Analisis Kerentanan Keamanan pada Website Kelurahan Rimba Sekampung dengan Menggunakan Framework OWASP ZAP
DOI:
https://doi.org/10.31004/jutin.v8i4.48523Keywords:
Website Security, OWASP ZAP, Vulnerability, Penetration Testing, Security AssessmentAbstract
The security of web-based applications is increasingly important due to evolving cyber threats. This study analyzes the security vulnerabilities of the Kelurahan Rimba Sekampung website using the OWASP ZAP tool to identify potential weaknesses and recommend mitigation strategies. The methodology includes automated scanning, vulnerability analysis, and applying security improvements. The initial scan identified 15 vulnerabilities, including issues under Broken Access Control, Security Misconfiguration, Cryptographic Failures, Use of Vulnerable and Outdated Components, and Software and Data Integrity Failures. After implementing mitigation measures, the number of vulnerabilities was reduced to 12. Key improvements included strengthening the Content Security Policy (CSP), enhancing encryption mechanisms, and configuring HTTP headers and cookies correctly. These actions significantly reduced the website’s security risks. The results of this study can serve as a reference for web administrators in enhancing application security and safeguarding user data.References
Ariyadi, T., Widodo, T. L., Apriyanti, N., & Kirana, F. S. (2023). Analisis Kerentanan Keamanan Sistem Informasi Akademik Universitas Bina Darma Menggunakan OWASP. Techno.Com, 22(2), 418–429. https://doi.org/10.33633/tc.v22i2.7562
Aryanti, D., & Utamajaya, J. N. (2021). Analisis Kerentanan Keamanan Website Menggunakan Metode OWASP (Open Web Application Security Project) Pada Dinas Tenaga Kerja. Jurnal Syntax Fusion, 1(03), 15–25.
Edy Listartha, I. M., Premana Mitha, I. M. A., Aditya Arta, M. W., & Yuda Arimika, I. K. W. (2022). Analisis Kerentanan Website SMA Negeri 2 Amlapura Menggunakan Metode OWASP (Open Web Application Security Project). Simkom, 7(1), 23–27. https://doi.org/10.51717/simkom.v7i1.63
Riandhanu, I. O. (2022). Analisis Metode Open Web Application Security Project (OWASP) Menggunakan Penetration Testing pada Keamanan Website Absensi. Jurnal Informasi Dan Teknologi. https://doi.org/10.37034/jidt.v4i3.236
Ghozali, B., Kusrini, K., & Sudarmawan, S. (2019). Mendeteksi kerentanan keamanan aplikasi website menggunakan metode OWASP (Open Web Application Security Project) untuk penilaian risk rating. Creative Information Technology Journal, 4(4), 264–275. https://citec.amikom.ac.id/main/index.php/citec/article/view/119
Tangkudung, I., Dako, R. D. R., & Dako, A. Y. (2019). Evaluasi website menggunakan metode ISO/IEC 25010. In SemanTECH (Seminar Nasional Teknologi, Sains dan Humaniora) (pp. 87–107).
Sinaga, A. S. R. M. (2020). Keamanan komputer. CV Insan Cendekia Mandiri.
Zahra, N. A., Zidane, F. H., & Kuslaila, N. R. (2023). Analisis keamanan sistem informasi pada website PT Sentra Vidya Utama (SEVIMA) menggunakan metode OWASP. Prosiding Seminar Nasional Teknologi dan Sistem Informasi, 3(1), 384–393. https://doi.org/10.33005/sitasi.v3i1.564
Hidayatulloh, S., & Saptadiaji, D. (2021). Penetration testing pada website Universitas ARS menggunakan Open Web Application Security Project (OWASP). Jurnal Algoritma, 18(1), 77–86. https://doi.org/10.33364/algoritma/v.18-1.827
Al’am’yubi, M. R. S., & Wijayanto, D. (2023). Analisis sistem keamanan website XYZ menggunakan framework OWASP ZAP. Jurnal Ilmu Komputer, 3(1), 1–5. https://journal.umgo.ac.id/index.php/juik/index
Adinugroho, N. B., Hendradi, P., & Sasongko, D. (2022). Analisis keamanan e-learning menggunakan Open Web Application Security Project (OWASP) (Studi kasus MOCA UNIMMA). Jurnal Informatika, 22(2), 132–138. https://doi.org/10.30873/ji.v22i2.3327
OWASP. (n.d.). About OWASP. Retrieved July 16, 2024, from https://www.owasp.org/index.php/About_OWASP
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2025 Nurasmawati Nurasmawati, Mansur Mansur, Nurmi Hidayasari

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.

