[ / / / / / / / / / / / / / ] [ dir / random / abcu / alleycat / femdom / islam / newbrit / pone / wmafsex / x ]

/random/ - random

shitpost central
Name
Email
Subject
Comment *
File
Password (Randomized for file and post deletion; you may also set your own.)
Archive
* = required field[▶ Show post options & limits]
Confused? See the FAQ.
Embed
(replaces files and can be used instead)
Oekaki
Show oekaki applet
(replaces files and can be used instead)
Voice recorder Show voice recorder

(the Stop button will be clickable 5 seconds after you press Record)
Options
dicesidesmodifier

Allowed file types:jpg, jpeg, gif, png, webm, mp4, swf, pdf
Max filesize is 16 MB.
Max image dimensions are 15000 x 15000.
You may upload 5 per post.


 No.35562

I am an intermediate-level pentester and I have found very serious security issues in the websites of Allen Career Institute and Sri Chaitanya institute. These issues are so serious that if GDPR laws were applicable in India, these institutes might have been shut down by now.

Allen Career Institute currently has over 2 lakh students studying with them. And all the students' pictures are OPENLY ACCESSIBLE without any authentication credentials and hosted on their domain officeweb.allen.ac.in. I cannot give the full URL here because someone could misuse the students' images. And guess what, there are pictures of children as young as 11 years since Allen starts batches from Class 6. Wonder what a potential abuser could do with the pictures of these young souls.

Not only that, but at the time of admission, Allen takes the full details of a student, including Parents' Name, Blood Group and Residential Address. I was also able to easily retrieve all this information of any student given just his/her registration number.

The security measures on their website are so damn pathetic that an amatuer person like me could easily retrieve such sensitive private details of students without any considerable effort.

And about Sri Chaitanya, they even ask the aadhaar number of the student at the time of admission, and their test website epraghna.com is so-poorly designed that I managed to reset any student's password with just a custom POST request. Then I was able to view all of his/her details.

These institutes need to be charged and strict legal action should be taken against them in these matters. There is little awareness about privacy laws in this country. These institutes earn so much yet they care nothing about students' privacy.

I tried to contact both the institutes by email but none responded. Seems that they only respond to people who are interested in buying their courses.

Please share this as much as possible. It's better that these institutes realise the seriousness of this problem before something unfortunate happens. I hope these people are sued in courts and made to pay a huge price as they have taken the serious issue of privacy so lightly.

POC containing 3 censored pictures of students with roll number:- https://www.reddit.com/user/ParticularOk1268/comments/kzrtzm/sample_set_of_3_images_file_names_are/

I also tried to contact a journalist but he didn't show much interest in this story and never replied back.

If you know anyone who could help, please share their contact in the comments or by PMing me.

Thanks a lot.

____________________________
Disclaimer: this post and the subject matter and contents thereof - text, media, or otherwise - do not necessarily reflect the views of the 8kun administration.

 No.35563

File: e0bbd79152f1141⋯.jpg (278.71 KB, 1384x2047, 1384:2047, 85301839_p0.jpg)

bad security is one thing.. but people giving away any info that is asked for is part of the problem too

Disclaimer: this post and the subject matter and contents thereof - text, media, or otherwise - do not necessarily reflect the views of the 8kun administration.

 No.35565

File: f199127cadcb15b⋯.png (3.48 MB, 1544x1998, 772:999, Screen_Shot_2020_06_03_at_….png)

Congrats on posting the gayest least interesting hacking in the history of imageboards, oh and you just found it on reddit.

Disclaimer: this post and the subject matter and contents thereof - text, media, or otherwise - do not necessarily reflect the views of the 8kun administration.

 No.36324

File: 6d34586a309f492⋯.png (4.05 MB, 3584x2006, 1792:1003, Screen_Shot_2021_01_24_at_….png)

File: 103a51211e1871f⋯.png (4.1 MB, 3584x2004, 896:501, Screen_Shot_2021_01_24_at_….png)

File: 0a759b8e7ba823d⋯.png (3.19 MB, 3584x2008, 448:251, Screen_Shot_2021_01_24_at_….png)

Disclaimer: this post and the subject matter and contents thereof - text, media, or otherwise - do not necessarily reflect the views of the 8kun administration.

 No.36325

File: 86bbe17f1e4e9c1⋯.png (2.91 MB, 3584x1998, 1792:999, Screen_Shot_2021_01_24_at_….png)

File: 1e323e725f264ae⋯.png (3.9 MB, 3584x2004, 896:501, Screen_Shot_2021_01_24_at_….png)

Disclaimer: this post and the subject matter and contents thereof - text, media, or otherwise - do not necessarily reflect the views of the 8kun administration.



[Return][Go to top][Catalog][Nerve Center][Random][Post a Reply]
Delete Post [ ]
[]
[ / / / / / / / / / / / / / ] [ dir / random / abcu / alleycat / femdom / islam / newbrit / pone / wmafsex / x ]