Close Menu
True News India
  • Home
  • Politics
  • Economy
  • India
  • World
  • Opinion
  • Crime
  • Education
  • Entertainment
  • Tech News
  • Automobile
  • Science
  • Health
  • Sports
  • Islam
  • Diverse
Facebook X (Twitter) Instagram
  • About Us
  • Privacy Policy
  • DMCA
Facebook X (Twitter) Instagram
True News India
  • Home
  • Politics

    Modi-Yediyurappa-Bommai magic to win Karnataka polls

    23/01/2023

    Congress leader BK Hariprasad compares defecting MLAs to prostitutes

    19/01/2023

    Congress leader’s link with terrorist Mohammad Shariq surfaces

    15/01/2023

    Annamalai to get Z security after receiving threats from Islamists

    14/01/2023

    We will send terrorists to gun down Governor: DMK

    14/01/2023
  • Economy

    New income tax regime, all you need to know

    02/02/2023

    Despondency grips corporates in Punjab, youth losing jobs

    31/10/2021

    Centre stands by FCRA amendments for NGOs

    27/10/2021
  • India

    Survey Reveals PM Narendra Modi as Most Respected World Leader

    23/10/2023

    Ramcharitmanas burning: NSA on samajwadi leaders

    07/02/2023

    Shaligram stones: Indo-Nepal cultural bridge

    04/02/2023

    Pastor Bajinder and Harpreet face Income Tax raid

    01/02/2023

    Rahul Yatra failed its aim to unite opposition

    01/02/2023
  • World

    Brampton temple hate attack: Indians slam Mayor

    03/02/2023

    BBC Documentary on Modi is biased: thousands sign petition

    25/01/2023

    Hindu temple Vandalised by Khalistan miscreants in Australia

    25/01/2023

    TTP parallel Govt: Will Pakistan disintegrate again?

    04/01/2023

    EAM S Jaishankar owns Pakistani reporter at UNSC counter terrorism meet

    16/12/2022
  • Opinion

    Chidambaram comments on SC demonetisation verdict are unbecoming

    03/01/2023

    Why DK Shivakumar and Congress oppose Savarkar?

    20/12/2022

    Why did Nitish Kumar lose his cool in Bihar assembly?

    16/12/2022

    Tarn Taran attack: Is Kejriwal soft on Khalistani terrorists?

    11/12/2022

    Is Ex-PM Deve Gowda supporting UCC?

    02/12/2022
  • Crime

    Nitin Gadkari was threatened by Dawood gang member

    17/01/2023

    Pratik Sinha of Alt News is lecherous, womaniser and fraud: Metoo victim

    15/01/2023

    Sheezan pressurised Tunisha to convert to Islam: Mother

    30/12/2022

    Sushant Singh Rajput’s body indicates Murder: Mortuary attendant

    27/12/2022

    Mohammad electrocutes wife Uma, buries her in his own room

    25/12/2022
  • More
    1. Education
    2. Entertainment
    3. Tech News
    4. Automobile
    5. Science
    6. Health
    7. Sports
    8. Islam
    9. Diverse
    10. View All

    Hijab headache reaches Bihar: Muslim Girls refuse to remove Hijab for exams

    17/10/2022

    Hijab row: Split verdict by SC on Patriarchal Islamic practice

    13/10/2022

    Hijab controversy: Karnataka government bans clothes which disturb equality

    06/02/2022

    Don’t mix education and religion: Karnataka Home Minister on Hijab controversy

    04/02/2022

    ‘Boycott Bollywood’ trend: Suniel Shetty seeks help from Yogi Adityanath

    06/01/2023

    CBFC suggests changes in SRK starrer Pathaan

    30/12/2022

    Hinduphobic “Faadu – A Love Story” defiles Lord Ganesha

    15/12/2022

    Indian workers of American boss troll Akshay Kumar as Canadian

    25/11/2022

    Top 10 Hackers in India

    04/09/2024

    Twitter suspends India’s Koo App

    19/12/2022

    Brazil’s president-elect Lula da Silva joins Koo

    02/12/2022

    HDFC Bank launches SmartHub Vyapar for merchants

    07/10/2022

    Mahindra Autos XUV700 receives unprecedented response

    08/10/2021

    ISRO makes history, India’s first privately built rocket launched

    18/11/2022

    Experts claim Covishield and Covaxin are effective against Omicron.

    16/12/2021

    Captains ready as PKL Season 9 begins tomorrow

    06/10/2022

    India beat Pakistan, claim bronze medal

    23/12/2021

    After losing, Pakistanis target Hasan Ali for being a Shia

    14/11/2021

    Rohit named T20 skipper; Kohli rested for T20 matches against NZ

    11/11/2021

    Love Jihad in Purola Unveils Concerns of Islamic Terrorism in Uttarakhand

    17/06/2023

    O Sruthi: The Heroic Tale of Ghar Wapsi Girl

    07/02/2023

    Private Madrasas to be merged with large ones in Assam

    19/01/2023

    Kufr Fatwas are political: Kerala Governor Arif Mohammad Khan

    17/01/2023

    Halala is worst crime against women: Swami Ramdev

    23/01/2023

    NCPCR to the rescue of non-Muslims from madrasas

    22/01/2023

    Places of Worship act: Modi govt seeks more time

    10/01/2023

    Discard saffron, wear modern clothes: ex-Congress MP Hussain to Yogi

    06/01/2023

    Top 10 Hackers in India

    04/09/2024

    No, the Viral Photo Does Not Show the Visit of Shankaracharya Swamis to a Masjid; It Depicts Baba Ramdev’s darbar

