Quranic Student in Makassar Discovers NASA Security Vulnerabilities
Muhammad Al Hindawi, a student and 30-juz Quran memoriser from the Al Imam Ashim Islamic Boarding School in Makassar, South Sulawesi, has successfully discovered critical security vulnerabilities in the systems of the National Aeronautics and Space Administration (NASA) in the United States and the University of Melbourne, Australia.
The student, currently in his 12th year of secondary education, identified two SQL injection vulnerabilities within NASA’s systems and one similar flaw within the University of Melbourne’s infrastructure.
These findings were reported through the official Vulnerability Disclosure Program (VDP) on the Bugcrownd platform and have been formally validated by the cybersecurity teams of both institutions.
“I have been studying cybersecurity autodidactically for about four to five months,” said Hindawi on Wednesday.
Regarding the methods used for ethical hacking, Hindawi explained the identification stages he undertook to uncover the critical vulnerabilities.
“During the reconnaissance phase, I initially used Subfinder to collect subdomains, then checked their response status codes using httpx,” he explained.
Once the reconnaissance phase was complete, he proceeded to scan the systems to search for specific weaknesses.
“From there, I searched for systems vulnerable to SQL injection,” he added.
In recognition of his contribution, Hindawi received a Letter of Recognition (LOR) from NASA, as well as validation confirmation from the Cyber Operations team at the University of Melbourne.
Hindawi’s track record in cybersecurity began within his immediate environment. Before penetrating the security systems of global institutions, he first identified vulnerabilities within the systems of the Islamic boarding school where he studies.
He developed his cybersecurity skills independently through video tutorials and by studying research reports published by security researchers on Bugcrowd.
Hindawi continues to deepen his expertise in system vulnerability identification techniques by utilising various online learning resources independently.