India's largest e-ticketing platform IRCTC fixes bug after school student raises alarm : The Tribune India

Join Whatsapp Channel

India's largest e-ticketing platform IRCTC fixes bug after school student raises alarm

Plus Two student says he accidently discovered a critical IDOR that leaks the transaction details of millions of travellers, when he was trying to book tickets on August 30

India's largest e-ticketing platform IRCTC fixes bug after school student raises alarm

Photo for representation. PTI



Chennai, September 21

The Indian Railway Catering and Tourism Corporation Ltd. (IRCTC) fixed a bug on its e-ticketing platform after a plus two student from the city raised an alarm over the presence of Insecure direct object references (IDOR) -- a type of access control vulnerability in the booking site.

The IT wing of the IRCTC which took note of the complaint, immediately resolved the vulnerability issue that has been reported, a senior official said on Tuesday.

“Our e-ticketing system is well protected (now). The issue was reported on August 30 and it was fixed on September 2,” he added.

The IDOR, a type of access control vulnerability, arises when an application uses user-supplied input to access objects directly.

“I accidently discovered a critical IDOR that leaks the transaction details of millions of travellers, when I was trying to book tickets on August 30. It was the most common bug. Immediately, I reported about it to the Indian Computer Emergency Response Team (CERT-In),” P Renganathan, a plus two student of a private school in Tambaram here, said.

“I've discovered a critical IDOR that leaks the transaction details of millions of travelers. Go to your account ticket history, click on any ticket with burp suite turned on. Now change the transaction ID to gain access to another's tickets, you will get all the sensitive details. You can also cancel someone's ticket or do anything malicious,” he said in an email complaint to CERT-In, under the Union Ministry of Electronics and Information Technology.

As a mitigation, Renganathan who identifies himself as ethical hacker and cyber security researcher, said the booked user and ticket should be validated so that no one else can access it except the booked user.

On September 11, 2021, he received a mail thanking him for reporting the incident to CERT-In and also a confirmation that the “reported vulnerability has been resolved” by the authorities concerned.

Renganathan, currently pursuing commerce group, has been acknowledged by LinkedIn, United Nations, BYJU's, Nike, Lenovo, Upstox for reporting security vulnerabilities in their web applications.

Schools across Tamil Nadu re-opened only for classes ninth to twelfth on September 1. “I have opted for online classes owing to the pandemic,” he said. PTI


Top News

Deeply biased: MEA on US report citing human rights violations in India

Deeply biased: MEA on US report citing human rights violations in India

The annual report of the State Department highlights instanc...

Family meets Amritpal Singh in Assam jail after his lawyer claims he'll contest Lok Sabha poll from Punjab’s Khadoor Sahib

Couldn't talk due to strictness of jail authorities: Amritpal's family after meeting him in jail

Their visit comes a day after Singh's legal counsel Rajdev S...

Delhi mayoral polls, slated for April 26, postponed due to non-appointment of presiding officer

Delhi mayoral polls, slated for April 26, postponed due to non-appointment of presiding officer

The civic body postponed the polls after the Raj Niwas issue...

Centre grants 'Y' category security cover to Phillaur MLA Vikramjit Chaudhary among 3 Punjab Congress rebels

Centre grants 'Y' category security to Phillaur MLA Vikramjit Chaudhary and 2 other Punjab Congress rebels

The Central Reserve Police Force has been directed by the Mi...


Cities

View All