{"id":396,"date":"2025-08-01T08:17:54","date_gmt":"2025-08-01T08:17:54","guid":{"rendered":"http:\/\/localhost\/binus-wp\/cyber-security\/?p=396"},"modified":"2026-07-16T15:26:45","modified_gmt":"2026-07-16T15:26:45","slug":"phising-detection-system","status":"publish","type":"post","link":"https:\/\/socs.binus.ac.id\/cyber-security\/2025\/08\/01\/phising-detection-system\/","title":{"rendered":"Gerobug"},"content":{"rendered":"<p class=\"font-claude-response-body break-words whitespace-normal\"><strong>The Bug Bounty Platform Indonesia Built and Gave Away<\/strong><\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal\">Most organizations know they should invite security researchers to find their flaws. Far fewer actually do it. Commercial bug bounty platforms come with a heavy price tag and require handing sensitive vulnerability reports to a third party, while building a platform in house takes time and effort that most security teams do not have to spare. Gerobug exists to close that gap, positioning itself as the first open source self-managed bug bounty platform, aimed squarely at organizations that want their own program on a minimum budget.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal\">The premise is refreshingly direct. The project describes itself in three words: easy, since a program can be running from a single command line; secure, through an email parser and network segregation that minimize risk; and open source, which is to say free. Deployment is a matter of cloning the repository and running a setup script, with the dashboard listening on port 6320 by default. Nothing needs to be installed by hand, which lowers the barrier for a small team that wants to start receiving reports rather than start a build project.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal\">Under the surface there is more engineering than the simplicity suggests. All services run in separate containers, so the only thing the public can reach is the static page carrying the program&#8217;s rules and guidelines. HTTPS is configured automatically through NGINX and Let&#8217;s Encrypt. Researchers submit findings by email, which the platform parses, filters, and surfaces on the dashboard, replying automatically and notifying hunters when their report status changes. On the company side, new reports trigger notifications through Slack or Telegram, and the reports themselves are managed on a kanban dashboard with role based user management behind it.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal\">The details reveal a team that has clearly run a program themselves. Incoming reports are filtered and flagged when duplication is suspected, a CVSS and OWASP risk calculator is built into the review process, and emails engaged in spam activity can be temporarily blacklisted and later released. Certificates of appreciation for bug hunters are generated automatically, internal audit logging with rotation is enabled by default, and a hall of fame leaderboard rounds out the package. These are the unglamorous pieces that decide whether a bug bounty program survives its first busy month.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal\">The project&#8217;s credibility is not merely self declared. Gerobug has been presented at Black Hat Asia Arsenal in both 2023 and 2024, and continues to be actively developed, with version 3 released in June 2026 across sixteen releases and more than six hundred commits. It is licensed under the GNU AGPLv3 and built primarily in Python with a Django style web and dashboard structure.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal\">For students, Gerobug is worth attention for reasons beyond the tool itself. It is a working example of Indonesian security practitioners identifying a real gap in the ecosystem and answering it with production grade open source rather than a whitepaper. It also sits at the exact intersection this program teaches, combining vulnerability disclosure, secure deployment through containers and network segregation, risk scoring, and report writing into a single system. A student who deploys it, reads its code, and submits a pull request will learn more about how vulnerability disclosure actually works than any lecture can convey. It is open to contribution, which is the whole point.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal\"><strong>Explore Gerobug<\/strong><\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal\">Repository: <a class=\"underline underline underline-offset-2 decoration-1 decoration-current\/40 hover:decoration-current focus:decoration-current\" href=\"https:\/\/github.com\/gerosecurity\/gerobug\">github.com\/gerosecurity\/gerobug<\/a><br \/>\nDocumentation: <a class=\"underline underline underline-offset-2 decoration-1 decoration-current\/40 hover:decoration-current focus:decoration-current\" href=\"https:\/\/gerobug.gitbook.io\/documentation\/\">gerobug.gitbook.io\/documentation<\/a><br \/>\nOfficial site: <a class=\"underline underline underline-offset-2 decoration-1 decoration-current\/40 hover:decoration-current focus:decoration-current\" href=\"https:\/\/gerobug.gerosecurity.com\">gerobug.gerosecurity.com<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Bug Bounty Platform Indonesia Built and Gave Away Most organizations know they should invite security researchers to find their flaws. Far fewer actually do it. Commercial bug bounty platforms come with a heavy price tag and require handing sensitive vulnerability reports to a third party, while building a platform in house takes time and [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":73094,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4,34],"tags":[],"class_list":["post-396","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-portofolio","category-presence-2024"],"_links":{"self":[{"href":"https:\/\/socs.binus.ac.id\/cyber-security\/wp-json\/wp\/v2\/posts\/396","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/socs.binus.ac.id\/cyber-security\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/socs.binus.ac.id\/cyber-security\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/socs.binus.ac.id\/cyber-security\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/socs.binus.ac.id\/cyber-security\/wp-json\/wp\/v2\/comments?post=396"}],"version-history":[{"count":2,"href":"https:\/\/socs.binus.ac.id\/cyber-security\/wp-json\/wp\/v2\/posts\/396\/revisions"}],"predecessor-version":[{"id":73096,"href":"https:\/\/socs.binus.ac.id\/cyber-security\/wp-json\/wp\/v2\/posts\/396\/revisions\/73096"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/socs.binus.ac.id\/cyber-security\/wp-json\/wp\/v2\/media\/73094"}],"wp:attachment":[{"href":"https:\/\/socs.binus.ac.id\/cyber-security\/wp-json\/wp\/v2\/media?parent=396"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/socs.binus.ac.id\/cyber-security\/wp-json\/wp\/v2\/categories?post=396"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/socs.binus.ac.id\/cyber-security\/wp-json\/wp\/v2\/tags?post=396"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}