BOOK THIS SPACE FOR AD
ARTICLE ADHello all,
Welcome to my first ever writeup.. I am Jeet Patel, a security enthusiast and a self learner and in this writeup I will share the tale of my first ever report in cyber security domain.
Getting to know our target: As you all may know NPTEL is an online platform where anyone can enroll and get certified from IIT’s (NPTEL is our target). NPTEL consists of online assignments(mostly MCQ’s) which should be completed before deadline and then just after the deadline they release the correct answers of the assignments.
Plot Setup: So just like any other student I enrolled myself in a couple of courses. Initially I was completing my assignments before deadline, but (there is always a but before something great happens) due to university load I was unable to complete a few assignments before deadline. Since I had very busy schedule and at the same time I wanted to get certified from the IIT’s, I started to find ways to submit assignment before deadline(I could have used this time to do the assignment itself but I didn’t).
The moment: It’s the night of deadline and I was feeling very dumb since all I did was waste my time. I wanted to know if I had the time to complete the assignment, so I looked up to find out exactly how many minutes were left before deadline. I found that only 15 minutes were left and it was impossible to complete the assignment. So I dropped the idea to get certified from the IIT’s. After around 20 minutes all the answers of the assignments were available. At this very moment I got an idea.
The idea: I thought what would happen if I change my mobile date to a day before. Will the app allow me to enter the answers now? I wasn’t sure of the outcome but just like you I was curious to find out. So I changed my mobile date and time to a day before the deadline and reopened the app. And to my surprise the app allowed me to mark all the answers(that adrenaline rush).
After thoughts: I quickly made a report and reported to the concerned authorities. I was happy, since I made an effort to secure a national platform of such high value.
I could have used this vulnerability to achieve 100% on every assignment but I didn’t. Moreover I could have also used this vulnerability to get certified from the IIT’s but I didn’t (why I didn’t? Because this is what a gentleman does and this is what I am taught by my parents).
Report summary:
1. Login to your candidate account.
2. Now open mobile settings.
3. Change your mobile date to the date before the submission date of the assignment.
4. Reload or Refresh the app.
5. You may re enter the answers to questions which you got wrong or you may enter all the answers.
6. Click submit and observe your marks got updated in your profile.
Until next time.
Cheers!!