Friday, May 9, 2025
LBNN
  • Business
  • Markets
  • Politics
  • Crypto
  • Finance
  • Energy
  • Technology
  • Taxes
  • Creator Economy
  • Wealth Management
  • Documentaries
No Result
View All Result
LBNN

Indian state government fixes website bug that revealed Aadhaar numbers and fingerprints

Simon Osuji by Simon Osuji
October 13, 2023
in Creator Economy
0
Indian state government fixes website bug that revealed Aadhaar numbers and fingerprints
0
SHARES
2
VIEWS
Share on FacebookShare on Twitter

A security researcher says a bug on an Indian state government website inadvertently revealed documents containing residents’ Aadhaar numbers, identity cards, and copies of their fingerprints.

The bug was fixed last week after the security researcher disclosed the bug to local authorities.

Sourajeet Majumder found the bug in the West Bengal government’s e-District web portal that allows state residents to access government services online, like obtaining birth and death certificates and building applications. Majumder said the website bug meant it was possible to obtain land deeds, which contain records about the owners of a piece of land, from the e-District website by guessing sequential deed application numbers.

Application identification numbers are unique 16-digit numbers issued by the state government when a local resident applies for a digital copy of a deed.

an example of what a land deed looks like, slightly blurred

A partially blurred copy of an exposed West Bengal resident’s land deed.

Not every application identification number was valid. Using publicly available tools like Burp Suite to analyze the network traffic in and out of the website meant that Majumder could cycle through entire lists of sequential application numbers and use the responses from the server to determine if an application identification number was valid.

Related posts

Instagram Threads is getting video ads

Instagram Threads is getting video ads

May 9, 2025
ChatGPT’s deep research tool gets a GitHub connector to answer questions about code

ChatGPT’s deep research tool gets a GitHub connector to answer questions about code

May 8, 2025

With access to an application identification number, anyone with a login to the e-District system could access a copy of a land deed. Two land deed records seen by TechCrunch contain the names of the individuals involved with the deed, their photographs, and their full set of fingerprints from both hands. It’s not uncommon to see multiple individuals on a single deed.

The deeds also contain the individuals’ government-issued identity documents, including their confidential Aadhaar numbers, which every citizen is assigned as part of India’s national identity and biometric database. Aadhaar numbers are required for accessing banking, cell phone plans, and many government services.

Majumder reported the website vulnerability to India’s computer emergency response team, known as CERT-In, and the West Bengal government, fearing that the vulnerability could be misused for identity fraud. The bug was fixed soon after.

It’s not known if anyone else other than Majumder discovered the bug. Representatives for the West Bengal government and CERT-In did not return requests for comment. The West Bengal government’s e-District website says it has processed more than 17 million applications to date, though it’s not known how many relate to land deeds.

Local media reports a recent rise in fraud linked to the alleged theft of biometric information, which criminals are said to be using to empty bank accounts.

Source link

Previous Post

Army eyes munitions stockpiles amid focus on longer wars

Next Post

Hassan Hajjaj Collaborates with 1-54 Art Fair to Aid Morroco

Next Post
Hassan Hajjaj Collaborates with 1-54 Art Fair to Aid Morroco

Hassan Hajjaj Collaborates with 1-54 Art Fair to Aid Morroco

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

RECOMMENDED NEWS

Top 10 African countries most affected by terrorism in 2024

Top 10 African countries most affected by terrorism in 2024

11 months ago
3 Lucky NCBA Visa Cardholders Win a once-in-a-lifetime experience, courtesy of Visa

3 Lucky NCBA Visa Cardholders Win a once-in-a-lifetime experience, courtesy of Visa

10 months ago
World continues to be less peaceful, with conflict greatest since post-WWII levels

World continues to be less peaceful, with conflict greatest since post-WWII levels

11 months ago
Developer sues Sedgefield environmentalist for R5m

Developer sues Sedgefield environmentalist for R5m

2 months ago

POPULAR NEWS

  • Ghana to build three oil refineries, five petrochemical plants in energy sector overhaul

    Ghana to build three oil refineries, five petrochemical plants in energy sector overhaul

    0 shares
    Share 0 Tweet 0
  • When Will SHIB Reach $1? Here’s What ChatGPT Says

    0 shares
    Share 0 Tweet 0
  • Matthew Slater, son of Jackson State great, happy to see HBCUs back at the forefront

    0 shares
    Share 0 Tweet 0
  • Dolly Varden Focuses on Adding Ounces the Remainder of 2023

    0 shares
    Share 0 Tweet 0
  • US Dollar Might Fall To 96-97 Range in March 2024

    0 shares
    Share 0 Tweet 0
  • Privacy Policy
  • Contact

© 2023 LBNN - All rights reserved.

No Result
View All Result
  • Home
  • Business
  • Politics
  • Markets
  • Crypto
  • Economics
    • Manufacturing
    • Real Estate
    • Infrastructure
  • Finance
  • Energy
  • Creator Economy
  • Wealth Management
  • Taxes
  • Telecoms
  • Military & Defense
  • Careers
  • Technology
  • Artificial Intelligence
  • Investigative journalism
  • Art & Culture
  • Documentaries
  • Quizzes
    • Enneagram quiz
  • Newsletters
    • LBNN Newsletter
    • Divergent Capitalist

© 2023 LBNN - All rights reserved.