Newsbytes
  • India
  • Business
  • World
  • Politics
  • Sports
  • Technology
  • Entertainment
  • Auto
  • Lifestyle
  • Inspirational
  • Career
  • Bengaluru
  • Delhi
  • Mumbai
  • Videos
  • Visual Stories
  • Reviews
  • Phone Reviews
  • Fitness Bands Reviews
  • Speakers Reviews
  • Find Cricket Statistics
Hindi
More
In the news
Samsung
Google
Space News
OnePlus
Latest Tablets
Newsbytes
Hindi
Newsbytes
User Placeholder

Hi,

Logout


India
Business
World
Politics
Sports
Technology
Entertainment
Auto
Lifestyle
Inspirational
Career
Bengaluru
Delhi
Mumbai
Videos
Visual Stories
Reviews
Phone Reviews
Fitness Bands Reviews
Speakers Reviews
Find Cricket Statistics

More Links
  • Videos

Download Android App

Follow us on
  • Facebook
  • Twitter
  • Linkedin
  • Youtube
 
Home / News / Technology News / French security researcher hacks BSNL intranet, exposes critical security flaws
Technology

French security researcher hacks BSNL intranet, exposes critical security flaws

French security researcher hacks BSNL intranet, exposes critical security flaws
Written by Mudit Dube
Mar 05, 2018, 07:20 pm 2 min read
French security researcher hacks BSNL intranet, exposes critical security flaws

French cybersecurity researcher Baptiste Robert claims to have gained access to a private database of state-run Bharat Sanchar Nigam Limited (BSNL) which contains details of more than 47,000 employees. Baptiste Robert or Eliott Alderson (Twitter name), gained access by breaking into BSNL's intranet system and embedding a malicious code which helped him source the database. Here's more on this development.

Twitter Post
How the French security researcher hacked into BSNL intranet system

1) There was a SQL injection in their intranet website. It allows the attacker to dump the all database of the BSNL intranet. It contains the information of 47K+ BSNL employees, Senior officiers' information, BNSL administrators information, retired employee details and more. pic.twitter.com/HTEwtC63wp

— Elliot Alderson (@fs0c131y) March 4, 2018
Living at Risk
Indian engineer's warning fell on BSNL's deaf ears

The security issue brought to light what was earlier discovered by an Indian cybersecurity researcher Sai Krishna Kothapalli. Sai Krishna found this security vulnerability around two years back when he contacted BSNL about the issue which Sai Krishna says "could have been the largest data dump or hack in Indian history". However, Sai's requests fell on deaf ears.

Twitter Post
Alderson too confirms the issue was reported 2 years back

I found this issue a few days ago, but I'm not the first one to discover this issue. This issue had been discovered by a fellow Indian, @kmskrishna, 2 years ago. He sent mails to BSNL, even called senior officiers, but nobody answered him... pic.twitter.com/iN5mPr1EKs

— Elliot Alderson (@fs0c131y) March 4, 2018
Security flaws
From private data to Ransomware

Apart from all the private data and passwords of the employees, Alderson claimed that couple of BSNL websites - intranetuk.bsnl.co.in and intranethr.bsnl.co.in had also been attacked by ransomware and were unnoticed by BSNL, until he reported about it. He also highlighted that BSNL website had several open directories which "allowed everybody to consult their documents" and that a "monitoring bandwidth system was accessible publicly."

Earlier leaks
Meanwhile, how secure is your data?

Last week, Alderson alerted Bengaluru Police regarding security flaws in its VPNs and directories. He has also identified vulnerabilities in Telangana government's TSPost and gained access to Aadhaar details of 56 lakh NREGA scheme beneficiaries. Last year, Alderson also exposed security flaws in mAadhaar app.

