HT TECH wants to start sending you push notifications. Click allow to subscribe

IRCTC bug: Student detects HUGE flaw, saves data of millions of users

IRCTC bug: A student in Chennai has discovered a dangerous flaw in IRCTC website while booking train tickets. He saved data of millions of users from being leaked by hackers.

By: HT TECH
Updated on: Aug 21 2022, 20:32 IST
IRCTC bug: The IRCTC bug was revealed by a student and it has helped resolve a security vulnerability in the IRCTC online ticketing platform that is used by millions of Indians. The IRCTC website was fixed thereafter. (Pixabay)

In what will bring welcome relief to officials, a teenager detected a dangerous flaw on IRCTC website. The youngster detected the IRCTC bug while using the IRCTC system to book a train ticket. Thankfully, the teenager acted as a good Samaritan and alerted the authorities. The IRCTC flaw was reportedly fixed within five days of him reaching out to highlight the issue.

The presence of this IRCTC bug was revealed by a 17-year-old student in Chennai and it has helped resolve a security vulnerability in the Indian Railway Catering and Tourism Corporation (IRCTC) online ticketing platform that is used by millions of Indians. The early detection by the enthusiast reportedly resulted in the flaw being patched before it could be misused by malicious actors that could have exposed personal data of most IRCTC users.

You may be interested in

Mobiles Tablets Laptops
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
28% OFF
Samsung Galaxy S23 Ultra 5G
  • Green
  • 12 GB RAM
  • 256 GB Storage
₹107,999₹149,999
Buy now
Google Pixel 8 Pro
  • Obsidian
  • 12 GB RAM
  • 128 GB Storage
₹106,998
Check details
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹87,900
Check details
21% OFF
Acer Swift Go SFG14 41 NX KG3SI 002 Laptop
  • Pure Silver
  • 8 GB RAM
  • 512 GB SSD
₹58,999₹74,999
Buy now
41% OFF
Acer Aspire 5 A515 57G Laptop
  • Gray
  • 16 GB RAM
  • 512 GB SSD
₹52,990₹89,999
Buy now
22% OFF
Acer Aspire 3 A315 24 NX KDESI 004 Laptop
  • Silver
  • 8 GB RAM
  • 512 GB SSD
₹33,499₹42,999
Buy now
40% OFF
Asus VivoBook 15 X515JA BQ322WS Laptop
  • Transparent Silver
  • 8 GB RAM
  • 512 GB SSD
₹31,350₹51,990
Buy now
35% OFF
Xiaomi Pad 6
  • Mist Blue
  • 6 GB RAM
  • 128 GB Storage
₹25,999₹39,999
Buy now
55% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹20,999₹47,000
Buy now
32% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹19,718₹28,999
Buy now
Honor Pad X9
  • Gray
  • 4 GB RAM
  • 128 GB Storage
₹14,999
Check details

Also read: Looking for a smartphone? Check Mobile Finder here.

The IRCTC bug was spotted by P Renganathan, who is currently studying in standard 12 at Tambaram, as reported by The Hindu. Renganathan was using the IRCTC portal some time ago to book a ticket when he found certain security vulnerabilities that could have led to personal information of this website's users being leaked online.

According to the report, Renganathan found the most critical Insecure Object Direct References (IDOR) vulnerability, which he was able to use to access personal information such as a passenger’s age, their name, PNR details and departing times along with date and time of the journey. Interestingly, Renganathan’s disclosure to the Computer Emergency Response team (CERT-In) was on August 30, and a ticket was raised within minutes, while the IRCTC resolved the issue within five days, the report said.

“Since the back-end code is the same, a hacker would have been able to order food, change the boarding station and even cancel the ticket without the knowledge of the bona fide passenger,” Renganathan explained to The Hindu. He also added that domestic tourism and international travel, along with bus and hotel booking could be found in a user’s profile, which could mean millions of passengers could have lost their data in a breach.

The report states that Renganathan has also received acknowledgement for helping resolve security flaws with products from Nike, Lenovo LinkedIn and the United Nations.

Catch all the Latest Tech News, Mobile News, Laptop News, Gaming news, Wearables News , How To News, also keep up with us on ,Twitter, Facebook, , and Instagram. For our latest videos, subscribe to our YouTube channel.

First Published Date: 21 Sep, 16:45 IST
Tags:

Sale

Mobiles Tablets Laptops
4% OFF
Samsung Galaxy S24 Ultra
  • Titanium Black
  • 12 GB RAM
  • 256 GB Storage
₹129,999₹134,999
Buy now
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
13% OFF
Xiaomi 14
  • Matte Black
  • 12 GB RAM
  • 512 GB Storage
₹69,999₹79,999
Buy now
11% OFF
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹79,800₹89,900
Buy now
57% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹19,999₹47,000
Buy now
28% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹17,999₹24,999
Buy now
27% OFF
Samsung Galaxy Tab S8
  • Silver
  • 8 GB RAM
  • 128 GB Storage
₹59,999₹81,999
Buy now
20% OFF
Samsung Galaxy Tab S9 5G 256GB
  • Graphite
  • 8 GB RAM
  • 256 GB Storage
₹86,999₹108,699
Buy now
23% OFF
Infinix INBook X1 Neo XL22 Laptop Intel Celeron Quad Core 8 GB 256 GB SSD Windows 11
  • Blue
  • 4 GB RAM
  • 128 GB SSD
₹22,990₹29,990
Buy now
40% OFF
Samsung Galaxy Book Go Laptop
  • Silver
  • 4 GB RAM
  • 128 GB SSD
₹28,690₹47,990
Buy now
22% OFF
Asus ROG Strix G15 G513RC HN085WS Laptop
  • Electro Punk
  • 16 GB RAM
  • 1 TB SSD
₹70,990₹90,990
Buy now
30% OFF
Asus ROG Strix G15 G513QY HQ032WS Laptop
  • Original Black
  • 16 GB RAM
  • 1 TB SSD
₹79,990₹113,990
Buy now
NEXT ARTICLE BEGINS