LinkedIn · Azhar Basyiri Hartono
Photo of Azhar

Azhar Basyiri Hartono

Security Researcher

San Bernardino, California, USA.

Nick Name: Azhar English Resume 64 Experience Entries

Contact Info

Nick Name Azhar
Birth Name Azhar Basyiri Hartono
Date of Birth April 19, 1999
Place of Birth Pemalang, Central Java, Indonesia
Gender Male
SMS - 3 IOH (Main) +6289671183100
SMS - By.U Tsel (Backup) +6285188353323
Masriah Hasan Blog ohmiloveit.my.id
Address San Bernardino, California, USA.

Objective

I'm not anyone, but you can make me who I am by giving me life experiences and collaborating with me on the work I can do. Ask me and offer me any opportunity to earn income, and don't ask anything unimportant unless you want to discuss the knowledge I've discussed in my experience.

Education

Senior High School

2017

Origin Of Institute: SMAN 12 Bekasi

Major: Natural Science

Junior High School

2014

Origin Of Institute: SMPN 38 Bekasi

Major: General

Elementary School

2011

Origin Of Institute: SDN Harapan Baru 5 Bekasi

Major: General

Elementary School

2008

Origin Of Institute: SDN Klapanunggal 04 Bogor

Major: General

Elementary School

2007

Origin Of Institute: SDN 01 Sirangkang Jateng

Major: General

Elementary School

2006

Origin Of Institute: SDN Harapan Baru 3 Bekasi

Major: General

Kindergarten

2005

Origin Of Institute: RA Ibnu Sina Bekasi

Major: General

Nat. Exam Score

Senior High School

2017

Indonesian: 78.0

English: 56.0

Mathematics: 15.0

Biology: 42.5

Junior High School

2014

Indonesian: 7.4

English: 8.0

Mathematics: 4.75

Natural Science: 6.75

Elementary School

2011

Indonesian: 7.6

Mathematics: 7.25

Natural Science: 7.75

Other

Assets Valuation (Stocks)

2017 - 2026

Research Non Profit: Rp3.2B (US$181,500)

Media: Rp614M (US$34,151)

Domestic Account (Citibank USA)

2026

Routing ABA: 031100209

Account Number: 70581330002616579

Account Type: CHECKING

Recipient Name: AZHAR BASYIRI HARTONO

Domestic Account (Citibank UK)

2026

Sort Code: 185008

Account Number: 56975178

Recipient Name: AZHAR BASYIRI HARTONO

Driving License (SIM C)

2024

ID: 1222-9904-003616

Electronic Money (Donation)

2023

Bank Central Asia: 0663436268

SWIFT Code: CENAIDJA

IDX Investor ID (AKSes KSEI)

2021

ID: IDD1904WV720833

National Library

2021

ID: 19022000021

Saidjah Adinda Library

2021

ID: 19121500001

Fingerprints Formula

2020

Right: 14 M 7 U OOO 10

Left: O 4 W OOO

Tax ID Number (NPWP)

2020

ID: 94.291.539.8-407.000

Population ID Number (NIK)

2017

ID: 3275031904990016

STIFIn

2016

Test Result: Intuiting Extrovert

Blood Type

2015

Test Result: A /Rh. +

Social Health (BPJS)

2014

ID: 0001800350201

Staatsblad (Stbld.)

1999

ID: 1920:751 jo. 1927:564

Skill

Simple Household

Doing basic household chores (Sweeping, Mopping) & Observer of social and political issues independently (Limited Scale)

Computer & Information System

Basic use of operating systems (Linux, Windows, iOS, Android, Symbian, BlackBerry) & Cyber Security Analyst

Experience

Menampilkan semua 64 entri.

BBK Electronics

2026

Security Researcher

  • On cellphones under the auspices of BBK for example Vivo there are actions that block access to certain websites even if using Secure DNS or VPN so that accessing the internet is not safe because it is intercepted in their system

Meta

2026

Security Researcher

  • Hackers make changes to WhatsApp contacts on several vulnerable Android devices (Except: Huawei) via remote access trojan to trick the user concerned as if the contact is real, the name and WhatsApp profile information of the contact are the same but the cellphone number has changed or is not the same as the original owner. Hackers do this by imitating the behavior of the person concerned and can then carry out other losses such as criminal acts. Always make sure that WhatsApp contacts are stored on the SIM card too and not just in the phone storage so that if there is an attack like this it will not have an effect because users can compare contact information that is not in sync because there are two different cellphone numbers

