SECURITY VULNERABILITY ANALYSIS IN CYBER PATROL WEB APPLICATION USING OWASP WEB SECURITY TESTING GUIDE (WSTG) METHODOLOGY

dc.contributor.advisorNelmiawati
dc.contributor.authorSamosir, Fikri
dc.date.accessioned2026-08-27T08:44:09Z
dc.date.issued2026-07-08
dc.description.abstractWeb applications remain a primary attack vector for data breaches. Consequently, securing internal systems is as critical as fortifying external perimeters to mitigate insider threats. Web Cyber Patrol, an internal offensive security platform developed by Seclab, manages highly sensitive organizational data where any potential breach poses severe operational risks. Furthermore, the application has never undergone a formal security evaluation, making a comprehensive penetration test an absolute prerequisite before its operational launch in a production environment. This study aims to perform a thorough security evaluation to uncover vulnerabilities and ensure the platform's deployment readiness. Utilizing an evaluative research method with a qualitative approach, this study executed a grey box penetration test targeting a specific scope of 79 web endpoint. The assessment was strictly guided by the Open Web Application Security Project (OWASP) Web Security Testing Guide (WSTG) v4.2. Identified vulnerabilities were categorized by employing the OWASP Top 10 2025 and Common Weakness Enumeration (CWE), while risk severities were quantified through the Common Vulnerability Scoring System (CVSS) v3.1. The testing phase uncovered 16 vulnerabilities, predominantly rooted in Insecure Design and Authentication Failures, with the highest severity classified as Medium risk. Following the delivery of actionable mitigation recommendations, the development team implemented system patches. A subsequent Retest validated that all 16 vulnerabilities were successfully resolved, achieving full remediation. This research emphasizes that internal security tools storing critical data require rigorous testing, and it contributes a reproducible and systematic framework for applying OWASP WSTG to achieve pre-deployment security clearance.
dc.identifier.citationIEEE
dc.identifier.kodeprodiKODEPRODI57302#Rekayasa Keamanan Siber
dc.identifier.nidnNIM4332201002
dc.identifier.nimNIDN0029088902
dc.identifier.urihttps://repository.polibatam.ac.id//handle/PL29/6299
dc.language.isoother
dc.publisherPoliteknik Negeri Batam
dc.subjectPenetration Testing
dc.subjectOWASP WSTG
dc.subjectVulnerability
dc.subjectCyber Security
dc.subjectOffensive Security
dc.titleSECURITY VULNERABILITY ANALYSIS IN CYBER PATROL WEB APPLICATION USING OWASP WEB SECURITY TESTING GUIDE (WSTG) METHODOLOGY
dc.title.alternativeANALISIS CELAH KEAMANAN PADA APLIKASI WEB CYBER PATROL MENGGUNAKAN METODOLOGI OWASP WEB SECURITY TESTING GUIDE (WSTG)
dc.typeArticle

Files

Original bundle

Now showing 1 - 3 of 3
Loading...
Thumbnail Image
Name:
4332201002_Article.pdf
Size:
715.53 KB
Format:
Adobe Portable Document Format
Loading...
Thumbnail Image
Name:
4332201002_Lembar Pengesahan.pdf
Size:
138.27 KB
Format:
Adobe Portable Document Format
Loading...
Thumbnail Image
Name:
4332201002_Borang Publikasi.pdf
Size:
92.62 KB
Format:
Adobe Portable Document Format

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed upon to submission
Description: