Rashtra NewsRashtra News
  • National
  • Business
  • Education
  • Entertainment
  • Finance
  • Insurance
  • Jobs
  • Sports
  • Stock Market
  • Technology
Notification Show More
Font ResizerAa
Rashtra NewsRashtra News
Font ResizerAa
  • National
  • Rashtra News Hindi
Search
  • National
  • Business
  • Education
  • Entertainment
  • Finance
  • Insurance
  • Jobs
  • Sports
  • Stock Market
  • Technology
Follow US
Rashtra News > Latest News > Technology > Techie prevents train tickets booked on IRCTC from getting ‘hacked’ – Rashtra News : Tech News
Technology

Techie prevents train tickets booked on IRCTC from getting ‘hacked’ – Rashtra News : Tech News

RN News Room
Last updated: September 16, 2021 6:45 am
RN News Room
Share
4 Min Read
Techie prevents train tickets booked on IRCTC from getting ‘hacked’ – Rashtra News : Tech News
SHARE

Techie prevents train tickets booked on IRCTC from getting ‘hacked’ – Rashtra News

NEW DELHI: In a recent exposé, an independent security researcher named Renganathan P recently alerted the Indian Computer Emergency Response Team (CERT-In) about a major vulnerability on the IRCTC platform that allowed easy access to private information of lakhs of passengers. Not just that, exploiting the IDOR (Insecure Direct Object Reference) vulnerability on IRCTC could have even allowed the attacker to cancel booked train tickets of random passengers.
The IDOR vulnerability on IRCTC also allowed anyone to change the boarding point (of the train), order food, book a hotel, tourist package, and even book a bus, as per Renganathan.
Renganathan, who claims to have helped LinkedIn, United Nations, BYJU’s, Nike, Lenovo, Upstox in fixing security vulnerabilities in their web applications, reported the issue to CERT-In on August 30, 2021, by emailing on “incident@cert-in.org.in”. The IDOR vulnerability was fixed on September 4 and IRCTC acknowledged the same on September 11.
It is not possible to determine for how long this vulnerability was present on the IRCTC platform. Also, there’s little official information on whether or not this vulnerability was exploited or not. We don’t know right now whether or not any user was directly affected due to the said tech issue.
Considering that IRCTC being one of the largest ticket booking platforms in India with the majority of citizens relying on it to travel on trains, the implications could have been massive.
Explaining how the vulnerability was found, Renganathan said, “While I was booking a ticket as a normal human I suddenly got an idea to test for vulnerabilities.” In his mail to CERT-In (a copy of which is present with The Rashtra News–GadgetsNow), he wrote, “Go to your account ticket history, click on any ticket with burp suite turned on. Now change the transaction ID to gain access to another’s tickets, you will get all the sensitive details. You can also cancel someone’s ticket or do anything malicious.”
“I tried for IDOR and decreased the number of the transaction ID and forwarded the packet. And Yeah! I got a random user’s transaction and ticket details like Train Number, Departure time, Duration of the journey, PNR number, Status of the ticket, Boarding station, Passenger’s information like their names, seat details, gender & age,” he added.

( News Source :Except for the headline, this story has not been edited by Rashtra News staff and is published from a timesofindia.indiatimes.com feed.)

Related searches :

  • tech news hindi
  • tech news usa
  • tech news app
  • tech news tamil
  • tech news sites india
  • short tech news
  • techcrunch tech news sites
  • live tech news
  • technology news india
  • tech news today hindi
  • tech news sites india
  • tech news india hindi
  • tech news top
  • computer technology news
  • technology articles
  • information technology news today
  • technology news today
  • information technology news india
  • technology news in hindi

Related

TAGGED: booked, CERT-In, cybersecurity, hacked, Indian Computer Emergency Response Team, indian railways, Insecure Direct Object Reference, irctc, irctc hack, irctc idor vulnerability, News, prevents, Rashtra, renganathan, renganathan p, Tech, Techie, tickets, train
Share This Article
Facebook Twitter Copy Link Print
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Surprise0
Joy0
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

You Might Also Like

ChatGPT Ghibli Art Generator: Create Studio Ghibli-Style Art with AI [2025]
SoftwareTechnology

ChatGPT Ghibli Art Generator: Create Studio Ghibli-Style Art with AI [2025]

2 months ago
Hexaware and Novelty Group Forge Transformative Joint Venture
Press Release

Hexaware and Novelty Group Forge Transformative Joint Venture

1 year ago
The Limitations of AMD’s Open-Source Linux Graphics Driver for HDMI 2.1 Functionality
Technology

The Limitations of AMD’s Open-Source Linux Graphics Driver for HDMI 2.1 Functionality

1 year ago
Tech Mahindra Foundation and GIZ Join Hands to Build a Skilling Ecosystem for the Allied Healthcare Sector Through Technological Interventions
Press Release

Tech Mahindra Foundation and GIZ Join Hands to Build a Skilling Ecosystem for the Allied Healthcare Sector Through Technological Interventions

1 year ago

About RashtraNews.com

We're your comprehensive news source, covering a wide range of topics to empower you in all aspects of life. From navigating the world of finance (market trends, personal tips, loans, mortgages, credit) and legal matters (attorneys, lawyers), to staying ahead of the curve in technology (advancements, automobiles, business news) and education (careers, job opportunities, classes), RashtraNews.com keeps you informed.

Latest Updates

  • A Comprehensive Guide to Transportation, Logistics, and Relocation Services Across Cities
  • Global Markets in Turmoil Amid Rising Inflation and Escalating Trade Tensions
  • California Ballot Initiative Seeks to Prevent Unjust Health Insurance Denials
  • Millions of Travelers Risk Losing Insurance Coverage Over Simple Mistakes
  • Severe Thunderstorm Warnings Sweep Across USA: Tornado Threat Looms Over Oklahoma
  • ChatGPT Ghibli Art Generator: Create Studio Ghibli-Style Art with AI [2025]
  • Nida Rides India to Global Glory, 22-year to Become First Indian Lady to Compete at FEI Endurance World Championship for Seniors, Monpazier, France

Helpful Link

  • Automobile77
  • Business4,343
  • Crime129
  • Education4,542
  • Entertainment58
  • Finance5
  • India9,623
  • Insurance3
  • Legal News5
  • Lifestyle21
  • Media News79
  • Medical Education1
  • Politics4,340
  • Press Release5,319
  • Software100
  • Sports3,095
  • Stock Market2
  • Technology3,180
  • Top Stories7
  • World2,907

Contact Us

To send your suggestions to "Rashtra News", email: editor@rashtranews.com

To send articles, news, or your opinions: editor@rashtranews.com
For Business and other enquiries: admin@rashtranews.com

If you‘ find any violation of the editorial code of conduct or have any other complaint about the content or video content published on "Rashtra News"’, you can send your complaint to our Grievance Officer by clicking on the Grievance Redressal link.

Follow US
©2011-2024 rashtranews.com
  • About Rashtra News
  • Ownership & funding
  • Corrections Policy
  • Fact Checking Policy
  • Privacy Policy
  • Terms of Use
  • Subscribe Now
  • Become a Author
  • Partnership With Us
Go to mobile version
adbanner
AdBlock Detected
Our site is an advertising supported site. Please whitelist to support our site.
Okay, I'll Whitelist
Welcome Back!

Sign in to your account

Lost your password?