Welcome Guest ( Log In | Register )

4 Pages < 1 2 3 4 >Bottom

Outline · [ Standard ] · Linear+

 MySejahtera Not So Sejahtera, Full of Exploits

views
     
TSDarkripper
post Oct 18 2021, 02:40 PM

What do you expect?
******
Senior Member
1,258 posts

Joined: Dec 2008
From: /k/
QUOTE(WaCKy-Angel @ Oct 18 2021, 02:38 PM)
slowly lah wait he think of a good cum back like dajjal hahahaha

who knows later he will employ u as their Security consultant eh
*
Btw seems like the dev is fixing, some of the other exploits is getting patched. But still doesn't give much confidence when they don't acknowledge it.

This post has been edited by Darkripper: Oct 18 2021, 02:40 PM
jmas
post Oct 18 2021, 02:43 PM

I can edit title???
*****
Junior Member
828 posts

Joined: Mar 2010
QUOTE(Darkripper @ Oct 18 2021, 02:37 PM)
Cost is not the question here. This is a critical app required by most residents in Malaysia, cannot compromise on security yo. Imagine a data-breach?
I see you're man of culture here. Jquery hurts my eye tho.
*
not denying the app is critical, just correcting the fact that ppl thought the apps cost 70mil to develop and discounting the effort of the developers
but the truth is the developer was doing this for free (initially) and I think only officially get paid around end of last year/early this year

TSDarkripper
post Oct 18 2021, 02:46 PM

What do you expect?
******
Senior Member
1,258 posts

Joined: Dec 2008
From: /k/
QUOTE(jmas @ Oct 18 2021, 02:43 PM)
not denying the app is critical, just correcting the fact that ppl thought the apps cost 70mil to develop and discounting the effort of the developers
but the truth is the developer was doing this for free (initially) and I think only officially get paid around end of last year/early this year
*
Good to do it for free, the issue is on Govt for not ensuring quality in such a critical application. Devs are probably getting squeezed also la.
WaCKy-Angel
post Oct 18 2021, 02:51 PM

PeACe~~
*********
All Stars
21,961 posts

Joined: Dec 2004
From: KL



QUOTE(jmas @ Oct 18 2021, 02:43 PM)
not denying the app is critical, just correcting the fact that ppl thought the apps cost 70mil to develop and discounting the effort of the developers
but the truth is the developer was doing this for free (initially) and I think only officially get paid around end of last year/early this year
*
user posted image


Pls lah nobody do things for FREE
AssToast
post Oct 18 2021, 03:03 PM

Rarely on Lowyat
******
Senior Member
1,618 posts

Joined: Jun 2012
QUOTE(Darkripper @ Oct 18 2021, 02:46 PM)
Good to do it for free, the issue is on Govt for not ensuring quality in such a critical application. Devs are probably getting squeezed also la.
*
Govt probably has no idea what or how to manage. When app first released, looked like uni project. Now probably still no QA or code review, Dev just fix when people complain.
kidmad
post Oct 18 2021, 08:19 PM

Look at all my stars!!
*******
Senior Member
4,481 posts

Joined: Jul 2005
QUOTE(Darkripper @ Oct 18 2021, 02:27 PM)
They can't do that, as that's the endpoint that client side is calling to trigger it. Eaiest way is just to rate limit + some kind of Captcha. That would reduce the exposure to an acceptable limit.

client side to trigger? it don't work that way. the service i work on sents millions of sms daily. we are the one triggering to an end point expose by the provider. mysejahtera would have the list of contact on their end. all they need to do is periodically send the sms via to end point expose by the few operator we have.

if it's really trigger by us who has mysejahtera that's stupid
rooney723
post Oct 18 2021, 08:32 PM

On my way
****
Junior Member
596 posts

Joined: Dec 2010

and i can bet with you that the gomen will not give a single fuck about this, just diam diam only, look at what happen to the recent LHDN data breach? whistling.gif
Syeikh Ruler al-Hotzz
post Oct 18 2021, 09:59 PM

New Member
*
Junior Member
5 posts

Joined: Oct 2021
Mysengsara
TSDarkripper
post Oct 18 2021, 11:13 PM

What do you expect?
******
Senior Member
1,258 posts

Joined: Dec 2008
From: /k/
QUOTE(kidmad @ Oct 18 2021, 08:19 PM)
client side to trigger? it don't work that way. the service i work on sents millions of sms daily. we are the one triggering to an end point expose by the provider. mysejahtera would have the list of contact on their end. all they need to do is periodically send the sms via to end point expose by the few operator we have.

if it's really trigger by us who has mysejahtera that's stupid
*
you're talking about their backend implementation, which is out-of-reach. Client trigger mysejahtera, which in turn they forward it to provider. It doesn't matter how the backend is implemented if they open their doors wide open.


