Claim Missing Document
Check
Articles

Found 1 Documents
Search
Journal : METIK JURNAL

Penetration Testing Website E-Journals Metode NIST SP 800-115 dan OWASP Mifthahuddin, Mifthahuddin; Setyadi, Hario Jati; Ibrahim, Muhammad Rivani
METIK JURNAL (AKREDITASI SINTA 3) Vol. 9 No. 1 (2025): METIK Jurnal
Publisher : LPPM Universitas Mulia

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.47002/metik.v9i1.1030

Abstract

The development of information technology has encouraged the digitization of scientific publications through e-journals, which facilitate access and distribution of scientific papers online. Mulawarman University uses Open Journal Systems (OJS) as a publication platform but still relies on version 2 which has several security gaps. This research aims to analyse the level of security vulnerabilities on the e-journals website of Mulawarman University using the penetration testing method based on NIST SP 800-115 and OWASP Top 10 parameters in 2021. This method includes four main stages: planning, discovery, attack, and reporting. Testing was conducted using various tools to identify and validate security holes. The results found 27 vulnerabilities, consisting of 1 high risk, 6 medium risk, 13 low risk, and 7 informational. Some of the main vulnerabilities that were successfully validated include Cross-Site Scripting, Clickjacking, Session Hijacking, Information Disclosure, and Cross-Site Request Forgery. These findings indicate significant weaknesses in access control, security configuration, and session management. Each vulnerability was analysed to understand its impact on data integrity and confidentiality. Proposed remediation recommendations include strengthening security header configuration, input/output validation, and removal of unnecessary system information. This research provides empirical insight into specific vulnerabilities in OJS version 2 at Mulawarman University, which has never conducted penetration testing with a framework using international standards, which is an original contribution to efforts to improve the security of academic publication systems.
Co-Authors Adiputra, Dimas Bayu ahmad arifin Aji Prasetya Wibawa Al Hidayat, Muhammad Restu Al'Aqsa, Muhammad Ramadhan Alifia, Shafa Nur Aljidannur, Andi Muhammad Rivaldy Amal, Fakhmul Amin Padmo Azam Masa Amin Padmo Azam Masa Andika, Arya Bhima Anggraini, Nela Dwi Anton Prafanto Apriansyah, Muhammad Dandi Aprilia, Trisna Aprilianto, Riky Ardana, Utari Widya Ari Pradhana, Alvin Arif, Afdinal Arinda Mulawardani Kustiawan Arviani, Syilla Aulia, Hadriani Avivah, Nur Ayu Rusnawati Azhari, Ikmal Ali Badaruddin Bin Halib Basani, Yuniarta Budiman, Edy Budiman, Edy Chrisman Bonor Sinaga Dinda Izmya Nurpadillah Dwicky Ari Pandawa Dyna Marisa Khairina Fadhilah, Farah Fahriza, Ridho Fajar Syafatoni Raihanadif Felix Andika Dwiyanto Galih Yudha Saputra Ghalda Melika Gibrani, Muhammad Raza Daffa Gubtha Mahendra Putra Hairah, Ummu Hairunnisa, Namira Aida Handoko, Heldi Harianto, Biko Harsyal Kila, Hiskya Hasman, Firnawan Azhari Haviluddin Haviluddin Herman Santoso Pakpahan Husyairi, Rizani Ibrahim, Muhammad Rivani Indah Fitri Astuti, Indah Fitri Indra Maulana, Indra Irsyad, Akhmad Islamiyah Islamiyah Islamiyah Islamiyah Islamiyah Islamiyah Islamiyah, Islamiyah Jundillah, Muhammad Labib Kamila, Vina Zahrotun Kelvin Wong Kusumawardani, Aditya Putri Listiana Dewi Milasari Madani, Mohammad Ichsan Masa, Amin Padmo Azam Mifthahuddin, Mifthahuddin Mila Kartika Sari Muhamad Ali Muhammad Bambang Muhammad Hisyam Nugroho Muhammad Labib Jundillah Nadia Nadia Nasrullah, Ryanda Putra Nataniel Dengen Nazwa Tri Ananda Ni’mah Moham Ni’mah Moham Novianti Puspitasari Nurlaila Nurlaila Nurwahyu, Ferryza Prafanto, Anton Prasetya, Raya Priantono, Ahmad Agung Purnawansyah Purnawansyah Puspitasari, Novianti Putra, Gubtha Mahendra Putut Pamilih Widagdo Putut Pamilih Widagdo Putut Pamilih Widagdo, Putut Pamilih Rabbani, Zaki Fauzan Ramadiani Ramadiani - Rapiq, Rayhan Abdilah Rara Puspa Aisyah Rayner Alfred Rayner Alfred Reza Wardhana Ririn Yuliani Azahra Zardan Rosita Dewi Rosmasari Rosmasari, Rosmasari Ryan Afriadi Whardana Sagita, Andi Yolanda Sandrina Aulia Saputra, Muhammad Fawaz Saputra, Muhammad Rizq Sari, Upik Kumala Shiva Mutia Maffirotin Sidabutar, Erni Veronica Siti Solikah Yosi Karinda Supriono Supriono Taruk, Medi Tejawati, Andi Tobing, Christina Febriyanti Ulhaq, Dhiya Untu, Zainuddin Untu Upik Kumala Sari Utama, Chorine Jessica Vina Zahrotun Kamila Wage Jason Wahyu Kesuma Bakti Wahyudi, Asnan Fadjri Wanda, Awang Muhammad Trielevy Wardana, Romy Hakim Wardhana, Reza Wati, Masna Wong, Kelvin Yunus, Ahmad