Smartfren

2026

Security Researcher

  • Cases were found that the company (before the merger with XL Axiata) manipulated the appearance of the 4G/LTE network indicator on older devices that were previously sold, such as Andromax devices on MiFi, namely Andromax M2y and M3y, Andromax cellphones such as Andromax A, as well as on Samsung devices that collaborated with the note that only modem chipsets specifically run 4G on one sim slot only and not dual 4G, manipulation by making weak signal bars appear full, but if on other operators they are made to look worse, to 2G everything looks normal and the signal indicators are not manipulated

Meta

2026

Security Researcher

  • WhatsApp fails to delete the old contact list of users synchronized by the previous user, for example, even though the WhatsApp account has been deleted or deactivated, including numbers that have been recycled by mobile operators and used by new users, it still stores contacts from previous users which causes data leaks, scammers buy used numbers and target existing contact numbers to commit crimes, besides that, if a legitimate user can also be dangerous, for example, writing a status to "My Contacts" in privacy settings but seen by unauthorized people

Bank Mandiri

2026

Security Researcher

  • The balance is sometimes deducted twice and there is no protection for the balance being deducted for the same nominal amount within a relatively short time, for example 1 minute, and the admin fee for topping up electronic money at minimarkets is sometimes not IDR 1,500 but IDR 2,000, so users are not aware of such things because they occur randomly, making it difficult to audit.

IOH

2026

Security Researcher

  • Hidden commands launched to IM3 or Tri (3) cards via the baseband are forwarded to the SMS storage on the SIM card itself and not through the phone storage so that users do not realize that there is something suspicious behind the scenes, its function is to track users secretly or subscribe to Premium SMS secretly with a random 4-digit ADN number so that users cannot manually unregister the ADN that enters the incoming SMS storage on the phone because the ADN number between the one on the SIM and the phone is different, besides that it cannot be read either through the system such as *185# or checking subscription content via USSD. The reason why it is stored in the SIM storage itself is due to the deliberate inability of the modern cellphone vendor to backtrack so that users cannot do anything as known as a zero day attack

GoTo Indonesia

2026

Security Researcher

  • If you use QRIS Tap and have tapped in on a mode of transportation, for example Trans Jakarta, then do not empty your balance to zero rupiah during the trip, which will result in you not being able to tap out because the balance is insufficient even though the balance has been held previously when you tap in, leave a minimum of 1 Rupiah or to be safer, a balance equivalent to the longest trip, for example, if you use Trans Jakarta, the minimum balance should be IDR 3,500 in your GoPay account to avoid problems, likewise other modes of transportation can be adjusted according to the fare information provided, for example MRT, LRT and KRL Commuter Line.

N. Library of Indonesia

2026

Security Researcher

  • Public computers on the 19th floor do not completely delete data such as Mozilla Firefox and Google Chrome up to downloaded files after the previous user has left the computer so that some data can be accessed by other parties for example the next user. For users of this public computer, it is recommended to delete cookies on Mozilla Firefox and Google Chrome after finishing using the computer and also delete downloaded files and the recycle bin, after that turn off the computer completely, not logging off but shutting down.

Replica Chinese Phones

2026

Security Researcher

  • On replica Chinese cellphones that are found, such as old Nokia cellphones with only telephone and SMS capabilities (Old Cellphones), they send statistics in the form of logs of incoming calls, outgoing calls, incoming SMS and outgoing SMS, and for more sophisticated cellphones such as Vivo or Oppo, they send similar things plus the ability to take screenshots hidden behind the screen for several applications which can result in financial losses.

Microsoft

2026

Security Researcher

  • On Windows Phone (Windows 10 Mobile), do not remove the battery or turn it off forcibly or suddenly for any reason that causes it to not start or get stuck in BSOD (Black Screen Of Death) which displays Windows Boot Manager just like on a computer, if you have experienced this then connect the phone and use the software on the computer in Windows called Windows Phone Internals and/or Windows Device Recovery Tool and look for the appropriate software for the type of Windows phone that is damaged. It is recommended if the previous Operating System used Windows Phone 8.1 to return to that version to avoid BSOD.

XLSmart

2026

Security Researcher

  • The operator is suspected of exploiting the network on XL card users by sending random hidden commands without the user's knowledge, which triggers the Google service framework to send automatic subscription SMS to certain numbers, for example 99265, resulting in credit being deducted if prepaid or billing being inflated if postpaid. This exploit is transparent or can be seen on Qualcomm chipset devices, but on devices with MediaTek chipsets, the process can be hidden behind the scenes.

