Analysis of Web Vulnerability Using Open-Source Scanners on Different Types of Small Entrepreneur Web Applications in Malaysia
Most of Malaysia’s small entrepreneurs have switched to online platforms as an alternative to their physical businesses. Social media sites such as TikTok, Instagram, Twitter, and Facebook provide free advertising tools and convenient access to a broader global target. However, security issues on th...
Published in: | Journal of Advanced Research in Applied Sciences and Engineering Technology |
---|---|
Main Author: | |
Format: | Article |
Language: | English |
Published: |
Semarak Ilmu Publishing
2024
|
Online Access: | https://www.scopus.com/inward/record.uri?eid=2-s2.0-85185698625&doi=10.37934%2faraset.40.1.174188&partnerID=40&md5=b8c1aa95acffbfefeca2662aa7d8106b |
id |
2-s2.0-85185698625 |
---|---|
spelling |
2-s2.0-85185698625 Buja A.G.; Low N.N.M.A.A.; Zolkeplay A.F.; Azam N.A.; Isa F.M. Analysis of Web Vulnerability Using Open-Source Scanners on Different Types of Small Entrepreneur Web Applications in Malaysia 2024 Journal of Advanced Research in Applied Sciences and Engineering Technology 40 1 10.37934/araset.40.1.174188 https://www.scopus.com/inward/record.uri?eid=2-s2.0-85185698625&doi=10.37934%2faraset.40.1.174188&partnerID=40&md5=b8c1aa95acffbfefeca2662aa7d8106b Most of Malaysia’s small entrepreneurs have switched to online platforms as an alternative to their physical businesses. Social media sites such as TikTok, Instagram, Twitter, and Facebook provide free advertising tools and convenient access to a broader global target. However, security issues on these websites remain questionable as users are exposed to web attacks due to the vulnerabilities on the websites. Considering the cost and lack of awareness of the importance of cybersecurity, some organizations find it not profitable to invest in securing their websites. Therefore, this paper aims to test Malaysian small entrepreneurs’ web applications using open-source scanners and analyse the results of web vulnerabilities detected. To do so, two types of open-source scanners, OWASP ZAP and IRONWASP, were installed to scan five websites found through advertisements on social media sites. The web vulnerability identification was based on the top 5 OWASP web vulnerability reports, and the results showed that five types of web vulnerabilities were detected. The analysis of the results showed that the top 5 web vulnerabilities in Malaysian small entrepreneurs’ websites are the ‘Missing Session Timeout’ vulnerability with 81.84 percent, the ‘Sensitive Information Passed as Clear Text in GET URL’ vulnerability with 14.74 percent, and the ‘Session ID Cookies not Marked Secure’ vulnerability with 2.47 percent. This paper provides security analysis on Small Medium Enterprise (SME) websites for future enhancement and consideration during development and implementation to avoid possible attacks. Therefore, developers are advised to handle these vulnerabilities by carefully managing the session timeout, and users are recommended to log out from the websites immediately after they are done. © 2024, Semarak Ilmu Publishing. All rights reserved. Semarak Ilmu Publishing 24621943 English Article All Open Access; Hybrid Gold Open Access |
author |
Buja A.G.; Low N.N.M.A.A.; Zolkeplay A.F.; Azam N.A.; Isa F.M. |
spellingShingle |
Buja A.G.; Low N.N.M.A.A.; Zolkeplay A.F.; Azam N.A.; Isa F.M. Analysis of Web Vulnerability Using Open-Source Scanners on Different Types of Small Entrepreneur Web Applications in Malaysia |
author_facet |
Buja A.G.; Low N.N.M.A.A.; Zolkeplay A.F.; Azam N.A.; Isa F.M. |
author_sort |
Buja A.G.; Low N.N.M.A.A.; Zolkeplay A.F.; Azam N.A.; Isa F.M. |
title |
Analysis of Web Vulnerability Using Open-Source Scanners on Different Types of Small Entrepreneur Web Applications in Malaysia |
title_short |
Analysis of Web Vulnerability Using Open-Source Scanners on Different Types of Small Entrepreneur Web Applications in Malaysia |
title_full |
Analysis of Web Vulnerability Using Open-Source Scanners on Different Types of Small Entrepreneur Web Applications in Malaysia |
title_fullStr |
Analysis of Web Vulnerability Using Open-Source Scanners on Different Types of Small Entrepreneur Web Applications in Malaysia |
title_full_unstemmed |
Analysis of Web Vulnerability Using Open-Source Scanners on Different Types of Small Entrepreneur Web Applications in Malaysia |
title_sort |
Analysis of Web Vulnerability Using Open-Source Scanners on Different Types of Small Entrepreneur Web Applications in Malaysia |
publishDate |
2024 |
container_title |
Journal of Advanced Research in Applied Sciences and Engineering Technology |
container_volume |
40 |
container_issue |
1 |
doi_str_mv |
10.37934/araset.40.1.174188 |
url |
https://www.scopus.com/inward/record.uri?eid=2-s2.0-85185698625&doi=10.37934%2faraset.40.1.174188&partnerID=40&md5=b8c1aa95acffbfefeca2662aa7d8106b |
description |
Most of Malaysia’s small entrepreneurs have switched to online platforms as an alternative to their physical businesses. Social media sites such as TikTok, Instagram, Twitter, and Facebook provide free advertising tools and convenient access to a broader global target. However, security issues on these websites remain questionable as users are exposed to web attacks due to the vulnerabilities on the websites. Considering the cost and lack of awareness of the importance of cybersecurity, some organizations find it not profitable to invest in securing their websites. Therefore, this paper aims to test Malaysian small entrepreneurs’ web applications using open-source scanners and analyse the results of web vulnerabilities detected. To do so, two types of open-source scanners, OWASP ZAP and IRONWASP, were installed to scan five websites found through advertisements on social media sites. The web vulnerability identification was based on the top 5 OWASP web vulnerability reports, and the results showed that five types of web vulnerabilities were detected. The analysis of the results showed that the top 5 web vulnerabilities in Malaysian small entrepreneurs’ websites are the ‘Missing Session Timeout’ vulnerability with 81.84 percent, the ‘Sensitive Information Passed as Clear Text in GET URL’ vulnerability with 14.74 percent, and the ‘Session ID Cookies not Marked Secure’ vulnerability with 2.47 percent. This paper provides security analysis on Small Medium Enterprise (SME) websites for future enhancement and consideration during development and implementation to avoid possible attacks. Therefore, developers are advised to handle these vulnerabilities by carefully managing the session timeout, and users are recommended to log out from the websites immediately after they are done. © 2024, Semarak Ilmu Publishing. All rights reserved. |
publisher |
Semarak Ilmu Publishing |
issn |
24621943 |
language |
English |
format |
Article |
accesstype |
All Open Access; Hybrid Gold Open Access |
record_format |
scopus |
collection |
Scopus |
_version_ |
1809678004675149824 |