Influence of ZAP-70 Expression On Migration of Chronic Lymphocytic Leukemia (CLL) and Lymphoma Cells.
Abstract
Abstract 2345
Poster Board II-322
ZAP-70 (ξ-associated protein) is a tyrosine kinase (PTK) of the Syk/ZAP family normally expr...
Analisis Kerentanan Keamanan Website Sekolah Menggunakan Metode Vulnerability Assessment Berbasis OWASP ZAP
Analisis Kerentanan Keamanan Website Sekolah Menggunakan Metode Vulnerability Assessment Berbasis OWASP ZAP
Perkembangan teknologi informasi yang pesat telah mendorong pemanfaatan website dalam berbagai sektor, termasuk pada lingkungan pendidikan sebagai media penyampaian informasi dan l...
TINJAUAN HUKUM ISLAM TERHADAP STRATEGI PEMASARAN TOUR TRAVEL HAJI DAN UMRAH PADA PT. DARMAWAN TOUR & TRAVEL
TINJAUAN HUKUM ISLAM TERHADAP STRATEGI PEMASARAN TOUR TRAVEL HAJI DAN UMRAH PADA PT. DARMAWAN TOUR & TRAVEL
Abstrak
Pokok permasalahan penelitian ini adalah bagaimana hukum islam terhadap strategi pemasaran tour travel haji dan umrah pad PT. Darmawan tour & Travel. Pokok masalah ter...
Estado nutricional y medidas antropométricas en escolares Zapotecas y no Zapotecas de Oaxaca, México
Estado nutricional y medidas antropométricas en escolares Zapotecas y no Zapotecas de Oaxaca, México
Introduction: Indigenous groups face discrimination and exclusion, which generates inequities in the field of health. In addition, they are nutritionally vulnerable, which affects ...
[RETRACTED] Keanu Reeves CBD Gummies v1
[RETRACTED] Keanu Reeves CBD Gummies v1
[RETRACTED]Keanu Reeves CBD Gummies ==❱❱ Huge Discounts:[HURRY UP ] Absolute Keanu Reeves CBD Gummies (Available)Order Online Only!! ❰❰= https://www.facebook.com/Keanu-Reeves-CBD-G...
ANALISIS KEAMANAN WEBSITE PLANET KOMPUTER KEBUMEN MENGGUNAKAN METODE VULNERABILITY ASSESSMENT DENGAN TEMUAN 4 KERENTANAN TINGKAT MENENGAH
ANALISIS KEAMANAN WEBSITE PLANET KOMPUTER KEBUMEN MENGGUNAKAN METODE VULNERABILITY ASSESSMENT DENGAN TEMUAN 4 KERENTANAN TINGKAT MENENGAH
Penelitian ini bertujuan untuk menganalisis keamanan website Planet Komputer Kebumen dengan menerapkan metode Vulnerability Assessment. Pendekatan ini dilakukan untuk mengidentifik...
Kerentanan Sosial pada Wilayah Potensi Bencana Tsunami di Pesisir Kecamatan Rajabasa Kabupaten Lampung Selatan
Kerentanan Sosial pada Wilayah Potensi Bencana Tsunami di Pesisir Kecamatan Rajabasa Kabupaten Lampung Selatan
Wilayah pesisir Kecamatan Rajabasa Kabupaten Lampung Selatan memiliki potensi bencana tsunami karena berbatasan langsung dengan Selat Sunda Utara yang terdapat Gunung Anak Krakatau...
OWASP za vse, ne samo za razvijalce
OWASP za vse, ne samo za razvijalce
OWASP (Open Web Worldwide Application Security Project) je mednarodna neprofitna organizacija, ki se ukvarja z izboljšanjem varnosti programske opreme. Projekt je zasnovan kot odpr...

