Security Analysis on Websites Belonging to the Health Service Districts in Indonesia Based on the Open Web Application Security Project (OWASP) Top 10 2021
Ayu Choiriyah, Nurul Qomariasih · 2023
In August 2022, the Directorate of Cyber Security Operations, National Cyber and Crypto Agency received the most complaints about cybercrime. Of these complaints, there were more than 100 hacking cases, which were dominated by the local government sector. In the same year, there was a leak of medical sample data belonging to the Central Government of the Republic of Indonesia's Ministry of Health. So, this research aims to analyze the security of a website belonging to the health service of one of the districts in Indonesia. There were eleven vulnerabilities discovered and successfully classified using the OWASP Top 10 2021. Of the eleven vulnerabilities discovered, nine vulnerabilities were successfully exploited by following the WSTG 4.2 guidelines. By using the OWASP Risk Assessment Calculator, four vulnerabilities have a medium severity level and five others have a low severity level. Based on these findings, recommendations for improving each vulnerability are given.