Moneycontrol PRO
HomeNewsTechnology A French techie is exposing security loopholes in government-run websites including UIDAI

 A French techie is exposing security loopholes in government-run websites including UIDAI

Alderson also discovered that BSNL’s intranet websites had been attacked by a ransomware and allegedly, the IT department of the company had no knowledge about it

March 05, 2018 / 12:53 IST
Elliot Alderson

A French security researcher going by a pseudo-name of Elliot Alderson is exposing security vulnerabilities in Indian government-run websites and apps which include Aadhaar, Bengaluru Police, and the latest BSNL.

In the most recent exposé, Alderson bared open serious vulnerabilities which put personal details of BSNL’s former as well as present employees, over 47,000 in number, under threat. Alderson discovered that the data could be accessed by a simple SQL injection—the bread and butter of any professional computer hacker.

“There was a SQL injection in their intranet website. It allows the attacker to dump all database of the BSNL intranet. It contains the information of 47K+ BSNL employees, Senior officers' information, BNSL administrators information, retired employee details and more,” Alderson said in a tweet.

The researcher also shared screengrab of the dataset which tables the name, designation, fax number, phone and email address among other details.

Moreover, Alderson also discovered that BSNL’s intranet websites had been attacked by a ransomware and allegedly, the IT department of the company had no knowledge about it.

After discovering, Alderson informed the state-owned telecom company about the flaw which it rectified over the weekend.

Worryingly, the French hacker is not the first person to discover the security issue. An Indian engineering student had informed about the flaw to BSNL two years ago but the state-run telecom service provider didn't bat an eyelid.

Alderson’s other exploits include a series of exposé about security flaws in Aadhaar website as well as the app. After one of the exposé, the mAadhaar app was updated to eradicate the vulnerability.

Alderson also pointed out the security lapse in Bengaluru City Police and Telangana government website which oozed out details of beneficiaries of the MNREGA, including their contact details and personal information.

Invite your friends and family to sign up for MC Tech 3, our daily newsletter that breaks down the biggest tech and startup stories of the day

Moneycontrol News
first published: Mar 5, 2018 12:53 pm

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347