Evaluasi Keamanan Website Unm.ac.id Menggunakan Metodologi Penetration Testing Berdasarkan Framework OWASP Top 10
DOI:
https://doi.org/10.62951/repeater.v4i3.962Keywords:
CVSS 3.1, OWASP Top 10, Penetration Testing, Unm.ac.id, Website SecurityAbstract
The high incidence of cyberattacks across various sectors reported by the National Cyber and Crypto Agency (BSSN) poses a serious threat to data and service security in application systems, including at Makassar State University, which relies on web-based information technology for many of its activities, thereby creating potential risks to its website security. This study aims to evaluate the security of the domain unm.ac.id and its subdomains using penetration testing methods, identify security vulnerabilities based on the OWASP Top 10, and develop relevant mitigation strategies. The method used is penetration testing through several stages: information gathering, enumeration, vulnerability scanning, exploitation, OWASP Top 10–based security classification, risk assessment using CVSS 3.1, and formulation of mitigation strategies. The results identified 9 validated vulnerability types, with the majority of OWASP Top 10 classifications falling under security misconfiguration, cryptographic failures, and the use of vulnerable or outdated components. Most vulnerabilities were at medium, low, and informational levels. It can therefore be concluded that security mechanisms on the website have been implemented, but periodic evaluation and reinforcement of security are still required to minimize potential risks and prevent future attacks.
Downloads
References
Adam, H. M., Widyawan, & Putra, G. D. (2023). A review of penetration testing frameworks, tools, and application areas. 2023 IEEE 7th International Conference on Information Technology, Information Systems and Electrical Engineering (ICITISEE), 319–324. IEEE. https://doi.org/10.1109/ICITISEE58992.2023.10404397
Badan Siber dan Sandi Negara. (2024). Lanskap keamanan siber Indonesia 2024. Direktorat Operasi Keamanan Siber.
Daeng, Y., Levin, J., Prayudha, M. R., Ramadhani, N. P., & Imanuel, S. (2023). Analisis penerapan sistem keamanan siber terhadap kejahatan siber di Indonesia. Innovative: Journal of Social Science Research, 3(6), 1135–1145.
Darmawan, C., Naibaho, J. P. P., & Kweldju, A. D. (2024). Penerapan metode vulnerability assessment untuk identifikasi keamanan website berdasarkan OWASP ID tahun 2021. Edumatic: Jurnal Pendidikan Informatika, 8(1), 272–281. https://doi.org/10.29408/edumatic.v8i1.25834
Darul Fata. (2023). Evaluasi risiko celah keamanan menggunakan metodologi Open Web Application Security Project (OWASP) pada aplikasi web Sistem Informasi Akademik (SIAKAD) UIN Ar-Raniry [Tugas akhir, Universitas Islam Negeri Ar-Raniry].
Dawadi, B. R., Adhikari, B., & Srivastava, D. K. (2023). Deep learning technique-enabled web application firewall for the detection of web attacks. Sensors, 23(4), 2073. https://doi.org/10.3390/s23042073
Dharmawangsa, I., Sasmita, G., & Pratama, I. P. A. E. (2023). Penetration testing berbasis OWASP Testing Guide versi 4.2: Studi kasus X website. JITTER: Jurnal Ilmiah Teknologi dan Komputer, 4(1), 1613. https://doi.org/10.24843/JTRTI.2023.v04.i01.p06
Dwi Agustina, V., Ariyadi, T., Syah Putra, T., & Lega, A. (2025). Teknik pengujian penetrasi HTTP menggunakan tools Burp Suite pada Kali Linux. STORAGE: Jurnal Ilmiah Teknik dan Ilmu Komputer, 4(1), 16–21. https://doi.org/10.55123/storage.v4i1.4770
Handayani, I., Febriyanto, E., & Kristanti, C. Y. (2019). Peran perkembangan teknologi informasi dan komunikasi dalam pembelajaran iLearning Plus di Universitas Raharja. Jurnal Pendidikan Teknologi dan Kejuruan, 16(2), 181. https://doi.org/10.23887/jptk-undiksha.v16i2.17859
Herawati, N., Budiyanto, V., & Uminingsih. (2023). Analisis keamanan sebuah domain menggunakan Open Web Application Security Project (OWASP) ZAP. Jurnal Teknologi Technoscientia, 15(2), 27–36. https://doi.org/10.34151/technoscientia.v15i2.4013
Kongara, D., & Krishnama, S. (2023). A process of penetration testing using various tools. Mesopotamian Journal of CyberSecurity, 2023, 93–103. https://doi.org/10.58496/MJCS/2023/014
Lazarov, W., Seda, P., Martinasek, Z., & Kummel, R. (2025). Penterep: Comprehensive penetration testing with adaptable interactive checklists. Computers & Security, 154, 104399. https://doi.org/10.1016/j.cose.2025.104399
Muhammad Fauzi, R., Hermawan, R., Rosian Adhy, D., & Maesaroh, S. (2024). Analisis kerentanan keamanan web menggunakan metode OWASP dan PTES di web pemerintahan Desa XYZ. Jurnal Orang Elektro, 13(2), 225–231. https://doi.org/10.30591/polektro.v13i2.6711
National Cyber Security Index. (2023). Laporan National Cyber Security Index Indonesia 2023.
Nurelasari, E., Gumilang, D., & Farabi, A. (2024). Analisis keamanan sistem website menggunakan metode Open Web Application Security Project (OWASP) pada simantep.id. JATI: Jurnal Mahasiswa Teknik Informatika, 8(3), 3049–3054. https://doi.org/10.36040/jati.v8i3.9314
Prasetiyo, N. A., Huwae, R. B., & Jatmika, A. H. (2024). Audit dan analisis website pemerintah menggunakan pengujian penetrasi SQL injection dan cross-site scripting (XSS). Jurnal Teknologi Informasi, Komputer, dan Aplikasinya, 6(2), 525–533. https://doi.org/10.29303/jtika.v6i2.425
Supriyatna, A. R., Asrowardi, I., Putra, S. D., & Subyantoro, E. (2024). Analisis kerentanan aplikasi web e-commerce berdasarkan standar OWASP Top 10: Studi kasus pada situs Kopi Lampung Nusantara. EXPERT: Jurnal Manajemen Sistem Informasi dan Teknologi, 14(2), 95. https://doi.org/10.36448/expert.v14i2.4034
Wirawan, I. K., Srirahayu, A., & Sopingi, S. (2024). Rancang bangun sistem informasi keuangan sekolah berbasis website. Jurnal Teknologi dan Sistem Informasi Bisnis, 6(4), 639–648. https://doi.org/10.47233/jteksis.v6i4.1455
Zahra, N. A., Zidane, F. H., & Kuslaila, N. R. (2023). Analisis keamanan sistem informasi pada sistem website PT Sentra Vidya Utama (SEVIMA) menggunakan metode OWASP. Prosiding Seminar Nasional Teknologi dan Sistem Informasi, 3(1), 384–393. https://doi.org/10.33005/sitasi.v3i1.564
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Repeater : Publikasi Teknik Informatika dan Jaringan

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.




