Penerapan Analisis Komparatif Efektivitas OWASP ZAP dan Nikto dalam Mendeteksi Celah Keamanan Web Server

Authors

  • Robit maula UMNU Kebumen
  • fahmi fachri

Keywords:

Keywords: Web Application Security; Vulnerability Assessment; OWASP ZAP; Nikto Web Scanner; planetkomputer.my.id

Abstract

The integration of web-based information systems in the business sector, such as the planetkomputer.my.id website, is crucial for providing efficient services, yet it remains highly vulnerable to exploitation threats and data integrity manipulation. A real problem discovered in this research object is data inconsistency caused by abnormal price changes in the shop's product price list. This study aims to identify the exact location of these security flaws—whether originating from application code or server misconfigurations—while comparing the effectiveness of security scanning tools in detecting vulnerabilities. The proposed method is a qualitative-descriptive applied security assessment using a Black-Box Testing approach with two security scanners, namely OWASP Zed Attack Proxy (ZAP) and Nikto, executed through the stages of Reconnaissance, Vulnerability Scanning, and Data Analysis. The results indicate that both tools successfully identified several security vulnerabilities with Medium to Low risk levels. The core synthesis reveals complementary detection characteristics; OWASP ZAP proved thorough in detecting web application logic and session weaknesses, such as the absence of Anti-CSRF tokens and the HttpOnly flag on cookies, whereas Nikto was more sensitive in identifying misconfigurations at the web server architecture level and network technical information leaks. In conclusion, combining these two assessment tools is highly effective in providing a comprehensive security evaluation to formulate neat and systematic mitigation recommendations for the shop's IT infrastructure management.

 

References

Referensi

[1] A. Rochman, R. R. Salam, dan S. A. M., “ANALISIS KEAMANAN WEBSITE DENGAN INFORMATION SYSTEM SECURITY ASSESSMENT FRAMEWORK (ISSAF) DAN OPEN WEB APPLICATION SECURITY PROJECT (OWASP) DI RUMAH SAKIT XYZ,” Pharmacognosy Magazine, vol. 75, no. 17, hal. 399–405, 2021.

[2] M. Amirul, N. Tristanti, G. Pramuja, dan I. Fanani, “Analisis dan Pengujian Kerentanan Website Menggunakan OWASP ZAP,” vol. 3, no. 1, hal. 36–50, 2024.

[3] S. Andriansyah dan Nurhasanah, “Analisis Keamanan Website SMP Negeri 2 Bagan Sinembah Dengan Framework ISSAF (Studi Kasus : SMP Negeri 2 Bagan Sinembah) Elpi. Konsep Desain Menentukan Hull Type, Material, Dan Propulsi Unmanned Surface Vehicle (Usv) Untuk Patroli Di Wilayah Rokan Hiir Dengan Metode Desicion Tree, Lcm,” hal. 478–486, 2020.

[4] S. Andriyani, M. F. Sidiq, dan B. P. Zen, “Analisis Celah Keamanan Pada Website Dengan Menggunakan Metode Penetration Testing Dan Framework Issaf Pada Website SMK Al-Kautsar,” Journal Informatic and Information Technology, hal. 1–13, 2023.

[5] U. N. Cendana, A. History, dan S. Chain, “Optimalisasi Transformasi Digital dalam Pengelolaan Supply Chain Perusahaan,” vol. 4, hal. 186–192, 2025.

[6] F. Cobit dan P. Telkom, “AUDIT TATA KELOLA TEKNOLOGI INFORMASI MENGGUNAKAN,” Jurnal Software Engineering and Information System (SEIS), vol. 4, no. 2, 2024.

[7] N. D. Darno dan E. L. Tjiong, “Analisis Celah Keamanan Pada Website PDDIKTI Menggunakan Metode Penetration Testing Dan Framework ISSAF,” vol. 12, no. 02, hal. 1–13, 2025.

