Tirth Parmar
94 posts

Tirth Parmar
@thetirthparmar
Cyber Security Engineer | Full-Stack Developer | Founder @levythonhq
India Katılım Nisan 2020
49 Takip Edilen590 Takipçiler

This email from a girl student was received yesterday. While the CBSE portal shows that copies of all her answer sheets have been uploaded and provided, she has neither received them nor is she able to download one of them .
This is just one example showing that the CBSE portal is still not functioning properly. I have received numerous complaints regarding the same issue from students across the country.
@cbseindia29, students are continuously writing to you but are not receiving any response. Kindly look into these issues and resolve them immediately.
@EduMinOfIndia

English
Tirth Parmar retweetledi

@ni5arga @cbseindia29 good morning CBSE, you said you used scanners to scan these copies,
now since the copies are out to the public view, do you mind explaining
which copies when scanned through a scanner, have a drop shadow? and these 3 folds?
did you really use scanners?

English

We managed to access CBSE’s OSM storage bucket due to a basic misconfiguration it was left publicly open.
#cbse #cybersecurity
nisarga@ni5arga
CBSE people didn't configure their AWS bucket properly and now we can paginate & enumerate all their media which has 2026 answersheets & question papers. ListObjectsV2 works without any auth and the bucket root is listable too — anyone on the internet can download any scanned booklet — across institutions. Multiple institutions are using the same bucket, insanely insecure.
English

@ohyeah_xdd I already did research on similar axis bank app, check this
linkedin.com/posts/thetirth…
English

@thetirthparmar Very good write-up.
We need more of these 🙂.
Recently a relative's mobile got hacked after they installed SBI yono apk from WhatsApp but unfortunately I deleted the Apk and hence couldn't decompile/inspect it.
English

So I busted a fake RTO website yesterday (as I teased). Here's the full technical breakdown, it gets way wilder than I expected. 🧵 (1/12) #malware #cybersecurity
English

@ContactVVR Exactly! Indian expats in Saudi still have Indian bank accounts. So one infected phone = UPI PIN stolen (Indian savings) + Saudi bank SMS monitored (salary).
Both countries’ finances compromised in one click
English

@thetirthparmar So they are basically scamming Indians living in Saudi Arabia with fake challan. The currency restriction to Riyal was a deadgiveaway. Thank you for your meticulous work & a detailed thread. Sad that the authorities won't bother about this either.
English

almost every single OnMark portal built by EduTek is fundamentally insecure, and CBSE is lying to you about the safety of student data.
we found default passwords, URL-based RCEs, and raw MD5 hashes. millions of students are at risk.
read the blog here: sidharthify.tech/blogs/blog-31-…

English

@thetirthparmar What will happen if I click but do not install apk?
English

@0xApollyon Yes, we’ve got RCE on 2x Onmark subdomains and reported it, check this out
Tirth Parmar @thetirthparmar
PWNING OSM in a Speedrun 😼 #OSM #CBSE #cybersecurity
English

@thetirthparmar lmfao you have shell access ??? 🤣
who did the security for this shit bruh
English


@0xApollyon It’s not a defacement, it’s just an “echo” command
English

@thetirthparmar hey tirth, i wouldnt recommend doing this. while its funny as hell and the authorities equally incompetent, by defacing stuff you are giving them an easy target to make an example out of
English

@krutikvirani rto-seva[.]online/parivahan/app/
ata011.b-cdn[.]net/final-2d0d6519.apk
MD5: 88699d567254fa954f0394347317e1df
English

UPDATE: Bunny CDN just took down the malicious APK. Wasn't even 5 minutes since I reported lol
The malware can no longer be downloaded. New infections = blocked.
@BunnyCDN W 🐇

Tirth Parmar @thetirthparmar
So I busted a fake RTO website yesterday (as I teased). Here's the full technical breakdown, it gets way wilder than I expected. 🧵 (1/12) #malware #cybersecurity
English

IOCs:
- rto-seva[.]online/parivahan/app/
- ata011.b-cdn[.]net/final-2d0d6519.apk
- MD5: 88699d567254fa954f0394347317e1df
- fir-[REDACTED]-rtdb.firebaseio.com
Reported to Google + CERT-In & Bunny CDN
If you get a challan SMS with a link DO NOT click. (12/12) #AndroidMalware
English


