about
I'm a penetration tester on Temika Cyber's Red Team, based in Bandung, Indonesia — web, mobile, and infrastructure assessments against the OWASP WSTG and MASTG, with remediation retesting to confirm fixes actually hold.
My route here wasn't the usual one. I built mobile and backend applications first — Flutter, Dart, Node.js, Firebase, on-device ML — so I read applications from the inside out: how they're wired, where trust boundaries get assumed instead of enforced, and which "impossible" states nobody tested.
That builder's instinct is what I now point at access control, authentication, and business logic. I found and responsibly disclosed a Critical (P1) account-takeover chain in a production university portal, won first place at a national cybersecurity CTF, and reached Professional rank (Top 5%) on Hack The Box Academy. I still run CTFs and bug bounty outside work.
disclosed findings & wins
P1 · CRITICAL account-takeover.md
Account Takeover — IDOR + Broken Access Control
Chained an IDOR pattern in user-scoped requests with a broken access-control check to reach full account takeover on a USU production student portal (mahasiswa.usu.ac.id). Built a Burp Suite proof-of-concept, then reported through responsible disclosure with impact statement and remediation guidance. Received an official Certificate of Appreciation from Pusat Sistem Informasi USU.
Certificate of Appreciation — PSI USU →
1st PLACE siber-tangguh-2025.md
National Cybersecurity CTF — "Siber Tangguh Bangsa Merdeka" 2025
First place in a national, team-based Capture The Flag competition focused on web security fundamentals and attack-surface exploration.
Certificate →