financetom
Technology
financetom
/
Technology
/
IRCTC fixes bug after school student raises alarm
News World Market Environment Technology Personal Finance Politics Retail Business Economy Cryptocurrency Forex Stocks Market Commodities
IRCTC fixes bug after school student raises alarm
Sep 21, 2021 7:15 AM

The Indian Railway Catering and Tourism Corporation Ltd (IRCTC) fixed a bug on its e-ticketing platform after a plus two lad from the city raised an alarm over the presence of Insecure direct object references (IDOR) – a type of access control vulnerability in the booking site.

The IT wing of the IRCTC which took note of the complaint immediately resolved the vulnerability issue that has been reported, a senior official said on Tuesday. Our e-ticketing system is well-protected (now). The issue was reported on August 30 and it was fixed on September 2, he added.

The IDOR, a type of access control vulnerability, arises when an application uses user-supplied input to access objects directly. I accidentally discovered a critical IDOR that leaks the transaction details of millions of travellers, when I was trying to book tickets on August 30. It was the most common bug. Immediately, I reported about it to the Indian Computer Emergency Response Team (CERT-In), P Renganathan, a plus-two student of a private school in Tambaram here, said.

Also read:

Google clock bug is making people miss alarms: here's what is happening & what to do

I've discovered a critical IDOR that leaks the transaction details of millions of travellers. Go to your account ticket history, click on any ticket with burp suite turned on. Now change the transaction ID to gain access to another's tickets, you will get all the sensitive details. You can also cancel someone's ticket or do anything malicious, he said in an email complaint to CERT-In, under the union ministry of electronics and information iechnology.

As mitigation, Renganathan who identifies himself as an ethical hacker and cyber security researcher said the booked user and ticket should be validated so that no one else can access it except the booked user.

On September 11, 2021, he received a mail thanking him for reporting the incident to CERT-In and also a confirmation that the reported vulnerability has been resolved by the authorities concerned.

Also read: View: New Income Tax portal glitches - Every change is not progress

Renganathan, currently pursuing a commerce group, has been acknowledged by LinkedIn, United Nations, BYJU's, Nike, Lenovo, Upstox for reporting security vulnerabilities in their web applications. Schools across Tamil Nadu re-opened only for classes ninth to twelfth on September 1. I have opted for online classes owing to the pandemic, he said.

(Edited by : Jomy Jos Pullokaran)

Comments
Welcome to financetom comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Related Articles >
BTQ Technologies to Host Live Webinar on Quarterly Financial Results and General Corporate Update
BTQ Technologies to Host Live Webinar on Quarterly Financial Results and General Corporate Update
Nov 13, 2025
VANCOUVER, BC, Nov. 13, 2025 /PRNewswire/ - BTQ Technologies Corp. ( BTQ ) (BTQ or the Company) (FSE: NG3), a global quantum technology company focused on securing mission-critical networks, is pleased to announce that it will hold a shareholder call on Monday, November 17, 2025, at 12:00 p.m. EST to discuss its quarterly financial results and provide a general corporate update....
Nexxen Reports Third Quarter 2025 Financial Results
Nexxen Reports Third Quarter 2025 Financial Results
Nov 13, 2025
Generated record Q3 Contribution ex-TAC and programmatic revenue Renewed and expanded strategic ACR data and ad monetization partnership with VIDAA; announced additional $35 million investment Completed $50 million Ordinary Share repurchase program and launched a new $20 million program NEW YORK, Nov. 13, 2025 (GLOBE NEWSWIRE) -- Nexxen International Ltd. ( NEXN ) (“Nexxen” or the “Company”), a global, flexible advertising...
Breezeline Sets a New Benchmark for Connectivity Leadership: Launching Ultra-Fast 2.5 Gig Internet Service
Breezeline Sets a New Benchmark for Connectivity Leadership: Launching Ultra-Fast 2.5 Gig Internet Service
Nov 13, 2025
QUINCY, Mass., Nov. 13, 2025 /PRNewswire/ - Breezeline, a leading internet, TV, phone and wireless service provider, has launched its fastest-ever internet tier, delivering a groundbreaking upload and download speed of up to 2.5 Gigabits per second. This new speed tier provides faster internet performance, elevating the customer experience for all high-demand activities, from remote work and learning to seamless video...
Soluna Completes Project Dorothy 2, Increasing Operational Capacity by 64% to 123 MW
Soluna Completes Project Dorothy 2, Increasing Operational Capacity by 64% to 123 MW
Nov 13, 2025
The 98 MW site achieves over 3.9 EH/s of sustainable compute with 95% uptime and industry-leading efficiency ALBANY, N.Y.--(BUSINESS WIRE)-- Soluna Holdings, Inc. ( SLNH ) (“Soluna” or the “Company”) , a developer of green data centers for intensive computing applications, today announced the completion and full energization of Project Dorothy 2, the 48 MW second phase of its...
Copyright 2023-2026 - www.financetom.com All Rights Reserved