IMPLEMENTASI OWASP ZAP UNTUK PENETRATION TESTING PADA WEBSITE PEMERINTAH KOTA MALANG

Syalwa, Muhammad Daffa Raihan (2025) IMPLEMENTASI OWASP ZAP UNTUK PENETRATION TESTING PADA WEBSITE PEMERINTAH KOTA MALANG. Undergraduate thesis, Universitas Muhammadiyah Malang.

[thumbnail of BAB I.pdf]
Preview
Text
BAB I.pdf

Download (326kB) | Preview
[thumbnail of BAB II.pdf]
Preview
Text
BAB II.pdf

Download (361kB) | Preview
[thumbnail of BAB III.pdf] Text
BAB III.pdf
Restricted to Registered users only

Download (339kB) | Request a copy
[thumbnail of BAB IV.pdf] Text
BAB IV.pdf
Restricted to Registered users only

Download (5MB) | Request a copy
[thumbnail of BAB V.pdf] Text
BAB V.pdf
Restricted to Registered users only

Download (399kB) | Request a copy
[thumbnail of POSTER.pdf] Text
POSTER.pdf
Restricted to Registered users only

Download (377kB) | Request a copy
[thumbnail of PENDAHULUAN.pdf]
Preview
Text
PENDAHULUAN.pdf

Download (1MB) | Preview
[thumbnail of LAMPIRAN.pdf] Text
LAMPIRAN.pdf
Restricted to Registered users only

Download (184kB) | Request a copy

Abstract

This research evaluates the security of Malang City Government website (https://malangkota.go.id/) through penetration testing using OWASP ZAP with PTES framework. The methodology covers seven systematic stages from intelligence gathering to reporting. Scanning results identified six security alerts, with three confirmed as true positives after manual validation.
Findings show OWASP ZAP achieved 50% accuracy on Cloudflare WAF-protected website. Identified vulnerabilities were predominantly in Security Misconfiguration category (OWASP Top 10 A05:2021), mainly absence of Content Security Policy Header and insecure cookie configuration. Analysis revealed limitations of automated scanning against WAF-protected websites, making manual validation a critical component.
Based on the findings, the study formulates mitigation recommendations based on NIST SP 800-115 and ISO/IEC 27001, including security headers implementation, security configuration optimization, and security monitoring enhancement. These recommendations are expected to improve the website's security maturity level toward Managed and Measurable.

Item Type: Thesis (Undergraduate)
Student ID: 202110370311022
Keywords: OWASP ZAP, Penetration Testing, Website Security, PTES, OWASP Top 10
Subjects: T Technology > T Technology (General)
Divisions: Faculty of Engineering > Department of Informatics (55201)
Depositing User: 202110370311022 daffagitu3
Date Deposited: 13 Jan 2026 02:58
Last Modified: 13 Jan 2026 02:58
URI: https://eprints.umm.ac.id/id/eprint/25981

Actions (login required)

View Item
View Item