City
Epaper

Govt's Parivahan website's source code, user data exposed on dark web

By IANS | Updated: August 12, 2023 17:35 IST

New Delhi, Aug 12 Cybersecurity firm CloudSEK has reported that the Parivahan website suffered a data breach, leading ...

Open in App

New Delhi, Aug 12 Cybersecurity firm CloudSEK has reported that the Parivahan website suffered a data breach, leading to the leak of its source code and user data on the Dark Web.

CloudSEK claimed that the breach exposed the source code of the Integrated Road Accident Database (iRAD) website, an initiative by the Ministry of Road Transport and Highways (MoRTH).

The breach, discovered on August 2, involved sharing the code on an underground cybercrime forum, potentially compromising sensitive information and security infrastructure.

"CloudSEK has notified the MoRTH about the breach. The firm urges immediate action to secure the iRAD website and safeguard sensitive user data," the firm said.

Detailed analysis of the leaked source code by CloudSEK uncovered alarming issues. "We discovered sensitive assets embedded within the code, including hostnames, database names, and passwords. The usernames and passwords found in the source code were quite simple and susceptible to brute-force attacks when there's local access to the server," stated the cybersecurity firm.

The source code references sms.gov.in, a NIC SMS Gateway used by government departments to send SMS to Indian nationals. The embedded URL in the source code includes fields for usernames and passwords, which if exploited, might give unauthorized individuals the ability to send messages to recipients, CloudSEK noted.

The same threat actor, after exposing the source code, shared a sample dataset of 10,000 user records from a vulnerable API endpoint of the iRAD website on August 7. This data breach was achieved through an SQL injection, underscoring significant vulnerabilities. The leaked dataset contains sensitive information such as user IDs, names, emails, mobile numbers, and passwords.

Upon verification, some mobile numbers and names from the sample dataset matched via Truecaller. The dataset also included email IDs and clear text passwords of government officials, according to CloudSEK.

Bablu Kumar, Cyber Intelligence Analyst at CloudSEK, explained: "The extraction of source code and an SQL injection wield a power that extends far beyond the surface. These breaches are not mere data breaches; they are gateways to understanding the very essence of a website's business logic. The threat is not limited to the data lost today; it encompasses the potential for more profound impacts, opening doors to realms of sensitive information that we cannot foresee."

Disclaimer: This post has been auto-published from an agency feed without any modifications to the text and has not been reviewed by an editor

Tags: congresspitrodadelhimodideepikabjpwest-bengaldeepika-padukoneajay-devgnthakur
Open in App

Related Stories

Entertainment1 Year of Kalki 2898 AD: “If You Remove Her Character, There Is No Story,” Nag Ashwin on Deepika Padukone’s Role

MumbaiBuying a Home in Mumbai? You’ll Need to Save for 109 Years to Afford a 2BHK

PunePune: BJP Leader Pramod Kondhare Booked for Molesting Woman Police Officer During Nitin Gadkari Visit

NationalDelhi Shocker: 19-Year-Old Woman Dies After Being Pushed Off Terrace by Burqa-Clad Stalker; Heavy Police Deployment in Area

NationalDelhi Fire: 4 Killed in Chemical Factory Blaze Near Rithala Metro Station

Politics Realted Stories

NationalAssembly Bypoll Results 2025: AAP Wins Visavadar and Ludhiana West Seats; Congress Wrests Nilambur Seat in Kerala

MaharashtraNCP Leader Suraj Chavan Shares Alleged Black Magic Video of Shiv Sena Leader Bharat Gogawle Amid Row Over Raigad Guardian Post

MaharashtraMaharashtra Politics: Raj Thackeray Meets CM Devendra Fadnavis at Taj Lands End Amid Rumours of MNS–Sena UBT Alliance

MaharashtraMaharashtra Municipal Elections 2025: Mahayuti Alliance to Contest Civic Body Polls Together, Says CM Devendra Fadnavis

Maharashtra'Remembered the Advice My Mother Gave Me': Supriya Sule On Her WhatsApp Status