• हिन्दी
  • ગુજરાતી
  • বাংলা
  • తెలుగు
  • मराठी
  • ಕನ್ನಡ
  • money9
  • Insurance
  • Saving
  • Mutual Funds
  • Mirae Asset MF
  • Breaking Briefs
downloadDownload The App
Close
  • Home
  • Videos
  • Podcast
  • Banking
  • Bulletin
  • Gold
  • Healthcare
  • Real Estate
  • Tax
  • Travel
  • Survey 2023
  • Survey Report
  • Breaking Briefs
  • Insurance
  • Savings
  • Loan
  • Crypto
  • Investment
  • Mutual Funds
  • Real Estate
  • Tax
  • Exclusive
  • Home / Exclusive

IRCTC fixes bug on website after school student raises alarm

The class 12 student discovered the bug that leaked the transaction details of millions of travelers, when he was trying to book tickets on August 30

  • Money9
  • Last Updated : September 21, 2021, 19:09 IST
  • Follow
Renganathan who is also a cyber security researcher, said that the user who booked the ticket and the ticket should be validated so that no one else can access it except the booked user, as a mitigation.
  • Follow

Indian Railway Catering and Tourism Corporation Ltd (IRCTC) on Tuesday said that it has fixing a bug on its e-ticketing platform after a Chennai-based class 12 student raised an alarm over the presence of Insecure Direct Object References (IDOR) – a type of access control vulnerability. The vulnerability arises when an application uses user-supplied input to access objects directly.

IRCTC’s IT wing fixed the bug immediately once the complaint was reported, a senior official said. The issue was reported on August 30 and was fixed on September 2, he said, adding that now, the e-ticketing system is well protected.

IDOR, one of the most common bugs

P Renganathan, a plus two student of a private school in Tambaram, identifies himself as an ethical hacker said that he discovered a critical IDOR by accident, that leaked the transaction details of millions of travelers, when he was trying to book tickets on August 30. Then, he had reported the same to the Indian Computer Emergency Response Team (CERT-In). It was the most common bug, he adds.

He explained that he discovered the critical IDOR by going to the account ticket history, and clicking on any ticket with burp suite turned on, which leaked the transaction details of millions of travelers. Then, by changing the transaction ID to get access to another’s tickets, all the sensitive details will be available to you. “This can lead to cancellation of someone’s ticket or do anything malicious”, he said in an email complaint to CERT-In, under the Union Ministry of Electronics and Information Technology.

Renganathan who is also a cyber security researcher, said that the user who booked the ticket and the ticket should be validated so that no one else can access it except the booked user, as a mitigation.

In an email on September 11, 2021 he was thanked for reporting the incident to CERT-In, with the confirmation that the issue has been resolved, by the authorities.

Ranganathan has been acknowledged by Linkedin, BYJU’s, Lenovo, United Nations, Nike for reporting security vulnerabilities in their web applications.

Published: September 21, 2021, 19:09 IST

Download Money9 App for the latest updates on Personal Finance.

  • CERT-In
  • Chennai boy reports bug in IRCTC
  • IDOR

Related

  • Indigo की 200 से ज्यादा फ्लाइट रद्द, हजारों पैसेंजर फंसे
  • भारत-रूस समिट में बड़े फैसलों की तैयारी, इकोनॉमिक पार्टनरशिप पर बड़ा फोकस
  • भारत और यूरोपीय संघ के बीच पैसे भेजना होगा आसान,RBI ने शुरू की UPI TIPS; जानें कैसे करेगा काम
  • श्रम संहिता लागू होने से निर्यातकों को मिलेगा प्रोत्साहन: अधिकारी
  • मारुति सुजुकी ने प्रौद्योगिकी स्टार्टअप में करीब आठ प्रतिशत हिस्सेदारी हासिल की
  • टोयोटा ने डैशबोर्ड के हिस्से को बदलने के लिए 11.5 हजार अर्बन क्रूजर हाइडर वापस मंगाईं

Latest

  • 1. Know the correct way to get KYC done!
  • 2. Why health insurance claim gets rejected?
  • 3. Power to Respond!
  • 4. What is Asset Under Management?
  • 5. No Worries on Medical Expenses!
  • Trending Stories

  • मीशो के 5,421 करोड़ रुपये के आईपीओ को दूसरे दिन मिला 7.97 गुना अभिदान
  • इंडिगो को अगले साल 10 फरवरी तक उड़ान संचालन पूरी तरह बहाल होने की उम्मीद
  • Indigo की 200 से ज्यादा फ्लाइट रद्द, हजारों पैसेंजर फंसे
  • इंडिगो की 180 से अधिक उड़ानें रद्द
  • भारत-रूस समिट में बड़े फैसलों की तैयारी, इकोनॉमिक पार्टनरशिप पर बड़ा फोकस
  • TV9 Sites

  • TV9 Hindi
  • TV9Telugu.com
  • TV9 Marathi
  • TV9 Gujarati
  • TV9 Kannada
  • TV9 Bangla
  • TV9 English
  • News9 Live
  • Trends9
  • Tv9tamilnews
  • Assamtv9
  • Malayalamtv9
  • Money9 Sites

  • Money9 Hindi
  • Money9 English
  • Money9 Marathi
  • Money9 Telugu
  • Money9 Gujarati
  • Money9 Kannada
  • Money9 Bangla
  • Money9live
  • Topics

  • Insurance
  • Savings
  • Loan
  • Stocks
  • Mutual Funds
  • Real Estate
  • Tax
  • Crypto
  • Exclusive
  • Follow us

  • FaceBook
  • Twitter
  • Youtube
  • Instagram
  • Linkedin
  • Download App

  • play_store
  • App_store
  • Contact Us
  • About Us
  • Advertise With Us
  • Privacy & Cookies Notice
  • Complaint Redressal
  • Copyright © 2025 Money9. All rights reserved.
  • share
  • Facebook
  • Twitter
  • Whatsapp
  • LinkedIn
  • Telegram
close