    13/01/2024

    Survey Reveals PM Narendra Modi as Most Respected World Leader

    23/10/2023

    Fact Check: Sandeep Deo’s Viral Claim About Vedic Approval for Beef Consumption in “Organizer” Magazine Debunked

    30/07/2023
True News India
Tech News

Sunny Nehra and his team found critical security flaws in Indian army websites

TNI DeskBy TNI Desk01/01/2022
Facebook WhatsApp Twitter Telegram Email
Sunny Nehra
Share
Facebook WhatsApp Twitter LinkedIn Telegram Pinterest

Cyber Expert, Sunny Nehra and his team recently detected multiple security loopholes in the official websites of Indian Army. Sunny Nehra from “Secure Your Hacks” detected critical vulnerabilities in the websites indianarmy.nic.in and joinindianarmy.nic.in. Nehra and his team reported their findings to CERT-In and the concerned authorities for patching.

They observed that the Indian Armed forces website was using highly outdated Lodash (a JavaScript Library). Affected versions of the package were vulnerable to Prototype Pollution. The function zipObjectDeep can be tricked into adding or modifying properties of the Object prototype. These properties will be present on all objects.

Such a critical security issue, if exploited, could lead to severe threats, including the complete takeover of the webserver. Furthermore, these sites were using obsolete jQuery, Bootstrap, and several other aspects of the web applications. This made the sites susceptible to different types of attacks.

UHBVN and DHBVN

Apart from this, they found out that some other government websites were having some critical security vulnerabilities. These sites included the UHBVN (Uttar Haryana Bijli Vitran Nigam) and DHBVN (Dakshin Haryana Bijli Vitran Nigam) with data of so many users of Haryana state. One of the primary reasons for the security issues was failing to keep various critical components of the websites up to date.

Advertisment

The websites contain a number of out-of-date features, including an out-of-date Liferay portal. It can allow an attacker to exploit the Arbitrary File Upload Vulnerability. Attackers can exploit such vulnerability to upload or transfer dangerous files. Subsequently, such files can be automatically processed within the product’s environment. In layman terms, the hacker can effectively take over the entire webserver.

This is not the first time Hacks and Security have found critical vulnerabilities in government websites. Earlier in Aug 2021, Sanjeev Gupta (former Digital India CEO) had notified how some Pakistani hackers had hacked into some Indian news channels, and Hacks and Security helped them fix their security issues.

Nehra explains the Reason behind government websites being so insecure

One of India’s well-known and acknowledged Cyber Security Professional, Sunny Nehra, created a Twitter thread to explain the root cause behind government websites being so insecure.

Photo: Sunny Nehra

Government of India hosts its websites, including those of the Indian armed forces, on NICNET (National Informatics Centre Network) data centers. However, the respective departments mostly outsource their development to private firms. These firms have to adhere to some requirements, guidelines, and procedures that vary from department to department.

Where lies the problem?

A little scrutiny of the process of outsourcing gives an indication about the problem. The same happens in other tenders of government. Also, there is bidding-based outsourcing, the officials preferring their knowns and other political matters leading to this mess up.

Some private firms get the tenders, and they further outsource those to other smaller firms and save some funds as margin. To maximize the margins, some outsource to even the cheapest possible developers who have no idea about cyber security and don’t even bother to check critical updates. The authorities don’t do security audits for all the projects. When audits are carried out, connivance and rigging can not be ruled out.

He further explains that some cyber security researchers like him keep finding such flaws. Their aim is to detect them and inform the authorities. But, it is for the government to improve their policies and regulations for the development and audits of these tech projects. Aim of such researchers is to facilitate a secure infrastructure

Because at the end, it boils down to dedication and team work. If the developing team is not aware and dedicated every task is on ad-hoc basis. The employee of an outsourced firm will update it today. But, within a few days, another update will be required.

Updating is not the only issue. Administrators must take care of other aspects like implementation, logging, auditing etc also. Government of India must address these lapses on priority basis. Unless government gets its act together, such issues can have very serious implications.

Leave a Comment

Share. Facebook WhatsApp Twitter Telegram Email LinkedIn

Related News

Top 10 Hackers in India

04/09/2024

Twitter suspends India’s Koo App

19/12/2022

Brazil’s president-elect Lula da Silva joins Koo

02/12/2022

HDFC Bank launches SmartHub Vyapar for merchants

07/10/2022
Advertisement
TRENDING

Top 10 Hackers in India

04/09/2024

No, the Viral Photo Does Not Show the Visit of Shankaracharya Swamis to a Masjid; It Depicts Baba Ramdev’s darbar

13/01/2024

Survey Reveals PM Narendra Modi as Most Respected World Leader

23/10/2023

Fact Check: Sandeep Deo’s Viral Claim About Vedic Approval for Beef Consumption in “Organizer” Magazine Debunked

30/07/2023
Advertisement
Facebook X (Twitter) Instagram YouTube
  • About Us
  • Privacy Policy
  • DMCA
© 2024 True News India - All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.