ADVERTISEMENT
site_logo
  • Campus
  • Happening
  • Opinion
  • People
  • News
  • #BeInspired
  • Careers
  • 40 under 40
  • Exams
  • What The FAQ
  • Videos
    • Straight Up
    • Odisha Literary Festival 2020
    • Campus Convo
    • Careers After Corona
    • Express Expressions
    • Q&A With Prabhu Chawla
    • ThinkEdu Awards 2020
  • Web Stories
  • edex_worksEDEXWORKS
ADVERTISEMENT
IRCTC

Published: 22nd September 2021     

India's largest e-ticketing platform fixes bug after school student raises alarm

The IT wing of the IRCTC which took note of the complaint, immediately resolved the vulnerability issue that had been reported

Edex Live
Edex Live
f_icon t_icon i_icon l_icon koo_icon whatsapp_icon email_icon Google News

Share Via Email

04_04_2020-train_20164040

Image for representation (Pic: PTI)

The Indian Railway Catering and Tourism Corporation Ltd. (IRCTC) fixed a bug on its e-ticketing platform after a plus two lad from Chennai raised an alarm over the presence of Insecure direct object references (IDOR) - a type of access control vulnerability in the booking site.

The IT wing of the IRCTC which took note of the complaint, immediately resolved the vulnerability issue that has been reported, a senior official said on Tuesday. “Our e-ticketing system is well protected (now). The issue was reported on August 30 and it was fixed on September 2,” he added.

The IDOR, a type of access control vulnerability, arises when an application uses user-supplied input to access objects directly.

“I accidently discovered a critical IDOR that leaks the transaction details of millions of travelers, when I was trying to book tickets on August 30. It was the most common bug. Immediately, I reported about it to the Indian Computer Emergency Response Team (CERT-In),” P Renganathan, a plus two student of a private school in Tambaram here, said.

“I've discovered a critical IDOR that leaks the transaction details of millions of travelers. Go to your account ticket history, click on any ticket with burp suite turned on. Now change the transaction ID to gain access to another's tickets, you will get all the sensitive details. You can also cancel someone's ticket or do anything malicious,” he said in an email complaint to CERT-In, under the Union Ministry of Electronics and Information Technology.

As a mitigation, Renganathan who identifies himself as ethical hacker and cyber security researcher, said that the booked user and ticket should be validated so that no one else can access it except the booked user.

On September 11, 2021, he received a mail thanking him for reporting the incident to CERT-In and also a confirmation that the “reported vulnerability has been resolved” by the authorities concerned.

Renganathan, currently pursuing commerce group, has been acknowledged by LinkedIn, United Nations, BYJU's, Nike, Lenovo, Upstox for reporting security vulnerabilities in their web applications.

telegram
TAGS
IRCTC Online bug Ethical hacking

O
P
E
N

ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT
telegram
ADVERTISEMENT
Write to us!

If you have campus news, views, works of art, photos or just want to reach out to us, just drop us a line.

newsletter_icon
Mailbox
edexlive@gmail.com
fb_icon
Facebook
twitter_icon
Twitter
insta_icon
Instagram
ADVERTISEMENT
Facebook
ADVERTISEMENT
Tweets by Xpress_edex
ADVERTISEMENT
ADVERTISEMENT

FOLLOW US

The New Indian Express | The Morning Standard | Dinamani | Kannada Prabha | Samakalika Malayalam | Cinema Express | Indulgexpress | Events Xpress

Contact Us | About Us | Privacy Policy | Terms of Use | Advertise With Us

Home | Live Now | Live Story | Campus Trip | Coach Calling | Live Take

Copyright - edexlive.com 2023. All rights reserved. Website Designed, Developed & Maintained by Express Network Private Ltd.