bit-Tech
Vol. 8 No. 3 (2026): bit-Tech - IN PROGRESS

Evaluating Web Application Security Using OWASP Top 10 and NIST SP 800-115

Farrel Tiuraka Vierino (UPN Veteran Jawa Timur)
Henni Endah Wahanani (UPN Veteran Jawa Timur)
Achmad Junaidi (UPN Veteran Jawa Timur)



Article Info

Publish Date
10 Apr 2026

Abstract

Cybersecurity assurance for public-facing government websites remains critical amid accelerating digital transformation. This study adopts an exploratory–evaluative research design to systematically examine and validate the security posture of the Surabaya Public Slaughterhouse (RPH Surabaya) website through an integrated application of OWASP Top 10 (2021) as a vulnerability taxonomy and NIST SP 800-115 as a procedural testing framework. The methodology follows structured planning, discovery, attack, and reporting phases. Discovery combined reconnaissance tools (Nslookup, Whois, Nmap, Dirsearch, Wappalyzer, and Google Dorking) with OWASP ZAP scanning, while attack validation employed Burp Suite, SQLMap, and browser-based developer analysis within a controlled Kali Linux environment. Thirteen potential vulnerabilities were detected, of which ten were empirically confirmed after manual verification. Confirmed weaknesses were predominantly categorized as Security Misconfiguration, including missing Anti-CSRF protections, directory browsing exposure, absent Content Security Policy and anti-clickjacking headers, outdated JavaScript libraries, insecure cookie attributes (missing HttpOnly and SameSite), lack of Strict-Transport-Security and X-Content-Type-Options headers, and user-controllable HTML attributes. The contribution lies in demonstrating a reproducible dual-framework validation pipeline that distinguishes scanner alerts from confirmed exploitability, thereby strengthening methodological rigor in public-sector web security assessment. These findings indicate systemic configuration-level risk exposure that may elevate susceptibility to XSS, CSRF, clickjacking, and injection-related threats relative to comparable public-institution websites. However, the assessment is limited to a single institutional website and an unauthenticated testing scope, constraining generalizability and deeper application-layer analysis.

Copyrights © 2026






Journal Info

Abbrev

bt

Publisher

Subject

Computer Science & IT

Description

The bit-Tech journal was developed with the aim of accommodating the scientific work of Lecturers and Students, both the results of scientific papers and research in the form of literature study results. It is hoped that this journal will increase the knowledge and exchange of scientific ...