Ermadi Satria Wijaya
Program Studi Teknik Informatika, Universitas Muhammadiyah Purwokerto, Indonesia

Published : 1 Documents Claim Missing Document
Claim Missing Document
Check
Articles

Found 1 Documents
Search

Analisis Keamanan Website Sekolah MAN 1 Banyumas Menggunakan Penetration Testing Execution Standard (PTES) Dewi Mardiana; Sigit Sugiyanto; Harjono Harjono; Ermadi Satria Wijaya
Jurnal Teknologi Informasi dan Multimedia Vol. 8 No. 3 (2026): August
Publisher : Sekawan Institut

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.35746/jtim.v8i3.1102

Abstract

Digital transformation is driving educational institutions to adopt web portals, yet cybersecurity evaluation is still often neglected. This study aims to identify and validate security vulnerabilities on the official website of MAN 1 Banyumas using the Penetration Testing Execution Standard (PTES) framework. Testing was conducted using a black-box penetration testing approach by combining Open Worldwide Application Security Project (OWASP ZAP) scanning and manual verification to reduce false positives. The results showed the discovery of 4 true positive vulnera-bilities, 1 false positive, and medium-risk FTP and SSH ports. Validated vulnerabilities include Cross-Site Request Forgery (CSRF), Clickjacking, session management weaknesses, and Vulnerable JS Library, while Cross-Site Scripting (XSS) vulnerabilities were confirmed as false positives. Simulation of vulnerability chaining showed that the combination of these vulnerabilities has the potential to lead to account takeover. Therefore, server hardening and JavaScript library updates are recommended to improve system security.