Share this timeline
Facebook
Whatsapp
Twitter
Linkedin
Mudit Dube
Mudit Dube
Twitter
Mudit Dube is a technology and automobile editor at NewsBytes. He also manages the in-house news writing software, YANTRA. With an experience of nearly five years, his work focuses on daily news trends, explainers, reviews, and developing technologies. He has a postgraduate diploma in Journalism from the Asian College of Journalism and has previously worked with NewsX, a 24-hour english news channel.
Latest
India
Telangana
Technology
Ransomware
Bengaluru Police
Latest
Rajasthan: Stampede at Khatu Shyamji leaves 3 dead, several injured
Rajasthan: Stampede at Khatu Shyamji leaves 3 dead, several injured India
5 ways to master the minimalist look for your home
5 ways to master the minimalist look for your home Lifestyle
Happy birthday, Fahadh Faasil: Looking at his five memorable roles
Happy birthday, Fahadh Faasil: Looking at his five memorable roles Entertainment
2023 Dacia Duster Commercial debuts in the UK: Check features
2023 Dacia Duster Commercial debuts in the UK: Check features Auto
Garena Free Fire MAX: How to redeem August 8 codes?
Garena Free Fire MAX: How to redeem August 8 codes? Technology
India
NIA arrested IS suspect from Batla House, family denies charges
NIA arrested IS suspect from Batla House, family denies charges India
Dharamshala: Russian-origin man marries Ukrainian girlfriend in full desi style
Dharamshala: Russian-origin man marries Ukrainian girlfriend in full desi style India
Use these 5 free resources to ace JEE preparation
Use these 5 free resources to ace JEE preparation Career
Commonwealth Games: Indian women's hockey team thrashes Ghana 5-0
Commonwealth Games: Indian women's hockey team thrashes Ghana 5-0 Sports
Here are the interesting facts about the Commonwealth Games
Here are the interesting facts about the Commonwealth Games Sports
More News
Telangana
PM to chair NITI Aayog meet today; KCR to boycott
PM to chair NITI Aayog meet today; KCR to boycott Politics
4 Telangana municipal employees suspended for missing KTR's 'birthday'
4 Telangana municipal employees suspended for missing KTR's 'birthday' Politics
Telangana 'doctor' Governor Tamilisai Soundararajan treats ailing co-passenger mid-air
Telangana 'doctor' Governor Tamilisai Soundararajan treats ailing co-passenger mid-air India
UK announces largest drone superhighway: How's India boosting similar technology?
UK announces largest drone superhighway: How's India boosting similar technology? World
Monsoon: Delhi witnesses heavy rainfall today, several areas waterlogged
Monsoon: Delhi witnesses heavy rainfall today, several areas waterlogged Delhi
More News
Technology
OxygenOS 13, based on Android 13, announced: Check features, compatibility
OxygenOS 13, based on Android 13, announced: Check features, compatibility Technology
Best smartphones for content creators, designers, photographers, and game streamers
Best smartphones for content creators, designers, photographers, and game streamers Technology
Digital minimalism 101: Get a focused life with digital declutter
Digital minimalism 101: Get a focused life with digital declutter Lifestyle
Best tablets in India under Rs. 40,000
Best tablets in India under Rs. 40,000 Technology
#DealOfTheDay: This robotic vacuum cleaner is cheaper by Rs. 45,000
#DealOfTheDay: This robotic vacuum cleaner is cheaper by Rs. 45,000 Technology
More News
Ransomware
Swatch Group hit by cyberattack, operations affected
Swatch Group hit by cyberattack, operations affected Technology
Ray-Ban owner hit by ransomware attack: Details here
Ray-Ban owner hit by ransomware attack: Details here Technology
Germany: Cyber attack on a hospital leaves a patient dead
Germany: Cyber attack on a hospital leaves a patient dead Technology
Carnival, world's largest cruise line operator, falls victim to cyberattack
Carnival, world's largest cruise line operator, falls victim to cyberattack Technology
Canon loses 10TB data in massive ransomware attack: Details here
Canon loses 10TB data in massive ransomware attack: Details here Technology
More News
Bengaluru Police
'Was given drinks and drug-laced cigarettes,' claims Siddhanth Kapoor
'Was given drinks and drug-laced cigarettes,' claims Siddhanth Kapoor Entertainment
Day after arrest, Siddhanth Kapoor, 4 others released on bail
Day after arrest, Siddhanth Kapoor, 4 others released on bail Entertainment
Netflix docu-series 'Crime Stories: India Detectives' out on September 22
Netflix docu-series 'Crime Stories: India Detectives' out on September 22 Entertainment
Bengaluru rape: 2 accused shot by police during escape attempt
Bengaluru rape: 2 accused shot by police during escape attempt India
Vivek Oberoi's home searched in drugs case involving relative
Vivek Oberoi's home searched in drugs case involving relative Entertainment
More News
Next News Article
Next News Article

Love Technology news?

Subscribe to stay updated.

Science Thumbnail
India News Business News World News Politics News Sports News Technology News Entertainment News Auto News Lifestyle News Inspirational News
Career News Bengaluru News Delhi News Mumbai News Mukesh Ambani Indian Premier League (IPL) Karnataka Samsung Xiaomi West Bengal
Bihar Virat Kohli Rohit Sharma Haryana Narendra Modi Arvind Kejriwal Tamil Nadu Gujarat Yogi Adityanath YouTube
Instagram Hollywood News Uttar Pradesh Kerala Netflix Bollywood News Mamata Banerjee Maruti Suzuki Rahul Gandhi Elon Musk
Shah Rukh Khan Chelsea FC OPPO Akhilesh Yadav Indian Cricket Team Apple Manchester United Salman Khan Cryptocurrency OnePlus
Amitabh Bachchan ICC Women's World Cup Vivo India vs Sri Lanka
About Us Privacy Policy Terms & Conditions Contact Us Ethical Conduct Grievance Redressal News News Archive Topics Archive IPL 2022 Schedule IPL 2022 Points Table Find Cricket Statistics
Follow us on
Facebook Twitter Linkedin Youtube
All rights reserved © NewsBytes 2022