India’s largest e-ticketing platform fixes bug after school student raises alarm


PTI, Sep 21, 2021, 3:50 PM IST

Chennai: The Indian Railway Catering and Tourism Corporation Ltd. (IRCTC) fixed a bug on its e-ticketing platform after a plus two lad from the city raised an alarm over the presence of Insecure direct object references (IDOR) – a type of access control vulnerability in the booking site.

The IT wing of the IRCTC which took note of the complaint, immediately resolved the vulnerability issue that has been reported, a senior official said on Tuesday.

“Our e-ticketing system is well protected (now). The issue was reported on August 30 and it was fixed on September 2,” he added.

The IDOR, a type of access control vulnerability, arises when an application uses user-supplied input to access objects directly. “I accidently discovered a critical IDOR that leaks the transaction details of millions of travelers, when I was trying to book tickets on August 30. It was the most common bug. Immediately, I reported about it to the Indian Computer Emergency Response Team (CERT-In),” P Renganathan, a plus-two student of a private school in Tambaram here, said.

“I’ve discovered a critical IDOR that leaks the transaction details of millions of travelers. Go to your account ticket history, click on any ticket with burp suite turned on. Now change the transaction ID to gain access to another’s tickets, you will get all the sensitive details. You can also cancel someone’s ticket or do anything malicious,” he said in an email complaint to CERT-In, under the Union Ministry of Electronics and Information Technology.

As a mitigation, Renganathan who identifies himself as ethical hacker and cyber security researcher, said that the booked user and ticket should be validated so that no one else can access it except the booked user.

On September 11, 2021, he received a mail thanking him for reporting the incident to CERT-In and also a confirmation that the “reported vulnerability has been resolved” by the authorities concerned.

Renganathan, currently pursuing commerce group, has been acknowledged by LinkedIn, United Nations, BYJU’s, Nike, Lenovo, Upstox for reporting security vulnerabilities in their web applications.

Schools across Tamil Nadu re-opened only for classes ninth to twelfth on September 1. “I have opted for online classes owing to the pandemic,” he said.

Udayavani is now on Telegram. Click here to join our channel and stay updated with the latest news.

Top News

EVMs destroyed as two groups of villagers clash in Chamarajanagar district

Banjarumale hamlet in Belthangady records 100 per cent voting

Board exams twice a year from 2025: MoE asks CBSE to work out logistics, no plan for semesters

Lok Sabha 2024: Tribal hamlet of Banjarumale in Belthangady records 100% voter turnout

Padubidri: Speeding car collides with electric pole, one dead

Bengaluru eateries butter up voter turnout with free dosa

Low voter turnout in Karnataka: Only 38.23% cast votes in 14 LS segments during first half of the day

Related Articles More

Cache of arms including foreign-made revolvers seized by CBI in Sandeshkhali raids

24 Indian Fishermen Released from Sri Lankan Detention, Repatriated to India

SC verdict on EVM tight slap to Congress-led opposition: PM Modi in Bihar rallies

Board exams twice a year from 2025: MoE asks CBSE to work out logistics, no plan for semesters

Akhilesh Yadav accuses BJP of job losses and employment failure

MUST WATCH

Skin Rash, Causes, Signs and Symptoms

11 bullets found in python’s body!

K. Jayaprakash Hegde Sharing His Memories

Grafting Jack Anil

Heat Illness


Latest Additions

Elections held in 14 LS segments in Karnataka, voter turnout nearly 64 per cent till 5 pm

‘PM is scared, may even shed tears on stage’: Rahul Gandhi’s fresh salvo at Modi

Cache of arms including foreign-made revolvers seized by CBI in Sandeshkhali raids

24 Indian Fishermen Released from Sri Lankan Detention, Repatriated to India

Deep-tech drives growing patenting patterns in India; highest filings in Tamil Nadu: Study

Thanks for visiting Udayavani

You seem to have an Ad Blocker on.
To continue reading, please turn it off or whitelist Udayavani.