Journal on Pustaka Cendekia Informatika
Vol. 3 No. 1 (2025): Journal on Pustaka Cendekia Informatika: Volume 3 Nomor 1 February - May 2025

Analisis Kerentanan Web Menggunakan ZAP oleh Checkmarx pada Situs Kuliah Daring LMS Universitas Kebangsaan Republik Indonesia: Penelitian

Mughni Al Muzaki (Unknown)
Reksi Zender Perdian (Unknown)
Rohman Fajar (Unknown)
Saripah (Unknown)
Syifa Khofifah (Unknown)
Subhanjaya Angga Atmaja (Unknown)



Article Info

Publish Date
09 Jul 2025

Abstract

This study aims to conduct a security analysis on the online lecture site using the ZAP (Zed Attack Proxy) tool version 2.16.1, developed by OWASP and distributed by Checkmarx. The method used is black-box testing with an active scanning approach to identify security vulnerabilities that may exist in the application. The scanning process was carried out on all main pages and site resources, paying attention to various aspects such as HTTP headers, session management, JavaScript library usage, and other security configurations. The results of the scanning process showed 14 potential vulnerabilities classified into four risk levels: high (1 finding), medium (4 finding), low (6 finding), and informational (3 finding). The most significant findings were the use of a vulnerable (outdated) JavaScript library, the absence of a content security policy (CSP), and deficiencies in the implementation of important HTTP headers such as X-Frame-Options, Strict-Transport-Security, and X-Content-Type-Options. In addition, weaknesses in cookie attributes and the use of external JavaScript files without adequate source control were also found. Based on these results, a series of recommendations were developed that adhere to OWASP standards, including updating software libraries, reconfiguring security headers, strengthening session management, and implementing more secure cache policies.

Copyrights © 2025






Journal Info

Abbrev

pcif

Publisher

Subject

Aerospace Engineering Automotive Engineering Chemical Engineering, Chemistry & Bioengineering Electrical & Electronics Engineering Industrial & Manufacturing Engineering

Description

Journal on Pustaka Cendekia Informatika (PCIF) is published by the PT PUSTAKA CENDEKIA GROUP (NOMOR : AHU-012686.AH.01.30.Tahun 2023) in helping academics, researchers, and practitioners to disseminate their research results. PCIF is a double blind peer-reviewed journal dedicated to publishing ...