This Supervision Management Information System (SIMAWAS) is used to support the internal oversight process within the Inspectorate General of the Ministry of Forestry. However, the application has never undergone a comprehensive security assessment, especially after the domain change. This study aims to identify vulnerabilities in SIMAWAS using penetration testing methods with OWASP ZAP. The testing stages include planning, automated scanning, alert analysis, and recommendation formulation. The risk levels (Medium, Low, and Informational) were classified based on the OWASP Risk Rating Methodology, considering the likelihood and potential impact of each identified vulnerability. The results show that SIMAWAS has no high-risk vulnerabilities, but several Medium, Low, and Informational weaknesses were found, such as security misconfiguration, missing security headers, and insecure cookie settings. These vulnerabilities may be exploited if not addressed properly. Improvement recommendations were developed based on OWASP standards to enhance application security and prevent potential exploitation in the future.
Copyrights © 2026