[8] F. N. Dhanendra dan A. Sujarwo, “Strategi Keamanan pada Sistem Bank Air Kami v2 menggunakan Trias CIA,” vol. 4, hal. 1048–1062, 2024.

[9] S. EkoPrasetyo dan N. Hassanah, “Analisis Keamanan Website Universitas Internasional Batam Menggunakan Metode Issaf,” Jurnal Ilmiah Informatika, vol. 9, no. 02, hal. 82–86, 2021, doi: 10.33884/jif.v9i02.3758.

[10] F. Fachri, “Optimasi Keamanan Web Server Terhadap Serangan Brute-Force Menggunakan Penetration Testing,” Jurnal Teknologi In-formasi Dan Ilmu Komputer, vol. 10, no. 1, hal. 51–58, 2023, doi: 10.25126/jtiik.20231015872.

[11] “Framework Integrasi Digital Forensic Readiness dan Information Security Management System di lingkungan Pemerintahan,” 2024.

[12] H. S. Harahap, A. A. Rahman, I. Suraswati, dan S. N. Neyman, “Memahami Cara Kerja Phishing menggunakan Tools pada Kali Linux,” Journal of Internet and Software Engineering, vol. 1, no. 2, hal. 1–11, 2024.

[13] H. Herman, I. Riadi, Y. Kurniawan, dan I. A. Rafiq, “Analisis Keamanan Website Menggunakan Information System Security Asess-ment Framework (ISSAF),” Jurnal Teknologi Informatika Dan Komputer, vol. 9, no. 1, hal. 126–136, 2023, doi: 10.37012/jtik.v9i1.1439.

[14] M. O. Hoshmand dan S. Ratnawati, “Analisis Keamanan Infrastruktur Teknologi Informasi dalam Menghadapi Ancaman Cybersecu-rity,” vol. 5, no. 2, hal. 679–686, 2023.

[15] M. Issaf, “Analisis dan Rekomendasi Keamanan Website Kampus X,” vol. 6, no. 1, hal. 830–843, 2025.

[16] M. F. Issaf dan M. Koprawi, “Analisis Keamanan Website Pada Instansi XYZ Melalui Penetration Testing,” vol. 5, no. 1, hal. 547–555, 2025.

[17] M. Khairi, B. Rianto, dan M. Jalil, “Pengaruh teknologi dalam transformasi ekonomi dan bisnis di era digital 1,” vol. 7, hal. 71–78, 2025.

[18] H. Nasution dan A. Abdul, “Analisis Performa Web server Apache dan Go Pada Protokol HTTP (Hypertext Transfer Protocol) Per-formance Analysis of Apache and Go Web servers on HTTP Protocol (Hypertext Transfer Protocol),” vol. 02, no. 2, 2024, doi: 10.26418/juara.v2i2.81914.

[19] S. A. Nugroho dan T. Rochmadi, “Analisis Keamanan Sistem Informasi Pusaka Magelang Menggunakan Open Web Application Se-curity Project (OWASP) Dan Information Systems Security Assessment Framework (ISSAF) Security Analysis Of Magelang Pusaka Infor-mation System Using Open Web Application Security Project (OWASP) And Information Systems Security Assessment Framework (IS-SAF),” vol. 7, no. 1, hal. 56–61, 2024.

[20] M. Amirul, Y. Safitri, dan S. Saputra, “Analisis Keamanan Sistem Informasi Akademik XYZ Menggunakan Information System Secu-rity Assessment Framework (ISSAF) Security Analysis of XYZ Academic Information System Using Information System Security Assess-ment Framework (ISSAF),” Jurnal Pengembangan, vol. 1, hal. 50–60, 2025.

Downloads

Published

2026-07-15

How to Cite

maula, R., & fahmi fachri. (2026). Penerapan Analisis Komparatif Efektivitas OWASP ZAP dan Nikto dalam Mendeteksi Celah Keamanan Web Server. Jurnal Publikasi Ilmu Komputer Dan Multimedia, 4(1), 37–48. Retrieved from https://journalcenter.org/index.php/jupikom/article/view/7655