The high incidence of cyberattacks across various sectors reported by the National Cyber and Crypto Agency (BSSN) poses a serious threat to data and service security in application systems, including at Makassar State University, which relies on web-based information technology for many of its activities, thereby creating potential risks to its website security. This study aims to evaluate the security of the domain unm.ac.id and its subdomains using penetration testing methods, identify security vulnerabilities based on the OWASP Top 10, and develop relevant mitigation strategies. The method used is penetration testing through several stages: information gathering, enumeration, vulnerability scanning, exploitation, OWASP Top 10–based security classification, risk assessment using CVSS 3.1, and formulation of mitigation strategies. The results identified 9 validated vulnerability types, with the majority of OWASP Top 10 classifications falling under security misconfiguration, cryptographic failures, and the use of vulnerable or outdated components. Most vulnerabilities were at medium, low, and informational levels. It can therefore be concluded that security mechanisms on the website have been implemented, but periodic evaluation and reinforcement of security are still required to minimize potential risks and prevent future attacks.
Copyrights © 2026