Security is principal factor that matters in Web Applications. Penetration Testing now become the standard for security testing of applications before released to the public. Security analysis of the Functional Position Information System (JAFUNG) web application from BPS RI is conducted because BPS RI has important applications that assist in implementing statistical business processes. Therefore, conducting Grey-Box Penetration Testing is important to assess how resistant that application is. With PTES (Penetration Testing Execution Standard) testing method 2014 version for procedures and OWASP Risk Rating Methodology 2021 version for vulnerability assessment, counting attack scenarios by the BSSN Top 10 Vulnerabilities. Hopefully after conducting security testing, systematic analysis and assessment of vulnerabilities for the application will be obtained, counting a vulnerability category rating that accurately reflects the actual conditions, and hereafter, this research can be a reference for BPS in testing the security of applications to ensure the safety of statistical data.
Copyrights © 2024