COMPARATIVE ANALYSIS OF OWASP ZAP 2.17.0 AND NESSUS 10.11.3 SCANNING TOOLS FOR DETECTING VULNERABILITIES IN WEB APPLICATIONS

Sujatmoko, Amanda Widya Indah (2026) COMPARATIVE ANALYSIS OF OWASP ZAP 2.17.0 AND NESSUS 10.11.3 SCANNING TOOLS FOR DETECTING VULNERABILITIES IN WEB APPLICATIONS. Undergraduate thesis, UPN "Veteran" Jawa Timur.

[img] Text (Cover)
22081010263-cover.pdf

Download (1MB)
[img] Text (Bab 1)
22081010263-bab 1.pdf

Download (153kB)
[img] Text (Bab 2)
22081010263-bab 2.pdf
Restricted to Repository staff only until 22 July 2029.

Download (655kB) | Request a copy
[img] Text (Bab 3)
22081010263-bab 3.pdf
Restricted to Repository staff only until 22 July 2029.

Download (1MB) | Request a copy
[img] Text (Bab 4)
22081010263-bab 4.pdf
Restricted to Repository staff only until 22 July 2029.

Download (11MB) | Request a copy
[img] Text (Bab 5)
22081010263-bab 5.pdf

Download (175kB)
[img] Text (Daftar Pustaka)
22081010263-daftar pustaka.pdf

Download (180kB)
[img] Text (Lampiran)
22081010263-lampiran.pdf
Restricted to Repository staff only

Download (787kB) | Request a copy

Abstract

The growing use of websites has also increased the complexity of cybersecurity threats, making security testing using vulnerability scanning tools such as OWASP ZAP and Nessus essential. This study aims to compare the capabilities, scope, and effectiveness of OWASP ZAP and Nessus in detecting vulnerabilities through five testing phases: website analysis, vulnerability scanning, exploitation, test results, and analysis of results. A comparative analysis was conducted on the vulnerable websites bWAPP, Metasploitable 3, and Zero Bank, both quantitatively and qualitatively, as well as on website X, using a qualitative approach. Quantitative test results show that Nessus is superior at detecting vulnerabilities accurately and comprehensively in a shorter amount of time; however, OWASP ZAP is superior at identifying vulnerabilities with the highest severity. Furthermore, a qualitative analysis shows that, in terms of effectiveness in detecting website vulnerabilities, OWASP ZAP focuses more on web application layer vulnerabilities, such as configuration errors in HTTP headers and the absence of Anti-CSRF tokens, while Nessus excels at detecting vulnerabilities in infrastructure and server components, such as vulnerable nginx versions and exposed Git repositories. In terms of ease of use, OWASP ZAP requires proxy configuration and involves two scanning stages, Automatic and Manual Scanning while Nessus only requires a single feature, the Web Application Test, without the need for proxy configuration. Regarding limitations, OWASP ZAP can be used for free with no limit on the number of websites, whereas Nessus is limited in its free version but offers more comprehensive features in its paid version. In terms of features, OWASP ZAP has only two main features used for website security checks, whereas Nessus offers numerous scanning features for various types of applications, one of which is the Web Application Test feature used to check website application security. In conclusion, both tools have their own strengths depending on specific needs, so using a combination of both is recommended to achieve a more comprehensive coverage of website vulnerability scanning across various aspects.

Item Type: Thesis (Undergraduate)
Contributors:
ContributionContributorsNIDN/NIDKEmail
Thesis advisorWahanani, Henni EndahNIDN378091303481henniendah@upnjatim.ac.id
Thesis advisorJunaidi, AchmadNIDN0710117803achmadjunaidi.if@upnjatim.ac.id
Subjects: T Technology > TK Electrical engineering. Electronics Nuclear engineering > TK5105 Computer Network
Divisions: Faculty of Computer Science > Departemen of Informatics
Depositing User: Amanda Widya Indah Sujatmoko
Date Deposited: 22 Jul 2026 06:37
Last Modified: 22 Jul 2026 07:31
URI: https://repository.upnjatim.ac.id/id/eprint/57695

Actions (login required)

View Item View Item