ANALISIS KEAMANAN SEBUAH DOMAIN MENGGUNAKAN OPEN WEB APPLICATION SECURITY PROJECT (OWASP) Zap

Nuniek Herawati, Verry Budiyanto, Uminingsih
{"title":"ANALISIS KEAMANAN SEBUAH DOMAIN MENGGUNAKAN OPEN WEB APPLICATION SECURITY PROJECT (OWASP) Zap","authors":"Nuniek Herawati, Verry Budiyanto, Uminingsih","doi":"10.34151/technoscientia.v15i2.4013","DOIUrl":null,"url":null,"abstract":"Along with the development of information technology among the wider community, information systems make it easier for people to access and search for information in the form of websites. The problem of security risk is one of the important aspects of an information system. But, security risks are somehow less priority to be considered. In the present work, a security analysis of a domain was conducted using the Open Web Application Security Project (OWASP) Zap. The research method used is literature review and observation. The literature review is used to collect relevant previous research literatures as well as relevant theories and concepts in terms of Vulnerability Analysis. The literatures are obtained from journals, books, scientific papers, and digital media such as the internet. While observation is used to determine, sort, collect, and review the data needed in the test. The results of show that several vulnerabilities on the akprind.ac.id site that can have a detrimental impact on the campus. The security system on several akprind subdomains still does not meet the CIA TRIAD security principle, namely confidentiality. The OWASP Zap tools are still good as a basis for conducting penetration testing on several sites with the akprind.ac.id domain. Because there are still some security issues that match the owasp list. It is hoped that for the IST AKPRIND web, further research needs to be carried out using the ISSAF (Information System Security Assessment Framework) method so that it can be known more deeply if there are vulnerabilities from the web server.","PeriodicalId":301828,"journal":{"name":"JURNAL TEKNOLOGI TECHNOSCIENTIA","volume":"39 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-03-31","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"JURNAL TEKNOLOGI TECHNOSCIENTIA","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.34151/technoscientia.v15i2.4013","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

Along with the development of information technology among the wider community, information systems make it easier for people to access and search for information in the form of websites. The problem of security risk is one of the important aspects of an information system. But, security risks are somehow less priority to be considered. In the present work, a security analysis of a domain was conducted using the Open Web Application Security Project (OWASP) Zap. The research method used is literature review and observation. The literature review is used to collect relevant previous research literatures as well as relevant theories and concepts in terms of Vulnerability Analysis. The literatures are obtained from journals, books, scientific papers, and digital media such as the internet. While observation is used to determine, sort, collect, and review the data needed in the test. The results of show that several vulnerabilities on the akprind.ac.id site that can have a detrimental impact on the campus. The security system on several akprind subdomains still does not meet the CIA TRIAD security principle, namely confidentiality. The OWASP Zap tools are still good as a basis for conducting penetration testing on several sites with the akprind.ac.id domain. Because there are still some security issues that match the owasp list. It is hoped that for the IST AKPRIND web, further research needs to be carried out using the ISSAF (Information System Security Assessment Framework) method so that it can be known more deeply if there are vulnerabilities from the web server.
开放WEB应用程序安全项目(OWASP) Zap
随着信息技术在更广泛的社区中的发展,信息系统使人们更容易以网站的形式访问和搜索信息。安全风险问题是信息系统的一个重要方面。但是,安全风险在某种程度上是不那么优先考虑的。在本工作中,使用开放Web应用程序安全项目(OWASP) Zap对一个域进行了安全分析。研究方法为文献回顾法和观察法。文献综述的方法是收集前人在脆弱性分析方面的相关研究文献以及相关的理论和概念。这些文献来自期刊、书籍、科学论文和互联网等数字媒体。而观察则用于确定、分类、收集和审查测试中所需的数据。结果表明,akprind.ac.id站点上的几个漏洞可能对校园产生不利影响。几个akprind子域上的安全系统仍然不符合CIA TRIAD安全原则,即保密性。OWASP Zap工具仍然可以很好地作为在akprind.ac.id域的几个站点上进行渗透测试的基础。因为仍然有一些安全问题与owasp列表相匹配。希望对于IST AKPRIND web,需要使用ISSAF (Information System Security Assessment Framework)方法进行进一步的研究,以便更深入地了解web服务器是否存在漏洞。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信