Kharisma Tech
Vol 17 No 1 (2022): Jurnal KHARISMATEch

ANALISIS KERENTANAN WEBSITE RENOVACTION MENGGUNAKAN RANGKAIAN SECURITY TOOLS PROJECT BERDASARKAN FRAMEWORK OWASP

Erlan Darwis (STMIK KHARISMA Makassar)
Junaedy (Universitas Islam Makassar)
Izmy Alwiah Musdar (STMIK KHARISMA Makassar)



Article Info

Publish Date
20 May 2022

Abstract

The purpose of this research is to analyze website vulnerabilities to avoid cyber attacks, especially on cross site scripting &sql injection types by applying OWASP Top 10 2017 rules to find security gaps by performing automated scans using ajax spiders after which active scans and manual scans use fuzzer to perform more specific exposures to cross-site scripting (XSS) and SQL injection types. After testing the web RenovAction vulnerabilities found Cross-Domain Misconfiguration, Secure Pages Include Mixed Content, X-Frame-Options Header Not Set, Absence of Anti-CSRF Tokens, Cookie No HttpOnly Flag, Cross-Domain JavaScript Source File Inclusion, Incomplete or No Cache-control Header Set, X-Content-Type-Options Header Missing, Charset Mismatch, dan Information Disclosure - Suspicious Comments, Timestamp Disclosure – Unix., in addition to getting vulnerabilities in the RenovAction web, the author also provided a solution to overcome vulnerabilities in the RenovAction web based on the Zed Attack Proxy (ZAP) tool.

Copyrights © 2022






Journal Info

Abbrev

kharismatech

Publisher

Subject

Computer Science & IT Engineering

Description

Jurnal Ilmu Komputer merupakan jurnal yang menampung hasil penelitian di bidang informatika dan sistem informasi, mencakup : - Sistem Informasi - Informatika - Teknologi Informasi - Ilmu Komputer - Software ...