The Apogee
The Apogee
  • Home
  • From Courts
  • Global
  • Technology
  • Business
  • Law
  • Judgements
    • High Court
    • Supreme Court
  • Achievers
  • Video
  • More
    • Interviews
    • Opinion/Features
    • Research
    • Science
    • Environs
    • Health
  • test-series
  1. Home
  2. Technology
  3. Chennai school student helps IRCTC fix bug on its online platform
 Chennai school student helps IRCTC fix bug on its online platform
Renganathan,the Chennai school boy who helped IRCTC fix a bug on its online platform.
Technology

Chennai school student helps IRCTC fix bug on its online platform

by Newsdesk September 22, 2021

AA

Chennai, Sep 22 (IANS) A 17-year-old plus two student in a private school in Chennai’s Tambaram has helped the Indian Railway Catering and Tourism Corporation (IRCTC) fix a bug in its online ticketing platform, which could have exposed millions of passengers and their private information.

Ranganathan said that the critical Insecure Object Direct References (IODR) vulnerability on the website helped him to access the journey details of other passengers.

He told media persons that while he was logging into the IRCTC site for booking a ticket, he found that he could access the details of other passengers that could compromise the security features of the website.

The vulnerability helped him to access details of other passengers including name, gender, age, PNR number, train details, departure station, and date of journey.

Ranganathan said that as the back end code was the same, a hacker could have ordered food in the name of another passenger, changed the boarding station, and even cancelled the ticket without the knowledge of the passenger.

He said that more than this, there was the risk of the database of millions of passengers being compromised or leaked.

IRCTC officials said that Ranganathan had reported the matter to the Computer Emergency Response Team (CERT) on August 30, and the IRCTC was alerted. The problem was fixed in five days.

The teenager had earlier got acknowledgments from Linkedin, the United Nations, Nike, and several others for alerting them of the vulnerabilities in their websites.

Previous post
Next post

Latest Post

From Courts

Nagpur Bench of Bombay High Court quashes false rape and dowry case against would be husband

May 13, 2024
From Courts

SC asks Patanjali to place on record IMA chief’s interview terming apex court observations as ‘unfortunate’

April 30, 2024
From Courts

Delhi HC restrains Ashneer Grover from creating third party rights in BharatPe shares

April 30, 2024
Global

AstraZeneca admits Covishield jab raises TTS risk. Should you be worried?

April 30, 2024
Copyright © 2026 Qoxag. All Right Reserved.
Go to mobile version