Analysis of Web Vulnerability Using Open-Source Scanners on Different Types of Small Entrepreneur Web Applications in Malaysia

Most of Malaysia’s small entrepreneurs have switched to online platforms as an alternative to their physical businesses. Social media sites such as TikTok, Instagram, Twitter, and Facebook provide free advertising tools and convenient access to a broader global target. However, security issues on th...

Full description

Bibliographic Details
Published in:Journal of Advanced Research in Applied Sciences and Engineering Technology
Main Author: Buja A.G.; Low N.N.M.A.A.; Zolkeplay A.F.; Azam N.A.; Isa F.M.
Format: Article
Language:English
Published: Semarak Ilmu Publishing 2024
Online Access:https://www.scopus.com/inward/record.uri?eid=2-s2.0-85185698625&doi=10.37934%2faraset.40.1.174188&partnerID=40&md5=b8c1aa95acffbfefeca2662aa7d8106b
id 2-s2.0-85185698625
spelling 2-s2.0-85185698625
Buja A.G.; Low N.N.M.A.A.; Zolkeplay A.F.; Azam N.A.; Isa F.M.
Analysis of Web Vulnerability Using Open-Source Scanners on Different Types of Small Entrepreneur Web Applications in Malaysia
2024
Journal of Advanced Research in Applied Sciences and Engineering Technology
40
1
10.37934/araset.40.1.174188
https://www.scopus.com/inward/record.uri?eid=2-s2.0-85185698625&doi=10.37934%2faraset.40.1.174188&partnerID=40&md5=b8c1aa95acffbfefeca2662aa7d8106b
Most of Malaysia’s small entrepreneurs have switched to online platforms as an alternative to their physical businesses. Social media sites such as TikTok, Instagram, Twitter, and Facebook provide free advertising tools and convenient access to a broader global target. However, security issues on these websites remain questionable as users are exposed to web attacks due to the vulnerabilities on the websites. Considering the cost and lack of awareness of the importance of cybersecurity, some organizations find it not profitable to invest in securing their websites. Therefore, this paper aims to test Malaysian small entrepreneurs’ web applications using open-source scanners and analyse the results of web vulnerabilities detected. To do so, two types of open-source scanners, OWASP ZAP and IRONWASP, were installed to scan five websites found through advertisements on social media sites. The web vulnerability identification was based on the top 5 OWASP web vulnerability reports, and the results showed that five types of web vulnerabilities were detected. The analysis of the results showed that the top 5 web vulnerabilities in Malaysian small entrepreneurs’ websites are the ‘Missing Session Timeout’ vulnerability with 81.84 percent, the ‘Sensitive Information Passed as Clear Text in GET URL’ vulnerability with 14.74 percent, and the ‘Session ID Cookies not Marked Secure’ vulnerability with 2.47 percent. This paper provides security analysis on Small Medium Enterprise (SME) websites for future enhancement and consideration during development and implementation to avoid possible attacks. Therefore, developers are advised to handle these vulnerabilities by carefully managing the session timeout, and users are recommended to log out from the websites immediately after they are done. © 2024, Semarak Ilmu Publishing. All rights reserved.
Semarak Ilmu Publishing
24621943
English
Article
All Open Access; Hybrid Gold Open Access
author Buja A.G.; Low N.N.M.A.A.; Zolkeplay A.F.; Azam N.A.; Isa F.M.
spellingShingle Buja A.G.; Low N.N.M.A.A.; Zolkeplay A.F.; Azam N.A.; Isa F.M.
Analysis of Web Vulnerability Using Open-Source Scanners on Different Types of Small Entrepreneur Web Applications in Malaysia
author_facet Buja A.G.; Low N.N.M.A.A.; Zolkeplay A.F.; Azam N.A.; Isa F.M.
author_sort Buja A.G.; Low N.N.M.A.A.; Zolkeplay A.F.; Azam N.A.; Isa F.M.
title Analysis of Web Vulnerability Using Open-Source Scanners on Different Types of Small Entrepreneur Web Applications in Malaysia
title_short Analysis of Web Vulnerability Using Open-Source Scanners on Different Types of Small Entrepreneur Web Applications in Malaysia
title_full Analysis of Web Vulnerability Using Open-Source Scanners on Different Types of Small Entrepreneur Web Applications in Malaysia
title_fullStr Analysis of Web Vulnerability Using Open-Source Scanners on Different Types of Small Entrepreneur Web Applications in Malaysia
title_full_unstemmed Analysis of Web Vulnerability Using Open-Source Scanners on Different Types of Small Entrepreneur Web Applications in Malaysia
title_sort Analysis of Web Vulnerability Using Open-Source Scanners on Different Types of Small Entrepreneur Web Applications in Malaysia
publishDate 2024
container_title Journal of Advanced Research in Applied Sciences and Engineering Technology
container_volume 40
container_issue 1
doi_str_mv 10.37934/araset.40.1.174188
url https://www.scopus.com/inward/record.uri?eid=2-s2.0-85185698625&doi=10.37934%2faraset.40.1.174188&partnerID=40&md5=b8c1aa95acffbfefeca2662aa7d8106b
description Most of Malaysia’s small entrepreneurs have switched to online platforms as an alternative to their physical businesses. Social media sites such as TikTok, Instagram, Twitter, and Facebook provide free advertising tools and convenient access to a broader global target. However, security issues on these websites remain questionable as users are exposed to web attacks due to the vulnerabilities on the websites. Considering the cost and lack of awareness of the importance of cybersecurity, some organizations find it not profitable to invest in securing their websites. Therefore, this paper aims to test Malaysian small entrepreneurs’ web applications using open-source scanners and analyse the results of web vulnerabilities detected. To do so, two types of open-source scanners, OWASP ZAP and IRONWASP, were installed to scan five websites found through advertisements on social media sites. The web vulnerability identification was based on the top 5 OWASP web vulnerability reports, and the results showed that five types of web vulnerabilities were detected. The analysis of the results showed that the top 5 web vulnerabilities in Malaysian small entrepreneurs’ websites are the ‘Missing Session Timeout’ vulnerability with 81.84 percent, the ‘Sensitive Information Passed as Clear Text in GET URL’ vulnerability with 14.74 percent, and the ‘Session ID Cookies not Marked Secure’ vulnerability with 2.47 percent. This paper provides security analysis on Small Medium Enterprise (SME) websites for future enhancement and consideration during development and implementation to avoid possible attacks. Therefore, developers are advised to handle these vulnerabilities by carefully managing the session timeout, and users are recommended to log out from the websites immediately after they are done. © 2024, Semarak Ilmu Publishing. All rights reserved.
publisher Semarak Ilmu Publishing
issn 24621943
language English
format Article
accesstype All Open Access; Hybrid Gold Open Access
record_format scopus
collection Scopus
_version_ 1809678004675149824