LG

2026

Security Researcher

  • LG V and G series have a software error that causes repeated bootloops if Google Play Services is turned off on the stock ROM, the solution if you have already turned it off is to turn Google Play Services back on if the phone is still on or if a bootloop has occurred because the phone is turned off then the user can enter the recovery menu and wipe data, pay attention to the Google account if it is still there so you don't forget it because you have to re-enter it after the reset or if you forget it you will get stuck in FRP.

Trans Jakarta

2026

Security Researcher

  • If another person's card encounters an error, such as failing to tap out (on the bus machine), even though the original card has already tapped successfully, the next card that taps on the machine will be confused in reading the status whether it should be tap in or tap out. As a result, if the card is tapped in, it may be read as the opposite. When the card is later scanned upon exiting the bus stop, it will display "Card Reset Successful" which deducts the balance multiple times and is considered a violation. This error usually occurs more frequently on bus machines, while at bus stops it happens when the reader experiences disruptions either due to electrical issues (after a power outage) or slightly slow network connections.

Bank Central Asia

2026

Security Researcher

  • BCA does not encrypt the conversation history through HaloBCA that is sent via e-mail, including password changes, internet banking registration creation, and new device access that displays the user ID and time/date metadata. This causes data leakage and does not comply with personal data protection, and a hacker can gain access to MyBCA without facial verification.

IOH

2026

Security Researcher

  • IM3 Ooredoo Hutchison users can stream data randomly even without credit balance or internet quota. This is not an official benefit such as a bonus internet package, but rather a backdoor used for tracking users and secretly updating software on the SIM card without the user's awareness. If there is no credit balance or internet quota, users can remove the card from the phone. It is recommended not to use the card in a phone for IM3 Ooredoo Hutchison, but instead place it only in a WiFi modem. Do not use OTP access for mobile banking, social media, or other important matters with the IM3 Ooredoo Hutchison mobile number, it should preferably be used only for internet purposes.

IOH

2026

Security Researcher

  • Hackers can mimic as if there is a call from a legitimate IM3 Ooredoo Hutchison customer number to another mobile number, even without credit balance and without appearing fake, causing the network to become busy and unavailable. The customer does not realize that their number is currently out of reach, with the intention of obtaining or searching for certain information related to relationships. The indication of such an attack can only be carried out on Chinese phones that have a MediaTek baseband modem chipset, such as (Vivo), and hidden commands are executed through vulnerabilities in the related mobile operator. For now, it is known to exist only on the IM3 Ooredoo Hutchison operator. For other mobile customers who receive calls from IM3 Ooredoo Hutchison numbers belonging to contacts using MediaTek chipset phones, please be cautious and do not answer immediately, but instead confirm by calling the person back. If the call continues to be unavailable or redirected to voicemail after calling back, there is a possibility that the person is experiencing this attack.

Meta

2025

Security Researcher

  • Facebook application has an Easter egg when it is not connected to the internet for a long time randomly and does not always display to the user an instrumental piano music without the cat's voice "Miaw miaw miaw miaw (Sad cat song)". Note: This is not a security issue but additional knowledge for other Facebook users and the form of the song instrument or Easter egg can change at any time Facebook wants

Meta

2025

Security Researcher

  • Users whether through WhatsApp or WhatsApp Business who view incoming messages from WhatsApp Business are tracked secretly without the user's knowledge to obtain the following metadata: When the user first read the message and when the user reread the message. If this metadata is not obtained, WhatsApp and WhatsApp Business applications are forced close so that message cannot be read until the metadata is obtained

Telkomsel

2025

Security Researcher

  • It is suspected that state actors were involved in a cyber attack in the form of Sunburst malware against Azhar via Telkomsel's network infrastructure on Azhar's internet access in the early hours of the morning using DNS Hijacking. Several days before this incident, Azhar also received an OTP from Telkomsel without a request

Telkomsel

2025

Security Researcher

  • Prepaid cellular cards registered with any NIK and KK can be unregistered via USSD at *444# with NIK 111111111111111 (16 digits of number 1)

Meta

2025

Security Researcher

  • Leakage of chat content information on a previous mobile phone number that has been transferred to another device can be copied with a different number with the same chat content, a different mobile phone number with a different device but the same chat content (can be transferred without user consent to steal WhatsApp message content)

DANA

2025

Security Researcher

  • There has been a leak of personal information identification in Android applications even though they have been reset to factory settings or have been flashed with an Android ROM

Lalamove

2024-2025

Motorbike Driver (Courier)

