The integration of web-based information systems in the business sector, such as the planetkomputer.my.id website, is crucial for providing efficient services, yet it remains highly vulnerable to exploitation threats and data integrity manipulation. A real problem discovered in this research object is data inconsistency caused by abnormal price changes in the shop's product price list. This study aims to identify the exact location of these security flaws—whether originating from application code or server misconfigurations—while comparing the effectiveness of security scanning tools in detecting vulnerabilities. The proposed method is a qualitative-descriptive applied security assessment using a Black-Box Testing approach with two security scanners, namely OWASP Zed Attack Proxy (ZAP) and Nikto, executed through the stages of Reconnaissance, Vulnerability Scanning, and Data Analysis. The results indicate that both tools successfully identified several security vulnerabilities with Medium to Low risk levels. The core synthesis reveals complementary detection characteristics; OWASP ZAP proved thorough in detecting web application logic and session weaknesses, such as the absence of Anti-CSRF tokens and the HttpOnly flag on cookies, whereas Nikto was more sensitive in identifying misconfigurations at the web server architecture level and network technical information leaks. In conclusion, combining these two assessment tools is highly effective in providing a comprehensive security evaluation to formulate neat and systematic mitigation recommendations for the shop's IT infrastructure management.
Copyrights © 2025