ANALISIS KEAMANAN APLIKASI WEB MENGGUNAKAN WEB APPLICATION PENETRATION TESTING BERDASARKAN OWASP TOP 10

Agustian, Wildan Fauzi (2026) ANALISIS KEAMANAN APLIKASI WEB MENGGUNAKAN WEB APPLICATION PENETRATION TESTING BERDASARKAN OWASP TOP 10. Other thesis, Universitas Siliwangi.

[thumbnail of COVER.pdf] Text
COVER.pdf

Download (163kB)
[thumbnail of LEMBAR PENGESAHAN TUGAS AKHIR.pdf] Text
LEMBAR PENGESAHAN TUGAS AKHIR.pdf

Download (204kB)
[thumbnail of PENGESAHAN PENGUJI.pdf] Text
PENGESAHAN PENGUJI.pdf

Download (208kB)
[thumbnail of LEMBAR PERNYATAAN KEASLIAN.pdf] Text
LEMBAR PERNYATAAN KEASLIAN.pdf

Download (817kB)
[thumbnail of ABSTRAK-1.pdf] Text
ABSTRAK-1.pdf

Download (279kB)
[thumbnail of KATA PENGANTAR.pdf] Text
KATA PENGANTAR.pdf

Download (217kB)
[thumbnail of MOTTO.pdf] Text
MOTTO.pdf

Download (171kB)
[thumbnail of DAFTAR ISI.pdf] Text
DAFTAR ISI.pdf

Download (177kB)
[thumbnail of BAB I.pdf] Text
BAB I.pdf

Download (261kB)
[thumbnail of BAB II.pdf] Text
BAB II.pdf

Download (380kB)
[thumbnail of BAB III.pdf] Text
BAB III.pdf

Download (325kB)
[thumbnail of BAB IV.pdf] Text
BAB IV.pdf
Restricted to Repository staff only

Download (715kB)
[thumbnail of BAB V.pdf] Text
BAB V.pdf
Restricted to Repository staff only

Download (269kB)
[thumbnail of DAFTAR PUSTAKA.pdf] Text
DAFTAR PUSTAKA.pdf

Download (241kB)
[thumbnail of LAMPIRAN.pdf] Text
LAMPIRAN.pdf
Restricted to Repository staff only

Download (418kB)

Abstract

Integrasi sistem digital pada ekosistem akademis perguruan tinggi mempermudah manajemen data, namun sekaligus memperluas permukaan serangan siber yang mengancam integrasi informasi. Penelitian ini mengevaluasi kekuatan proteksi pada aplikasi SINTESYS Universitas Siliwangi dari potensi eksploitasi pihak ketiga. Pengujian dilakukan melalui pendekatan Web Application Penetration Testing (WAPT) berbasis kerangka kerja OWASP Top 10 dan OWASP WSTG. Pemindaian awal menggunakan OWAS ZAP menghasilkan 13 alerts (2 medium, 7 low, dan 4 informational). Berdasarkan analisis metrik CVSS dan validasi eksploitasi manual terkendali, ditemukan 2 celah True Positive berisiko sedang (Medium Risk), yaitu Clickjacking (CVSS: 6.8) akibat ketiadaan header X Frame-Options, serta risiko Session Hijacking (CVSS:6.8) akibat ketiadaan atribut HttpOnly paa cookie sesi siliwangi_integrated_system_session. Sebalikya, pengujian injeksi menghasilkan 3 Negative Finding/True Negative pada Reflected Cross-Site Scripting (XSS), SQL Injection, dan Insecure Direct Object Reference (IDOR). Hal ini membuktikan bahwa mekanisme filtrasi input dan otorisasi backend SINTESYS telah berjalan tangguh. Berdasarkan matriks manajemen risiko, diusulkan 9 poin rekomendasi remidiasi teknis dengan prioritas utama penguatan atribut cookie dan penerapan kebijakan framing guna menjamin kerahasiaan dan integritas data.

Kata Kunci: Penetration Testing, Aplikasi Web, OWASP Top 10, SYNTESIS, CVSS

Item Type: Thesis (Other)
Subjects: L Education > L Education (General)
Divisions: Fakultas Teknik > Teknik Informatika
Depositing User: user1 user1 user1
Date Deposited: 17 Sep 2026 06:29
Last Modified: 17 Sep 2026 06:29
URI: https://repositori.unsil.ac.id/id/eprint/7982

Actions (login required)

View Item
View Item