Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 MyJPJ apps got flaw for registration?

views
     
TSfadzly
post Feb 10 2023, 07:35 PM, updated 3y ago

Regular
******
Senior Member
1,757 posts

Joined: Oct 2005



I think I’ve found a serious flaw with the MyJPJ apps.

Did u know, the apps allowing anybody to register as long as u have an ic number that registered to JPJ database. Yes. without any verification that u own the ic number.

The only thing preventing you from registering with someone else ic are the term and condition. This could lead to some people with bad intention to use someone else ic and register the apps to get information such as home address and picture of u.

And i could see in future that some people could not register their account as the account might be registered earlier by someone else.

i do realised, u are required to put your phone number. But u can put anybody phone number. Right?

I might be wrong. Need to verify with someone with IT security expert or anybody?




-----


QUOTE(shangsuo @ Jun 20 2023, 04:57 PM)
Renew my car insurance/roadtax today. So, also try MyJPJ App.
During registration, stuck at "no siri lesen kompeten tidak sepadan".
A Google search shows me this thread. So, I want to share resolution.

The serial number is mixture of 8 random alpha-numeric big small cap, and printing is rather small.
i.e. high chance to read wrong.
I took a picture then enlarge it only to realize the '8' is actually B.
*
This post has been edited by fadzly: Jun 21 2023, 12:50 PM
TSfadzly
post Feb 10 2023, 08:12 PM

Regular
******
Senior Member
1,757 posts

Joined: Oct 2005



If u can register ur parents account using your phone number and email, means everyone can be your parents.

Old people are not tech savvy. Hence they are the one prone to complication like this.
TSfadzly
post Feb 10 2023, 09:14 PM

Regular
******
Senior Member
1,757 posts

Joined: Oct 2005



QUOTE(soul78 @ Feb 10 2023, 08:26 PM)
that's why with Recent jpn leak... someone who bought the Database just need to make a script to mass register for everyone in merehsia...

kekk...
*
QUOTE(brkli @ Feb 10 2023, 08:31 PM)
actually, if u want, you can just brute force, since mainly numeric and most of the number also within a specific range, sumore got millions of rakyat, which mean high probability to hit result. first 6 number is date so pandai pandai la construct base on date range, following 2 digit, is state code (also within a specific range). last 4 digit just hantam.
*
This is what i scared will happen.

It somewhat similar to MySejahtera where u can register anybody like KJ to be your dependent. But good thing with MyS, they are not releasing private information.
TSfadzly
post Feb 10 2023, 09:54 PM

Regular
******
Senior Member
1,757 posts

Joined: Oct 2005



QUOTE(kel32 @ Feb 10 2023, 09:29 PM)
possible to prevent this is mandatory scan physical IC, only matching IC able to proceed an account.
or get a TAC at booth like EPF online registration.
*
Can do like shopee or tng camera verification
TSfadzly
post Feb 11 2023, 07:53 AM

Regular
******
Senior Member
1,757 posts

Joined: Oct 2005



I got my parent registered within the same phone and email. Even after logged out my account, i can only see my license and not my parent. Havent tried delete the apps or clear cache yet. Another flaw.
TSfadzly
post Feb 11 2023, 08:37 AM

Regular
******
Senior Member
1,757 posts

Joined: Oct 2005



QUOTE(LamboSama @ Feb 11 2023, 08:35 AM)
You are not wrong,
It is also an issue with most government owned app/sites that provide detailed information just from ic number,

But as you can see a lot of Malaysian takes cybersecurity and personal information lightly.

IC number should be kept as private as possible.
*
KJ IC last time also leaked. People access to vaccine website and found the vaccine record is not there. Turn out the website no longer maintained. Very dangerous as could no longer change ur ic number.
TSfadzly
post Feb 11 2023, 11:51 AM

Regular
******
Senior Member
1,757 posts

Joined: Oct 2005



Could some one tag Anthony loke about this?

