Main Article Content

Abstract

Wahid Hasyim University has a website that contains information and documents that are published and can be accessed by users. One of the most crucial websites is the New Student Admissions (PMB) website. The rise of population data leaks in Indonesia has opened our eyes that behind the advancement of digital technology there is a fairly high level of threat. Based on the existing problems, an analysis of the level of website security is needed by using the Open Web Application Security Project (OWASP) security standard, which can ease the burden on system managers and developers with the aim of preventing and overcoming the effects of risks found on the New Student Admissions website at Wahid Hasyim University Semarang. Testing the security system used by researchers in this study is using the Open Web Application Security Project's security standard (OWASP), which is the top 10 of the security standards released by the organization (OWASP) which contains the 10 highest lists of security holes that threaten the security of a website, and using (OWASP-ZAP) Zed Attack Proxy is an application used in penetration testing to find security vulnerabilities/holes in a website application. The test method with (OWASP) can provide assistance in choosing the actions that need to be taken to minimize data leakage vulnerabilities. Based on the results of the analysis using (OWASP-ZAP) several loopholes and vulnerabilities were found on the website. Based on the results of the penetration test, the quality of website security for New Student Admissions is at a moderate level, so further corrective action is needed from the website developer to improve website security.

Keywords

OWASP Top 10 Website Security OWASP-ZAP SQL Injection Local File Inclusion

Article Details

References

  1. Begum, A., Hassan, M. M., Bhuiyan, T., & Sharif, M. H. (2017). RFI and SQLi based local file inclusion vulnerabilities in web applications of Bangladesh. IWCI 2016 - 2016 International Workshop on Computational Intelligence, June 2018, 21–25. https://doi.org/10.1109/IWCI.2016.7860332
  2. Fatma, W. D. (2018). Analisa Keamanan Server Pada Login Page Webserver Dengan Enkripsi Sha 1 Dari Serangan Sql Injection Menggunakansystemoperasi Kali Linux Di Lkp Multi Logika Binjai.
  3. Guntoro, G., Costaner, L., & Musfawati, M. (2020). Analisis Keamanan Web Server Open Journal System (Ojs) Menggunakan Metode Issaf Dan Owasp (Studi Kasus Ojs Universitas Lancang Kuning). JIPI (Jurnal Ilmiah Penelitian Dan Pembelajaran Informatika), 5(1), 45. https://doi.org/10.29100/jipi.v5i1.1565
  4. Irawan, A. S., Pramukantoro, E. S., & Kusyanti, A. (2018). Pengembangan Intrusion Detection System Terhadap SQL Injection Jurnal Pengembangan Teknologi Informasi Dan Ilmu Komputer (J-PTIIK) Universitas Brawijaya, 2(6), 2295–2301.
  5. Koprawi, M. (2020). Dampak dan Pencegahan Serangan File Inclusion: Perspektif Developer. InfoTekJar : Jurnal Nasional Informatika Dan Teknologi Jaringan, 5(1), 40–43. https://doi.org/10.30743/infotekjar.v5i1.1997
  6. LAYUK, K. Y. (2021). Analisis Keamanan Jaringan Web Server Menggunakan Suricata Pada Sekolah Menengah Pertama Negeri 1 Palopo. http://repository.uncp.ac.id/412/
  7. Riandhanu, I. O. (2022). Analisis Metode Open Web Application Security Project (OWASP) Menggunakan Penetration Testing pada Keamanan Website Absensi. Jurnal Informasi Dan Teknologi, 4(3), 160–165. https://doi.org/10.37034/jidt.v4i3.236
  8. Safitri, E. M., Ameilindra, Z., & Yulianti, R. (2020). Analisis Teknik Social Engineering Sebagai Ancaman Dalam Keamanan Sistem Informasi: Studi Literatur. Jurnal Ilmiah Teknologi Informasi Dan Robotika, 2(2), 21–26. https://doi.org/10.33005/jifti.v2i2.26
  9. Yudiana, Y., Elanda, A., & Buana, R. L. (2021). Analisis Kualitas Keamanan Sistem Informasi E-Office Berbasis Website Pada STMIK Rosma (Journal of Computer Engineering, System and Science), 6(2), 185. https://doi.org/10.24114/cess.v6i2.24777