  • Pick up the package at the delivery point and deliver the package to the destination point

Meta

2024

Security Researcher

  • Allegedly that WhatsApp sells data, the test was carried out by transferring the account from WhatsApp Personal to WhatsApp Business and filling in profile information with a Chinese theme such as profile photos and description information available in Chinese language, 1 day later someone offered information about KTA loans (Credit Without Collateral) by Bank CTBC Indonesia who contacted me by telephone to my personal cellphone number which is the same as registered on WhatsApp Business

By.U Indonesia

2024

Security Researcher

  • Found a security loophole that registration data can be changed remotely without knowledge so that the user loses access to their card and a security loophole in the OTP lock feature can be bypassed to waste someone's credit

Maxim

2024

Motorbike Driver (Ojek)

  • Pick up passengers at the booking point and drop off passengers at their destination point

Television Stations

2024

Paid Audience

  • Enliven the event that is being broadcast either live or postponed
  • Maintain order in the atmosphere of indoors and outdoors

Telkomsel

2024

Security Researcher

  • The security of replacement cards, such as upgrading 3G to 4G cards or replacing lost or damaged cards, has weaker security compared to new starter cards and old starter cards sold on the market

Tiktok

2024

Security Researcher

  • The TikTok application carries out surveillance in the form of hidden location checks when a user reposts without the user's knowledge. If they don't get hidden location access then the user won't find the repost button on the post that will be shared with the user's profile.

Meta

2024

Security Researcher

  • Found that WhatsApp on Android devices checks the location before the mobile number is registered and when changing the mobile number so the number cannot be registered outside the country of origin and I managed to log in even though I used a foreign number

IDGOV

2022

Security Researcher

  • Discovered that malicious hackers are leveraging government websites in subdomains and subdirectories to promote online gambling

IOH

2022

Security Researcher

  • Error in the loyalty point calculation system so users with failed transactions still get additional points and the active period on the card can be reversed with the weakness of default bundling package like a new card

Yandex

2022

Security Researcher

  • Found that Yandex made a censorship by blocking several IP addresses so that sending emails on external provider emails to Yandex was hampered and considered as wrong address even though the email address was available and even though it was not the spam category

Apple

2022

Security Researcher

  • Found that Apple does censorship by pre-scan emails before sending emails so that even though the status of the email is sent, it is not in the sent folder of the email sender nor does it reach the email recipient

The Hidden Wiki

2022

Volunteer

  • Follow as a contestant in writing blog articles as well as a contributor (volunteer) with the addition of the .onion link that is not yet available in the social networks category namely Twitter and a suggestion to remove the .onion link from CTemplar as they have been out of operation since May 26 of 2022 based on their official blog post on April 26 of 2022

Bestari Web Host

2022

Security Researcher

  • Finding the use of the identity of the company's website domain is used by irresponsible parties as gambling websites and has been reported to the official website owner and to PANDI (Registry)

Apple

2022

Security Researcher

  • A security hole in the default photo application which can restore a deleted old iCloud photos by adding as many photos as possible from the third party or default file application and send it to the default photo application

Twitter

2022

Security Researcher

  • Successfully made the system unable to reset the password of the account due to an ostensibly false reading so that identity information could not be synchronized with each other

Telegram

2022

Security Researcher

  • Can successfully enter the group even if the admin or moderator has banned

Smartfren

2022

Security Researcher

  • I provide criticism and suggestions on security issues and other important things on the SFShop service to make it more secure and comfortable for all users who use the service

Twitter

2022

Security Researcher

  • Found a security vulnerability that malicious links were inserted by hackers using multiple robotic accounts distributed into videos that would attract users to watch them (Links in the form of videos that can be played like user uploads in general), redirect users automatically to malicious websites that have the potential to harm users, further investigation found that the hacker's domain was from Russia & China and the link managed to trick the virus detection check so it didn't look dangerous, the hacker's technique used skipping the link several times before arriving at the actual malicious website's destination

Bukalapak

2022

Security Researcher

  • The description of the security hole is kept secret (Only for internal parties from Bukalapak ; the vulnerability has been reported through BukaBounty) for user safety
  • Update From Bukalapak: Hi, Thank you for your report. After going through the verification process, we categorize your findings as invalid (Out of scope). Social Engineering is a report that is not included in our bug bounty scope. Therefore, according to the rules of BukaBounty, you are not yet entitled to receive rewards. Thank you for participating in BukaBounty! Regards, NPT [Initial Name] (Cyber Incident Responder)
  • Update From Me (Response): This security vulnerability is the same as in Shopee Indonesia (No Click / Zero Click) without the user having to do anything but this security hole is still kept secret by me for the safety of other users even though it is categorized as Social Engineering by Bukalapak