I think they should come out with a verification to register.
TSfadzly
post Feb 11 2023, 12:02 PM

Regular
******
Senior Member
1,757 posts

Joined: Oct 2005



QUOTE(soul78 @ Feb 11 2023, 11:53 AM)
when register got ask for password?...
*
Its like registering new account for facebook or gmail. Need to set up password email and phone number
TSfadzly
post Feb 11 2023, 12:32 PM

Regular
******
Senior Member
1,757 posts

Joined: Oct 2005



QUOTE(la bella @ Feb 11 2023, 12:04 PM)
The first time I register at app it says my ID been registered before and I click forgot password and my email not matched.
Then I re-register at the JPJ website to change it to my email and reset password.

That means anyone can register on behalf of a person. Mine been registered by someone else.

JPJ need to think of a way to prevent such thing happened.
*
Means anyone can reset password also?🥲
TSfadzly
post Feb 11 2023, 01:08 PM

Regular
******
Senior Member
1,757 posts

Joined: Oct 2005



QUOTE(dattebayo @ Feb 11 2023, 12:56 PM)
Anthony Loke cakap
apps MyJPJ tidak diwajibkan

penguatguasa can still check the status lesen and roadtax via their device

sekian
*
Its not about compulsory or what.

Someone can just create a script for register and run brutforce to get all information among those who havent register. Worst they could sell the data. Your home address there.

Or ah long try to locate you 10 years hutang, old ic got old info. U update the latest home address when renew. They register using ur ic, walla, they got your latest address.
TSfadzly
post Feb 11 2023, 01:22 PM

Regular
******
Senior Member
1,757 posts

Joined: Oct 2005



QUOTE(dattebayo @ Feb 11 2023, 01:15 PM)
true

but this is Malaysia

i am highly sure this is not the first time of such instance happen

hell even Astro also got data leakage before, just run a brute force against their API (not secured via secret key) and get the customer info
*
They, JPJ got all the sop to verify user at their counter. Why didn’t practice the same online. Sigh.
TSfadzly
post Feb 15 2023, 07:20 PM

Regular
******
Senior Member
1,757 posts

Joined: Oct 2005



Thanks wee ka siong.
TSfadzly
post Feb 15 2023, 07:39 PM

Regular
******
Senior Member
1,757 posts

Joined: Oct 2005



What ive found is merely logic. Hence if they couldnt protect this simple thing means how bad our ict developers are.
TSfadzly
post Feb 15 2023, 07:44 PM

Regular
******
Senior Member
1,757 posts

Joined: Oct 2005



QUOTE(taitianhin @ Feb 15 2023, 07:43 PM)
As bad as the police force?
I still hearing 2 occasions of corruption on going now...
1 fren paying RM30K to Kuantan Police Head
another fren paying RM3k for drunk driving....no saman....just Their Head want Exactly RM3000, no less than that...

both cases, "wanna go court tak?"
*
Teruk nya. Sian.
TSfadzly
post Feb 23 2023, 03:50 PM

Regular
******
Senior Member
1,757 posts

Joined: Oct 2005



QUOTE(Shengo @ Feb 23 2023, 01:33 PM)
Anyone facing issue that No Siri Leson Kompeten tidak sepadan during registration at mySikap? I have key in for more than 10 times d.
*
proly u need to go JPJ.

im glad that they restricted the registration of the apps.
TSfadzly
post Jun 21 2023, 12:50 PM

Regular
******
Senior Member
1,757 posts

Joined: Oct 2005



QUOTE(shangsuo @ Jun 20 2023, 04:57 PM)
Renew my car insurance/roadtax today. So, also try MyJPJ App.
During registration, stuck at "no siri lesen kompeten tidak sepadan".
A Google search shows me this thread. So, I want to share resolution.

The serial number is mixture of 8 random alpha-numeric big small cap, and printing is rather small.
i.e. high chance to read wrong.
I took a picture then enlarge it only to realize the '8' is actually B.
*
Noted. Thanks. Will put at front page

 

Change to:
| Lo-Fi Version
0.0184sec    0.65    6 queries    GZIP Disabled
Time is now: 9th December 2025 - 02:29 PM