• Hype
  • Murai
  • Lipstiq
  • Varnam
  • Hangat
  • Autofreaks
Lowyat.NET
  • News
    • Lifestyle
    • Computing
    • Hardware
    • Internet
    • Rumours & Leaks
    • Software
  • Forums
    • Kopitiam
    • Tradezone
    • Property Talk
    • Finance & Business
    • Fast and Furious
  • Gaming
    • PC Gaming
    • Console
    • Mobile Gaming
    • Esports
  • Mobile
    • Apps
    • OS
    • Tablets
    • Phones
    • Telco
      • Celcom
      • DiGi
      • Maxis
      • Tune Talk
      • U Mobile
      • Buzzme
  • Pricelists
    • Compu-zoneUpdated
    • ViewnetUpdated
    • Sri ComputersUpdated
    • StartecUpdated
  • More
    • Automotive Tech
    • Drone
    • Enterprise
    • Entertainment
    • Fashion
    • E-Hailing
    • Wearables
No Result
View All Result
Lowyat.NET
  • News
    • Lifestyle
    • Computing
    • Hardware
    • Internet
    • Rumours & Leaks
    • Software
  • Forums
    • Kopitiam
    • Tradezone
    • Property Talk
    • Finance & Business
    • Fast and Furious
  • Gaming
    • PC Gaming
    • Console
    • Mobile Gaming
    • Esports
  • Mobile
    • Apps
    • OS
    • Tablets
    • Phones
    • Telco
      • Celcom
      • DiGi
      • Maxis
      • Tune Talk
      • U Mobile
      • Buzzme
  • Pricelists
    • Compu-zoneUpdated
    • ViewnetUpdated
    • Sri ComputersUpdated
    • StartecUpdated
  • More
    • Automotive Tech
    • Drone
    • Enterprise
    • Entertainment
    • Fashion
    • E-Hailing
    • Wearables
No Result
View All Result
Lowyat.NET
No Result
View All Result
Home Security

PADU Vulnerability Reportedly Allowed Password To Be Changed With IC Number

The flaw has apparently been patched.

by Ikmal Rozlan
January 3, 2024
padu security flaw vulnerability

Image: @Iamkanahraf, via X

Share on WhatsappShare on TelegramThreads

The Malaysian government officially launched the Central Database Hub (PADU) yesterday and within hours, a developer found a major flaw in the system’s API. The vulnerability reportedly allowed any bad actor to change a person’s login password using just their IC number if they wished to do so.

Following the reveal of this critical flaw, the ministry of economy replied to the developer’s tweet, stating that it took note of the finding and is making the needed improvements. According to an update by minister of economy Rafizi Ramli, this flaw has been fixed last night, with the developer in question also confirming that the API has indeed been changed.

Guess what.

I only need your IC number to override and change your PADU login password.@farhanhelmycode @rafiziramli @Dr_Uzir @lamkanahraf pic.twitter.com/m1K2mR3wP2

— useState('drmsr') (@drmsr_dev) January 2, 2024

While this vulnerability seems to be patched, former deputy minister of international trade and industry, Ong Kian Ming, has pointed out that anyone with your IC number and postcode can register for a PADU account on your behalf without your permission as the identity verification only comes after creating the account. This would lead to the actual owners of the IC numbers to be unable to register themselves.

While the relevant data is still owned by the respective agencies, Rafizi has said that PADU is owned and managed by the department of statistics. The department’s chief statistician Mohd Uzir Mahidin revealed that the database’s security is handled in-house with 49 certified data scientists and security barriers already in place.

RELATED:  Govt To Announce Expanded Use Of PADU By Early March 2026

(Source: @drmsr_dev/X)

Filed Under central database hubflawpadusecurityVulnerability
Updated 12:56 pm, Wed, 3 January 24
http://lowy.at/iUmvi
SendShareShareShare2Tweet1

Follow us on Instagram, Facebook, Twitter or Telegram for more updates and breaking news. 

No Result
View All Result

TRENDING THIS WEEK

  1. 1
    Lifestyle

    The Gundam Base Malaysia Is Now Officially Open

  2. 2
    Mobile Phones

    HONOR 600 Series Design Revealed Ahead Of Local Launch

  3. 3
    Mobile Phones

    HONOR 600 Series To Launch In Malaysia Next Week

  4. 4
    Mobile Phones

    Huawei Unveils Pura X Max Design; Comes In Five Different Colours

  5. 5
    News

    Malaysia Still Without Broadcaster For FIFA World Cup 2026

NETWORK

  • Hype
  • Murai
  • Lipstiq
  • Varnam
  • Hangat
  • Autofreaks

ABOUT

  • Advertise
  • Careers
  • Privacy Statement
  • Editorial Policy
  • Terms of Use
  • Contact Us

©2026 VIJANDREN RAMADASS. ALL RIGHTS RESERVED.

No Result
View All Result
  • News
  • Forums
  • Laptops
  • Telco
  • Mobile
  • Gaming
  • Fintech
  • Artificial Intelligence
  • Cryptocurrency
  • Cyber Security
  • Hybrid Vehicles
  • Advertise with Us

©2026 VIJANDREN RAMADASS. ALL RIGHTS RESERVED.

No Result
View All Result
  • News
  • Forums
  • Laptops
  • Telco
  • Mobile
  • Gaming
  • Fintech
  • Artificial Intelligence
  • Cryptocurrency
  • Cyber Security
  • Hybrid Vehicles
  • Advertise with Us

©2026 VIJANDREN RAMADASS. ALL RIGHTS RESERVED.