IRCTC clarifies on bug issue

September 28, 2021 02:45 pm | Updated 02:48 pm IST - CHENNAI:

P. Renganathan, a Standard 12th student, flagged the bug in IRCTC’s system. Photo: Special Arrangement

P. Renganathan, a Standard 12th student, flagged the bug in IRCTC’s system. Photo: Special Arrangement

The Indian Railway Catering and Tourism Corporation (IRCTC) has stated that there is no chance of cancelling a train ticket by using a different user identity and password.

Referring to a report titled “ Teen flags bug in IRCTC’s system ” published in these columns on September 21, 2021, IRCTC’s spokesperson Anand Kumar Jha said that there was no scope to cancel a ticket or change the boarding station etc. by taking advantage of a vulnerability since the functionalities were user profile specific.

But, he said the issue of accessing the transaction details by changing the transaction identity had been fixed on second September 2, 2021. IRCTC website is well secured and subjected to third-party security audits, he added.

However, P. Renganathan (17), Chennai-based XII Standard student who flagged the issue had written to the the Computer Emergency Repose Team stating that he had discovered a critical vulnerability that leaked the transaction details of millions of travellers.

Explaining how the private data could be accessed, Renganathan said that by changing the transaction identity one could gain access to others travel details. “You will get all the sensitive details. You can also cancel someone’s ticket or do anything malicious,” he said.

To this, CERT thanked the teenager and confirmed by email that the vulnerability had been fixed.

0 / 0
Sign in to unlock member-only benefits!
  • Access 10 free stories every month
  • Save stories to read later
  • Access to comment on every story
  • Sign-up/manage your newsletter subscriptions with a single click
  • Get notified by email for early access to discounts & offers on our products
Sign in

Comments

Comments have to be in English, and in full sentences. They cannot be abusive or personal. Please abide by our community guidelines for posting your comments.

We have migrated to a new commenting platform. If you are already a registered user of The Hindu and logged in, you may continue to engage with our articles. If you do not have an account please register and login to post comments. Users can access their older comments by logging into their accounts on Vuukle.