A
33.6K posts

A
@Valar_Coduliss
Engineer @nvidia, Cricket, Politics, Travel, Food.

How a CBSE student uncovered a security flaw in a national exam portal "I got curious," Nisarga Adhikary told Moneycontro's @AihikS in an interview. "They had rolled out a new portal (cbse.onmark.co.in) for digital evaluation of copies. I started looking around and found the domain. Teachers were already using it and there were videos about it online." Adhikary said he did not possess any credentials to access the system. Instead, he examined the website's publicly accessible JavaScript files — code that is automatically downloaded by any browser visiting the portal. "I came across the master password thing," he said. "It was not hashed. It was literally hardcoded in the code." According to Adhikary, the password could be located through a simple keyword search -- Control +F-- within the code bundle. Using publicly obtainable user identifiers and school IDs, he said he was able to access the portal. In his blog post, Adhikary detailed several alleged vulnerabilities in the system, including client-side OTP validation, exposed credentials and insufficient access controls. He described the flaws as "amateur mistakes" that required little sophistication to exploit. “This is a really big security blunder,” he said. “Anyone with a browser can read the code. You don't even need sophisticated exploitation. One Ctrl+F search and you can find the password.” moneycontrol.com/technology/big…



META'S $125 BILLION INVESTMENT IN AI COULD BE A SIGNIFICANT CAPITAL EXPENDITURE MISTAKE OF THE DECADE.










Clarification Regarding Claim of Compromise of CBSE OSM Portal In a post made by a user on social media, it has been claimed that the CBSE On Screen Marking (OSM) bearing URL: cbse.onmark.co.in was compromised by him on 26.02.2026. This has also formed the basis for a few news articles. At the outset, it is clarified that the Portal used for evaluation of answer-books bore a different URL, which has neither been compromised nor does it have the vulnerabilities indicated in the said social media post. The URL: cbse.onmark.co.in is the testing site only with sample data for internal testing and review purposes. There are no actual evaluation data, marks or other data held on that portal. The Board emphasises that no security breaches have come to light on the Portal deployed for the actual evaluation work. The Board would like to state that this system has been implemented for enhanced transparency in assessments with strong grievance redressal mechanisms built into it and would reassure all concerned about the strong safeguards implemented to ensure integrity of the platform actually deployed as regards any vulnerabilities. @EduMinOfIndia @PTI_News @PIB_India @PIB_Edu @AkashvaniAIR @airnewsalerts @DDNewslive @dpradhanbjp @sanjayjavin














