IMPLEMENTATION OF PASSWORD HASHING TO ENHANCE WEB-BASED LOGIN SYSTEM SECURITY

Authors

Keywords:

Password Hashing, Web Security, Login System, Laravel, Authentification

Abstract

User data security is a critical aspect of web-based system development, particularly for login systems that utilize passwords for authentication. Storing passwords in plaintext poses a security risk should the database be accessed by unauthorized parties. This study aims to implement password hashing in a web-based login system using the Laravel framework to enhance the security of stored user authentication data. The research methodology encompasses requirements analysis, system design, implementation, testing, and results analysis. Implementation involves hashing passwords prior to database storage, while the login process relies on verifying the input against the stored hash value. Testing was conducted using the black-box method across various scenarios, including user registration, database password checks, login attempts with correct and incorrect passwords, and the logout process. The results demonstrate that user passwords were successfully stored as hashes rather than plaintext. Furthermore, the authentication process functioned correctly, as the system was able to verify user-entered passwords against the stored hash values. These findings indicate that implementing password hashing with Laravel is an effective measure for improving the security of user credential storage in web-based login systems.

References

[1] R. Dafi Al Azhar and I. Sholihah Widiati, “Evaluasi Keamanan Penyimpanan Password Menggunakan Algoritma Hash: MD5, SHA-1, dan Bcrypt,” Pros. Semin. Nas. Teknol. Inf. dan Bisnis, pp. 1302–1305, 2025, doi: 10.47701/q885nj69.

[2] M Aditya Firmansyah, Qarinah, and Muhlis Tahir, “Integrasi Algoritma SHA-256 dan AES untuk Pengamanan Kredensial dan Data Sensitif pada Sistem Informasi Kepegawaian,” J. Komput. Teknol. Inf. Sist. Komput., vol. 5, no. 1, pp. 462–468, 2026, doi: 10.62712/juktisi.v5i1.1032.

[3] J. Prastyia, G. Agam Alfarizi, S. Romadhon, and F. Pratama, “Pembuatan Website Company Profile Pt. Muhammad Syahri Purnama Menggunakan Metode Hashing,” JATI (Jurnal Mhs. Tek. Inform., vol. 9, no. 1, pp. 1176–1182, 2024, doi: 10.36040/jati.v9i1.12550.

[4] Y. Arafat, T. Hidayat, M. Khozin, K. Kunci -Autentikasi, K. Siber, and S. Login, “Implementasi Penggunaan Bcrypt Dan Passkey Pada Sistem Login Web Di Smk Negeri 1 Xyz,” vol. 11, no. 1, pp. 70–76, 2026.

[5] M. C. Jayanti and D. A. Dermawan, “Implementasi Algoritma Hashing Pada Sistem Tracking Surat Himpunan Mahasiswa Prodi Dengan RAD ( Studi Kasus : Sarjana Terapan Manajemen Informatika ),” vol. 15, no. 1, pp. 66–76, 2026.

[6] S. Nasional, I. Fti, N. R. Anggraini, and B. A. Herlambang, “IN-FEST 2026 Implementasi Kriptografi Bcrypt Pada Sistem Informasi Dokumen Manajemen Mutu Berbasis Web IN-FEST 2026,” vol. 2026, pp. 60–68, 2026.

[7] T. Mary and N. Febriyani, “Peningkatan Keamanan Sistem Informasi Berbasis Laravel 12 dengan Rate Limiting dan Role-Based Access Control (RBAC),” J. Teknol. Dan Sist. Inf. Bisnis, vol. 7, no. 3, pp. 473–481, 2025, doi: 10.47233/jteksis.v7i3.1976.

[8] Ulil Asyhar, Budi Hartono, and Toni Wijanarko Adi Putra, “Implementasi Algoritma Base64 Pada Sistem Login Menggunakan Json Web Token (Jwt) Untuk Autentikasi Web,” J. Teknol. Inf. Dan Komun., vol. 17, no. 1, pp. 1–11, 2026, doi: 10.51903/jtikp.v17i1.1311.

[9] Nugroho Dwi Aji, Tomi Tri Sujaka, Husain, Ondi Asroni, and Kurniadin Abd. Latif, “Analisis Dan Implementasi Algoritma Bcrypt Dengan Affine Cipher Untuk Pengamanan Password Pada Aplikasi Web,” Cyber Secur. dan Forensik Digit., vol. 8, no. 1, pp. 1–9, 2025, doi: 10.14421/csecurity.2025.8.1.5076.

[10] R. Greslyana, S. Jatmika, and S. Arifin, “Development Of Adaptive Login Security Using A Combination Of AES And Bcrypt On The Laravel Framework,” ICoBITS, vol. 1, pp. 452–460, 2026, doi: 10.32664/icobits.v1.31.

[11] N. Ramadani and E. maiyana, “Perancangan dan Implementasi Sistem Informasi Perpustakaan BerbasisWeb Menggunakan Framework Laravel untuk Optimalisasi PengelolaanBuku dan Transaksi Peminjaman,” Neotech J. Inf. Technol. Innov., vol. 1, no. 01, pp. 01–17, 2026, [Online]. Available: https://journal.torkataresearch.org/index.php/neotech/article/view/10

[12] I. Q. Lubis and A. Zulherry, “Implementasi keamanan website dari serangan Cross Site Request Forgery menggunakan algoritma HMAC-SHA256 pada framework Laravel,” Hello World J. Ilmu Komput., vol. 5, no. 1, pp. 47–58, 2026.

[13] G. Maulana and U. I. Indragiri, “Analisis Keamanan Sistem Autentikasi Login Berbasis Framework Laravel,” vol. 1, no. 1, pp. 18–25, 2026.

[14] A. Fitriyani, H. Lubis, Y. Yaddarabullah, and R. Sari, “Keamanan Sistem Login Menggunakan Multifactor Authentication dan Algoritma Hashing,” J. Inf. Syst. Informatics Comput., vol. 9, no. 2, p. 263, 2025, doi: 10.52362/jisicom.v9i2.2137.

[15] D. Febrian et al., “Implementation of Bcrypt Algorithm on Website-Based Hashing Generator Using Laravel Framework,” J. Inf. Syst. Informatics Comput., vol. 7, no. 2, p. 199, 2023, doi: 10.52362/jisicom.v7i2.1130.

Downloads

Published

2026-08-31