Analisis Kerentanan Web Menggunakan ZAP oleh Checkmarx pada Situs Kuliah Daring LMS Universitas Kebangsaan Republik Indonesia

Penelitian

Authors

  • Mughni Al Muzaki Universitas Kebangsaan Republik Indonesia
  • Reksi Zender Perdian Universitas Kebangsaan Republik Indonesia
  • Rohman Fajar Universitas Kebangsaan Republik Indonesia
  • Saripah Universitas Kebangsaan Republik Indonesia
  • Syifa Khofifah Universitas Kebangsaan Republik Indonesia
  • Subhanjaya Angga Atmaja Universitas Kebangsaan Republik Indonesia

DOI:

https://doi.org/10.70292/pctif.v3i1.63

Keywords:

Web Application Security, ZAP, OWASP, System Vulnerabilities, Online Learning, Security Analysis, Checkmarx

Abstract

This study aims to conduct a security analysis on the online lecture site using the ZAP (Zed Attack Proxy) tool version 2.16.1, developed by OWASP and distributed by Checkmarx. The method used is black-box testing with an active scanning approach to identify security vulnerabilities that may exist in the application. The scanning process was carried out on all main pages and site resources, paying attention to various aspects such as HTTP headers, session management, JavaScript library usage, and other security configurations. The results of the scanning process showed 14 potential vulnerabilities classified into four risk levels: high (1 finding), medium (4 finding), low (6 finding), and informational (3 finding). The most significant findings were the use of a vulnerable (outdated) JavaScript library, the absence of a content security policy (CSP), and deficiencies in the implementation of important HTTP headers such as X-Frame-Options, Strict-Transport-Security, and X-Content-Type-Options. In addition, weaknesses in cookie attributes and the use of external JavaScript files without adequate source control were also found. Based on these results, a series of recommendations were developed that adhere to OWASP standards, including updating software libraries, reconfiguring security headers, strengthening session management, and implementing more secure cache policies.

Downloads

Published

09-07-2025

How to Cite

Mughni Al Muzaki, Reksi Zender Perdian, Rohman Fajar, Saripah, Syifa Khofifah, & Subhanjaya Angga Atmaja. (2025). Analisis Kerentanan Web Menggunakan ZAP oleh Checkmarx pada Situs Kuliah Daring LMS Universitas Kebangsaan Republik Indonesia: Penelitian. Journal on Pustaka Cendekia Informatika, 3(1), 125–132. https://doi.org/10.70292/pctif.v3i1.63

Most read articles by the same author(s)