Tasya ID Media

2021

Security Researcher

  • Bug (25-12-2021): I as the former owner of Tasya ID Media found a zero day attack that can't be fixed, this finding was found by me while visiting the interstitial page of Tasya ID Media which forced downloads, the visit was made with an Apple device and has not been found on an Android device or Computer, Tasya ID Media does not provide download files in any form and does not force users to take download actions, the source code of the website from Tasya ID Media does not provide source code malicious and all source code is publicly available
  • Fixed (28-12-2021): This issue was resolved by a third-party independent researcher; Errors on WebKit when experiencing heavy activity by running a series of activities on the browser by opening tabs a lot or quickly or closing tabs and immediately opening certain static web-based websites will result in triggering downloads accidentally, the solution is to periodically delete cookies and cache and if wanting to turn off JavaScript is recommended for visitors when visiting static websites, this bug is harmless but users should still be careful not to click download if a pop up appears on the first visit because the integrity of the website is questionable whether it is original or compromised by malicious source code from hacker

Facebook

2021

Security Researcher

  • Found that one mobile number can be used on two or more accounts
  • Bypass face verification by using a solid white color photo

Twitter

2021

Security Researcher

  • Found out that there was data theft from accounts run by robots by distributing fake quiz forms with prizes (For doxing targeted user data)
  • Found many unverified accounts (phone numbers and e-mails) to spread mentions or DMs used to track targeted users (Journalist, Activist, Opposition, Politician)

OVO Indonesia

2021

Security Researcher

  • Found an application security vulnerability on Apple devices that can bypass the the user's PIN so that it can enter the application (Physical access to the device is required)

Indonesia Stock Exchange

2021

Investor

  • Learn about stocks and company performance
  • Become a small investor and return big losses

Telkomsel

2020

Security Researcher

  • Found a security hole that the card that has been unregistered can still be used and runs smoothly like a normal registered card

3 Indonesia

2020

Security Researcher

  • Found a loophole that registration data can be changed remotely without the user's knowledge so the real user loses access to the card

Kopega PLN Sektor Priok

2020

Industrial Cleaner

  • Outdoor cleaning (Bunker, Street, Park, Seaside)
  • Indoor cleaning (Office, Control Room)

Cimigo Indonesia

2020

Product Research

  • Assess the feasibility of the product before it is marketed to the public
  • Keep the secret of product that will be issued by the company

Street

2020

Tramp

  • Become a beggar on the street
  • Observing and living the social life of the lower class with love

Tasya ID Media

2019-2021

Owner

  • Learn to manage my own media self-taught
  • Interact with people and international media on a non-profit basis

Television Stations

2019-2020

Paid Audience

  • Enliven the event that is being broadcast either live or postponed
  • Maintain order in the atmosphere of indoors and outdoors

InfinityFree

2019

Forum Volunteer Support

  • Ask and answer about hosting and websites problems to other users
  • Providing users with tips and tricks about hosting and websites

Media Monitoring Club

2019

Writer

  • Learn to write as a content creator
  • Writers who write about any topic of interest

Telkomsel

2018

Security Researcher

  • Finding security holes that other users can carry MITM (Man In The Middle) attacks so that they can carry out unauthorized transactions without the knowledge and confirmation of the real user

IPPO Fried Chicken

2018

Sales Officer

  • Make fried chicken & put it in the display case
  • Take orders & serve customers who want to buy

Secret Recipe Indonesia

2018

Restaurant Crew

  • Baking cakes in a microwave oven
  • Serving customers who want to buy

Asian Games 2018 (Test Event)

2017

Volunteer

  • Providing for the needs of athletes
  • Maintaining the cleanliness of the sports arena
  • Maintain security so that the event runs smoothly

CAFE V

2017

Waiter

  • Setting the table & cleaning dirty tableware
  • Take customer orders & deliver to the cook

Street

2017

Scavenger

  • Looking for a offline job by job fair
  • Picking up trash on the street to resell

FB, IG, Twitter

2017

White Hat Hacker

  • I got into all the old social media belonging to my middle school girl friend by hacking it and I already told her and apologize directly

Ministry of Education & Culture

2017

Security Researcher

  • I found a security loophole that using repeated answers can log all users out on one server and can slow down exam time
  • Exam browser can be minimized in a certain way so that users can cheat in exams without worrying about exiting the system