Indonesian Cyber Practitioner Earns NASA Recognition for Uncovering 5,000+ Exposed Credentials
Technology
2026年9月4日
5
VOI English

General articles are free for 24 hours after publish.

Indonesian Cyber Practitioner Earns NASA Recognition for Uncovering 5,000+ Exposed Credentials

Share
AI Summary

Indonesian cybersecurity practitioner Stephanus Sunarto Purnomo has received a Letter of Recognition from NASA for discovering a significant security flaw within the agency's systems, revealing the exposure of over 5,000 credentials. He emphasizes the importance of analyzing attack paths to assess risks beyond mere vulnerability identification.

JAKARTA - Indonesian cybersecurity practitioner, Stephanus Sunarto Purnomo, has received a Letter of Recognition (LOR) from NASA after identifying a security loophole within a system under the agency's testing scope. Purnomo's findings were initially rated at Medium-High. However, through manual validation, security control analysis, and attack path tracing, he found a potential for greater impact. In the process, it was identified that more than 5,000 internal credential records were exposed. The findings were then reported through the responsible disclosure mechanism to the parties concerned. In the testing process, Stephanus ensured that he did not make any changes or deletions of data, interfere with services, misuse accounts, or disseminate sensitive information found. He also did not publish technical details that could be misused, such as specific endpoints, tokens, credentials, payloads, internal configurations, or bypass methods. Stephanus explained that security research is not enough to be done by identifying a vulnerability separately. Researchers need to understand how the weakness can interact with other conditions in the system and develop into a greater risk. For this, he analyzed the attack surface, application behavior, authentication and authorization mechanisms, as well as the implementation of the security boundary. The analysis was then followed by a search for attack paths to see the possibility of exploitation more thoroughly. According to Stephanus, automated scanners are still important in the testing process because they can help identify various indications of vulnerabilities. However, the tool has limitations in understanding the context of the system and the relationship between weaknesses. "Therefore, the severity of an individual vulnerability does not necessarily reflect the ultimate risk," Stephanus explained, in his statement, Thursday, September 3. Risk assessment, he said, needs to consider a number of factors, including exploitability, exposure level, access rights, data sensitivity, and the potential impact on the organization. After the findings were documented and reported through the appropriate channels, Stephanus received a Letter of Recognition from NASA. This recognition became one of the important achievements in his activities as a security researcher. Stephanus is a cyber security practitioner who has a career in the Indonesian banking sector. He has experience in the fields of cyber security, IT infrastructure, security monitoring, SIEM, vulnerability management, incident response, and information security. In addition to working in the industry, Stephanus is also active as a Cyber Security mentor at one of the universities in Indonesia. He also applied this experience in mentoring activities. According to Stephanus, the new generation of cyber security practitioners is not enough to just master various tools, but also needs to be able to think from the perspective of attackers and defenses as well as understand the limits of ethics in conducting tests. For Stephanus, the recognition from NASA is not the end, but an encouragement to continue to learn and develop capabilities in the midst of increasingly complex digital security threats. "Cybersecurity is not about how far we can penetrate a system. Cybersecurity is about finding vulnerabilities before they are exploited by malicious parties, proving the risks, and helping make the system more secure," he said.

0

Original source

VOI English

原文を読む