Academic information system security is a crucial aspect in the development of technology and information today, especially in maintaining structured and comprehensive data from various threats. Academic Information System (AIS) XYZ which provides services based on HTTP or HTTPS protocols is vulnerable to hacker attacks through security holes that may not be realized by the website owner. This study aims to identify and analyze security vulnerabilities in the AIS and provide recommendations for improvements to improve the level of system security. Using the ISSAF method to evaluate system security. The tools used in the analysis include Whois, SSL Scan, Nmap, OWASP Zap, and LOIC to detect and test vulnerabilities on the website. From this study, 12 vulnerabilities were found, consisting of four medium level vulnerabilities, six in moderate vulnerabilities, and two information level vulnerabilities. In improving system security, it is recommended to make improvements to the vulnerabilities found, especially at high and medium levels, and to implement regular security monitoring to prevent future attacks.
Copyrights © 2025