Monday, May 29, 2023
  • Home
  • Politics
  • News
  • Business
  • Culture
  • National
  • Sports
  • Lifestyle
  • Travel
  • Opinion
No Result
View All Result
News 100
No Result
View All Result
Home India

India’s largest e-ticketing platform fixes bug after school student raises alarm

news100 by news100
September 21, 2021
in India
0 0
0
“Our e-ticketing system is well protected (now). The issue was reported on August 30 and it was fixed on September 2, he added
0
SHARES
27
VIEWS


Chennai: The Indian Railway Catering and Tourism Corporation Ltd. (IRCTC) fixed a bug on its e-ticketing platform after a plus two lad from the city raised an alarm over the presence of Insecure direct object references (IDOR) – a type of access control vulnerability in the booking site.

The IT wing of the IRCTC which took note of the complaint, immediately resolved the vulnerability issue that has been reported, a senior official said on Tuesday.

Related posts

Subramanian Swamy withdraws from Supreme Court his 2013 plea against Jet-Etihad Airways deal

Subramanian Swamy withdraws from Supreme Court his 2013 plea against Jet-Etihad Airways deal

January 6, 2023
Jharkhand: India bans tourism at holy Jain site after protests

Jharkhand: India bans tourism at holy Jain site after protests

January 6, 2023

 

“Our e-ticketing system is well protected (now). The issue was reported on August 30 and it was fixed on September 2,” he added.

The IDOR, a type of access control vulnerability, arises when an application uses user-supplied input to access objects directly.

“I accidently discovered a critical IDOR that leaks the transaction details of millions of travelers, when I was trying to book tickets on August 30. It was the most common bug. Immediately, I reported about it to the Indian Computer Emergency Response Team (CERT-In),” P Renganathan, a plus two student of a private school in Tambaram here, said.

 

“I’ve discovered a critical IDOR that leaks the transaction details of millions of travelers. Go to your account ticket history, click on any ticket with burp suite turned on. Now change the transaction ID to gain access to another’s tickets, you will get all the sensitive details. You can also cancel someone’s ticket or do anything malicious,” he said in an email complaint to CERT-In, under the Union Ministry of Electronics and Information Technology.

As a mitigation, Renganathan who identifies himself as ethical hacker and cyber security researcher, said that the booked user and ticket should be validated so that no one else can access it except the booked user.

 

On September 11, 2021, he received a mail thanking him for reporting the incident to CERT-In and also a confirmation that the “reported vulnerability has been resolved” by the authorities concerned.

Renganathan, currently pursuing commerce group, has been acknowledged by LinkedIn, United Nations, BYJU’s, Nike, Lenovo, Upstox for reporting security vulnerabilities in their web applications.

Schools across Tamil Nadu re-opened only for classes ninth to twelfth on September 1. “I have opted for online classes owing to the pandemic,” he said.

 

…



Source link

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

News 100

We bring you the best Premium WordPress Themes that perfect for news, magazine, personal blog, etc.

Follow us on social media:

Recent News

  • Most Wanted – Report Immediately
  • Commuters suffer fourth day of chaos as RMT launches new 48-hour strike -LIVE
  • North Korean students are expelled and forced to work in a coal mine

Category

  • Africa
  • Australia
  • Business
  • China
  • Culture
  • Europe
  • History
  • History & Art
  • India
  • Lifestyle
  • Middle East
  • National
  • News
  • Opinion
  • Politcs
  • Science
  • Shorts
  • Sports
  • Travel
  • UK
  • Uncategorized
  • United States
  • World

Recent News

Most Wanted  – Report Immediately

Most Wanted – Report Immediately

February 23, 2023
Commuters suffer fourth day of chaos as RMT launches new 48-hour strike -LIVE

Commuters suffer fourth day of chaos as RMT launches new 48-hour strike -LIVE

January 6, 2023
  • Home 2
  • Science
  • UK
  • Australia
  • Sports
  • World
  • United States
  • India
  • History & Art
  • Uncategorized
  • Europe

© 2023 JNews - Premium WordPress news & magazine theme by Jegtheme.

No Result
View All Result
  • Home
  • Politics
  • News
  • Business
  • Culture
  • National
  • Sports
  • Lifestyle
  • Travel
  • Opinion

© 2023 JNews - Premium WordPress news & magazine theme by Jegtheme.

Welcome Back!

OR

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Slot88

Slot Gacor

Situs Slot Gacor

Slot Gacor

Slot Online

Daftar Slot88

Slot88

Slot Gacor

Slot Gacor

Slot88 Online

Slot Gacor Pragmatic

Slot Online Terbaik dan Terpercaya

Slot Gacor

Slot Online Terbaik dan Terpercaya