Tired of ads? Enjoy an ad-free experience by signing up.
Nadine Freischlad · · 3 min read

Hacker exposes security flaw on major Indonesian sites, gets himself hired

Herdian Nugraha (third from left) is no stranger to computer challenges. Here he and his team won a gold medal at an information systems security competition. Photo credit: Himalkom.

Herdian Nugraha (third from left) is no stranger to computer challenges. Here he and his team won a gold medal at an information systems security competition. Photo credit: Himalkom.

In June, Herdian Nugraha, a fresh graduate from Indonesia’s Agricultural University in Bogor, found a security flaw on the websites of some major local startups.

The self-proclaimed computer security enthusiast didn’t exploit the situation to steal data or cause harm. Instead, he reported the bug and offered the companies time to respond. He published a documentation of his hack earlier this week, along with details on how the startups reacted.

How a bug bounty program can save you

The hack Herdian used isn’t new. On his blog, he writes that it’s based on the well-documented ImageTragick exploit. He wanted to try it on some of the sites he frequented.

Two local ecommerce sites became his target: Bukalapak and Tokopedia. The third one was Sribu, a design community.

Herdian was able to upload a corrupted file via an image upload button – think of that place on a site where you’re asked to submit a profile photo.

The code Herdian injected let him gain access and communicate with the companies’ servers.

After Herdian reported the bug, Bukalapak’s and Tokopedia’s security teams sprang into action.

Both firms run so-called bug bounty programs. When hackers report a problem, they’re promised a reward. The amount varies depending on the severity of the flaw. This incentivizes hackers to go the legal route, instead of abusing access, for example to steal data.

Bukalapak CEO Achmad Zaky.

Bukalapak CEO Achmad Zaky.

Herdian writes that he received US$1,146 from Bukalapak and US$764 from Tokopedia – in Indonesian rupiah, that’s a substantial reward.

The hacker praised Tokopedia for its quick response time. It took them only four hours to patch the bug. Bukalapak took two days.

Sribu, on the other hand, hadn’t fixed the bug at the time of Herdian’s writing.

Even Facebook gets hacked

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.

Community Writer

Nadine Freischlad

Startups, smartphones, sci-fi.