AyamBlend
post Oct 19 2021, 12:16 AM

New Member
*
Junior Member
27 posts

Joined: Nov 2011
Time to retire this app as More abuse being seen especially for enforcement.
Business operator don't even recognize kad vaksin and writing on the book
PleaseEnterYourName
post Oct 19 2021, 12:56 AM

Casual
***
Junior Member
386 posts

Joined: Jan 2006
From: between 0 and 1


since when malaysian care about security? leakers everywhere.
silverhawk
post Oct 19 2021, 01:17 AM

Eyes on Target
Group Icon
Elite
4,955 posts

Joined: Jan 2003


Well this is technically not security, more like unintended use of service.

Simplest solution to this is to only allow one OTP to be sent in x amount of minutes to a single number.
TruboXL
post Oct 19 2021, 01:23 AM

Keep on keeping on! 👍
******
Senior Member
1,050 posts

Joined: Jan 2016
From: Land of floods, Kota Tinggi


Spamming KJ phone number will ruckle some feathers
WinkyJr
post Oct 19 2021, 02:29 AM

Casual
***
Junior Member
430 posts

Joined: Jul 2010

like this?

user posted image
God Grid
post Oct 19 2021, 02:33 AM

New Member
*
Junior Member
35 posts

Joined: Aug 2021
QUOTE(kons @ Oct 18 2021, 02:32 PM)
tengine webserver...

twitter bootstrap.. google font api... owl carousel.. jquery...

all free stuff but cost 70m... thanks to our competent gomen.
*
QUOTE(Darkripper @ Oct 18 2021, 02:37 PM)
Cost is not the question here. This is a critical app required by most residents in Malaysia, cannot compromise on security yo. Imagine a data-breach?
I see you're man of culture here. Jquery hurts my eye tho.
*
What's wrong with jQuery? Hmmm...
IJustWantToAsk
post Oct 19 2021, 02:37 AM

Getting Started
**
Junior Member
216 posts

Joined: May 2019
If you want, go bombard those politicians phone number

See if this really works
TSDarkripper
post Oct 19 2021, 02:46 AM

What do you expect?
******
Senior Member
1,258 posts

Joined: Dec 2008
From: /k/
QUOTE(TruboXL @ Oct 19 2021, 01:23 AM)
Spamming KJ phone number will ruckle some feathers
*
QUOTE(IJustWantToAsk @ Oct 19 2021, 02:37 AM)
If you want, go bombard those politicians phone number

See if this really works
*
PM me their number lor. Its a curl command, you can try it for yourself. Its pretty much copy paste run.

QUOTE(God Grid @ Oct 19 2021, 02:33 AM)
What's wrong with jQuery? Hmmm...
*
Its time had passed. tongue.gif


God Grid
post Oct 19 2021, 02:47 AM

New Member
*
Junior Member
35 posts

Joined: Aug 2021
QUOTE(Darkripper @ Oct 19 2021, 02:46 AM)
PM me their number lor. Its a curl command, you can try it for yourself. Its pretty much copy paste run.
Its time had passed.  tongue.gif
*
How bad is it? I dunno frontend, so no idea

I mean, there are other frameworks like React, Vue and Angular, but those are not UI only right?
TSDarkripper
post Oct 19 2021, 02:51 AM

What do you expect?
******
Senior Member
1,258 posts

Joined: Dec 2008
From: /k/
QUOTE(God Grid @ Oct 19 2021, 02:47 AM)
How bad is it? I dunno frontend, so no idea

I mean, there are other frameworks like React, Vue and Angular, but those are not UI only right?
*
jquery is top go-to library when everyone is manually manipulating HTML elements for frontend, it is easier to use than vanilla JS. It is not bad, just it is not that relevant anymore.

Then SPA like Angular, React comes along, which is easier to code, a little bit more structured and efficient. The best thing about SPA is there is less page refresh, providing a better UX.

Now you even have Vue, Svelte, SolidJS which is trying to overtake React.

Its not just for UI, but for client-side aka frontend to render and do whatever it needs to (communicate with server, service worker to run some shit in the background)

This post has been edited by Darkripper: Oct 19 2021, 02:52 AM
ihm11
post Oct 19 2021, 03:23 AM

Getting Started
**
Junior Member
62 posts

Joined: Apr 2018
pay peanuts get [______]

4 Pages < 1 2 3 4 >Top
 

Change to:
| Lo-Fi Version
0.0157sec    0.76    5 queries    GZIP Disabled
Time is now: 24th November 2025 - 10:03 PM