HomeNewsTechnology A French techie is exposing security loopholes in government-run websites including UIDAI

 A French techie is exposing security loopholes in government-run websites including UIDAI

Alderson also discovered that BSNL’s intranet websites had been attacked by a ransomware and allegedly, the IT department of the company had no knowledge about it

March 05, 2018 / 12:53 IST
Story continues below Advertisement
Elliot Alderson
Elliot Alderson

A French security researcher going by a pseudo-name of Elliot Alderson is exposing security vulnerabilities in Indian government-run websites and apps which include Aadhaar, Bengaluru Police, and the latest BSNL.

In the most recent exposé, Alderson bared open serious vulnerabilities which put personal details of BSNL’s former as well as present employees, over 47,000 in number, under threat. Alderson discovered that the data could be accessed by a simple SQL injection—the bread and butter of any professional computer hacker.

Story continues below Advertisement

“There was a SQL injection in their intranet website. It allows the attacker to dump all database of the BSNL intranet. It contains the information of 47K+ BSNL employees, Senior officers' information, BNSL administrators information, retired employee details and more,” Alderson said in a tweet.

The researcher also shared screengrab of the dataset which tables the name, designation, fax number, phone and email address among other details.