financetom
Technology
financetom
/
Technology
/
India's road accident database website source code, user data exposed on dark web
News World Market Environment Technology Personal Finance Politics Retail Business Economy Cryptocurrency Forex Stocks Market Commodities
India's road accident database website source code, user data exposed on dark web
Aug 13, 2023 7:43 AM

Cybersecurity firm CloudSEK's XVigil AI digital-risk platform reported that the Parivahan website for the integrated road accident database of the ministry of road transport and highways suffered a data breach.

According to CloudSEK, the breach exposed the source code of the Integrated Road Accident Database (iRAD) website, leading to the leak of its source code and user data on the Dark Web.

"CloudSEK has notified the MoRTH about the breach. The firm urges immediate action to secure the iRAD website and safeguard sensitive user data," the company said.

"We discovered sensitive assets embedded within the code, including hostnames, database names, and passwords. The usernames and passwords found in the source code were quite simple and susceptible to brute-force attacks when there's local access to the server," the cybersecurity company stated.

The source code references sms.gov.in, a NIC SMS Gateway used by government departments to send SMS to Indian nationals. The embedded URL in the source code includes fields for usernames and passwords, which if exploited, might give unauthorised individuals the ability to send messages to recipients, CloudSEK noted.

The same threat actor, after exposing the source code, shared a sample dataset of 10,000 user records from a vulnerable API endpoint of the iRAD website on August 7. This data breach was achieved through an SQL injection, underscoring significant vulnerabilities. The leaked dataset contains sensitive information such as user IDs, names, emails, mobile numbers, and passwords.

Upon verification, some mobile numbers and names from the sample dataset were matched via Truecaller. The dataset also included email IDs and clear text passwords of government officials, according to CloudSEK.

(Edited by : Pradeep John)

Comments
Welcome to financetom comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Related Articles >
AIOZ Network Partners With Alibaba Cloud to Boost AI, Storage and Streaming Services
AIOZ Network Partners With Alibaba Cloud to Boost AI, Storage and Streaming Services
Mar 22, 2024
The two companies will establish a DePIN alliance in south-east Asia.AIOZ's native token is currently trading flat after the announcement, it is up by more than 200% in 30 days.AIOZ Network will use Alibaba Cloud to improve Web 3, AI, storage and streaming services.Decentralized infrastructure network (DePIN) AIOZ Network has become the leading blockchain partner in Alibaba Cloud’s Innovation Accelerator...
Japan braces for life with interest rates after historic change
Japan braces for life with interest rates after historic change
Mar 21, 2024
TOKYO, March 22 (Reuters) - In the coming years, Satoaki Kanoh needs to replace almost a dozen ageing machines at his Tokyo-based maker of acrylic panels, a major undertaking that he worries will become even more expensive. Ideally, I'd like to do one a year. But I don't have that much money, Kanoh said of the customised pieces of machinery...
Analysis-Apple antitrust suit mirrors strategy that beat Microsoft, but tech industry has changed
Analysis-Apple antitrust suit mirrors strategy that beat Microsoft, but tech industry has changed
Mar 22, 2024
(Reuters) - The U.S. government's antitrust lawsuit against Apple ( AAPL ) draws on the watershed 1998 case that broke Microsoft's ( MSFT ) stranglehold on desktop software, but that may prove to be an imperfect blueprint for addressing smartphone competition. The market for the iPhone today looks very different from the near-monopoly enjoyed by Microsoft's ( MSFT ) Windows...
Japan braces for life with interest rates after historic change
Japan braces for life with interest rates after historic change
Mar 21, 2024
TOKYO (Reuters) - In the coming years, Satoaki Kanoh needs to replace almost a dozen ageing machines at his Tokyo-based maker of acrylic panels, a major undertaking that he worries will become even more expensive. Ideally, I'd like to do one a year. But I don't have that much money, Kanoh said of the customised pieces of machinery that cost...
Copyright 2023-2026 - www.financetom.com All Rights Reserved