PENGUJIAN KEAMANAN WEBSITE TERHADAP SERANGAN DEFACE DAN REDIRECT INJECTION MELALUI SIMULASI DENGAN OWASP ZAP (STUDI KASUS: WEBSITE UNIVERSITAS UBUDIYAH INDONESIA)
DOI:
https://doi.org/10.33143/jics.v11i2.4911Kata Kunci:
Keamanan Website, OWASP ZAP, Redirect injection, XSS, Fuzzing, Universitas Ubudiyah IndonesiaAbstrak
Abstrak - Penelitian ini bertujuan untuk mengevaluasi tingkat keamanan website resmi Universitas Ubudiyah Indonesia terhadap potensi serangan deface dan redirect injection yang semakin marak terjadi pada aplikasi web institusi pendidikan. Pengujian dilakukan menggunakan tools OWASP ZAP (Zed Attack Proxy ) yang mampu melakukan scanning pasif dan aktif, termasuk teknik fuzzing, untuk mengidentifikasi potensi kerentanan. Target pengujian mencakup domain utama (www.uui.ac.id) dan beberapa subdomain seperti sipenmaru.uui.ac.id, rpl.uui.ac.id, dan daa.uui.ac.id. Hasil pengujian menunjukkan bahwa www.uui.ac.id memiliki konfigurasi cookie yang tidak aman (Passive Scanning, risiko sedang). Subdomain sipenmaru.uui.ac.id rentan terhadap open redirect (redirect injection , risiko tinggi), sedangkan rpl.uui.ac.id mengandung celah XSS (active scanning, risiko tinggi) dan memungkinkan pengalihan ke situs slot online (redirect injection , risiko tinggi). Selain itu, daa.uui.ac.id merespons dengan error 500 saat menerima input acak (fuzzing, risiko sedang). Kerentanan ini berisiko dimanfaatkan untuk merusak tampilan situs, mencuri informasi pengguna, hingga mengarahkan pengguna ke situs berbahaya. Penelitian ini merekomendasikan penerapan validasi input yang ketat, pengaturan cookie yang aman, audit keamanan rutin, serta peningkatan pemahaman pengembang terhadap praktik secure coding sebagai langkah mitigasi.
Referensi
Ikhlasul Amal, 2024. rancang bangun sistem informasi virtual tour campus menggunakan H5P studi kasus universitas ubudiyah indonesia. skripsi 2024.
Agung Wijoyo, Dkk. 2023. Keamanan Data dalam Sistem Informasi Manajemen: Risiko dan Strategi Perlindungan. Jurnal 2023.
Kaur, G., & Kinger, S. (2013). Analysis of SQL Injection Detection and Prevention Techniques. International Journal of Computer Applications, 77(16), 7–12. https://doi.org/10.5120/13435-1123
A. Gupta and R. Gupta, "Web Application Security: Threats and Solutions," Int. J. Adv. Res. Comput. Sci. Softw. Eng., vol. 5, no. 4, pp. 646–651, 2015.
Gregorius Hendita Artha Kusuma, 2022. Implementasi Owasp Zap Untuk Pengujian Keamanan Sistem Informasi Akademik. Jurnal 2022.
Z. Munawar. Dkk. 2020. Keamanan Jaringan Komputer Pada Era Big Data. Vol.2 No. Juni 2020. Jurnal Sistem Informasi.
Hasbullah Jamaluddin. Dkk. 2018. Analisis Keamanan Website Terhadap Sniffing Process Pada Jaringan Nirkabel Menggunakan Aplikasi Wireshark (Studi Kasus : Simak Unismuh). Skripsi, 2018.
D.B. Rendro, Dkk, 2020. Analisis Monitoring Sistem Keamanan Jaringan Komputer Menggunakan Software Nmap (Studi Kasus Di Smk Negeri 1 Kota Serang). Jurnal 2018. Vol. 7 N0. 2 E-Issn 2597-9922. September 2020. Jurnal PROSISKO
Edwin Mandala Putra. Dkk, 2021. Analisis Kemanan Jaringan Internet (Wifi) Dari Serangan Packet Data Sniffing Di Universitas Muhammadiyah .Jurnal, 2021
Unduhan
Diterbitkan
Terbitan
Bagian
Lisensi
COPYRIGHT TRANSFER FORM
The copyright to this article is transferred to Universitas Ubudiyah Indonesia (UUI) if and when the article is accepted for publication. The undersigned hereby transfers any and all rights in and to the paper including without limitation all copyrights to UUI. The undersigned hereby represents and warrants that the paper is original and that he/she is the author of the paper, except for material that is clearly identified as to its original source, with permission notices from the copyright owners where required. The undersigned represents that he/she has the power and authority to make and execute this assignment.
We declare that:
- This paper has not been published in the same form elsewhere.
- It will not be submitted anywhere else for publication prior to acceptance/rejection by this Journal.
- A copyright permission is obtained for materials published elsewhere and which require this permission for reproduction.
Furthermore, I/We hereby transfer the unlimited rights of publication of the above mentioned paper in whole to UUI. The copyright transfer covers the right to reproduce and distribute the article, including reprints, translations, photographic reproductions, microform, electronic form (offline, online) or any other reproductions of similar nature. The corresponding author signs for and accepts responsibility for releasing this material on behalf of any and all co-authors. After submission of this agreement signed by the corresponding author, changes of authorship or in the order of the authors listed will not be accepted.
Retained Rights/Terms and Conditions
- Authors retain all proprietary rights in any process, procedure, or article of manufacture described in the work.
- Authors may reproduce or authorize others to reproduce the work or derivative works for the author’s personal use or for company use, provided that the source and the UUI copyright notice are indicated, the copies are not used in any way that implies UUI endorsement of a product or service of any employer, and the copies themselves are not offered for sale.
- Although authors are permitted to re-use all or portions of the work in other works, this does not include granting third-party requests for reprinting, republishing, or other types of re-use.
.png)