
Alumni University of Teknocrat Indonesia, Muhammad Thomas Fadhila (Central)
TEKNOCK, - In an information technology, a security gap or a bug is something that can happen in a system. And if that weakness is discovered by someone, then of course the system data is in threat. For that to anticipate the threat, the big companies held contests of security systems. The participants challenged found a security gap in the platform system. If the challenge is done, the inventor is charged with a proper reward.
In 2019, Muhammad Thomas Fadhila was one of those security trackers. One of Thomas's accomplishments found a bug in instagram and a store. This is Thomas speaking over his phone, Thursday (10 / 7).
Thomas on the virtual world began at the capture of the flag or CTF, held by the Ministry of Defense in 2014. In that race, Thomas and the other participants got the challenge of finishing bugs on a mobile phone or desktop. "It's my early dabbling world bug hunter," he said. In addition, in college, he was active at the Teneesys Protection Division and the security course of the network. It's this base that was obtained in college at Teknokrat that was later developed by him.
In November 2019 Thomas found a discrepancy in the instagram system. Instagram user, foundation, keeps getting notifications even though it has logged out of instagram. This causes vulnerabilities on information personal instagram users. This matter then delivered Thomas to Instagram. Deprived this misconfiguration code apparently was not Instagram. On January 27, 2020, Thomas reported his findings to Facebook as the owner of the Instagram. He was either charged with Rp750 dollars or the equivalent of Rp10.7 million back then. "Facebook has a bug county program called Facebook White Hat.
In addition to Instagram, Thomas also found bugs on the e-commerce store application. That bug can make someone change the number of stars that the user has given the service of the shop partner or the Insecurure Direct Object Reference (IDOR).
In this condition, users can access objects without passing access checks. So, it allows people to add likes to product reviews without having to interact with store users. Thomas' findings were later declared validated by the shop and classified as medium vulnerabilities. The flaw was then repaired by the shop in April last year. Thomas got himself an appreciation of Rp2 million cash and certificates.
Now, the guy with the glasses also specializes as a tester penetration at Sumatra Cyber Security. According to him, hunting bugs is a fun job, especially when it comes to really new bugs. "So it feels nice," he said.
The University of Indonesian Tecocrat is committed to continuing to form students as a strong and knowledgeable and noble figure.

