By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Get the Latest Technology News and Updates, New Launches & MoreGet the Latest Technology News and Updates, New Launches & More
  • Home
  • Lifestyle
  • Business
  • Blog
  • Contact
Reading: Fault In RailYatri Security Could Have Exposed User Data Of 7 Lakh Passengers Including Debit Cards And UPI
Share
Notification Show More
Font ResizerAa
Font ResizerAa
Get the Latest Technology News and Updates, New Launches & MoreGet the Latest Technology News and Updates, New Launches & More
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Get the Latest Technology News and Updates, New Launches & More > Tech News > Fault In RailYatri Security Could Have Exposed User Data Of 7 Lakh Passengers Including Debit Cards And UPI
Tech News

Fault In RailYatri Security Could Have Exposed User Data Of 7 Lakh Passengers Including Debit Cards And UPI

admin
Last updated: August 24, 2020 12:15 pm
By admin
3 Min Read
Share
Security Flaw In RailYatri Could Have Resulted In Exposure Of Data Of 7 Lakh Passengers
SHARE

Highlights:

  • The security flaw in RailYatri exposed user names, payment information
  • The flaw was first spotted by Safety Detectives, a cyber-security firm
  • RailYatri has closed the unprotected server in questio

RailYatri is an Indian travel marketplace which was founded in 2011 and was reportedly left exposed due to inadequate security measures put in place, which has put the payment information and other personal data of lakhs of users at risk.

According to the report, that data was saved on a server which was unsecured and the online ticket-booking platform potentially exposed the personal information of more than 7 lakh passengers which includes Full Names, Phone Numbers, Addresses, E-Mail IDs, Ticket Booking Details, a Part of both Debit and Credit Card Numbers.

This flaw was first spotted by a team of cyber-security researchers on the 10th of August.

According to the report by The Next Web, the exposed Elasticsearch server was spotted by a team of researchers at cyber-security firm Safety Detectives on August 10.

The European security firm discovered that the affected server was left exposed without any encryption or password protection for several days. Safety Detectives, in its blog, said that anyone with the server’s IP address could have gained access to the full database.

Also Read: Top 10 Made In India Apps That You Should Know

The blog said that the data which amounted to almost 43 GB and mostly featured of users from India. The firm has estimated that more than 7 lakh people could have been affected by this vulnerability which was left unchecked for several days.

A national news agency tried to get in touch with RailYatri for a statement. However, the company did not respond while the report was uploaded.

When the report was written, RailYatri neither responded to The Next Web nor the Security Detectives, however, they did close the server after the security firm raised the matter with the government wing, Indian Computer Emergency Response Team (CERT-In).

On the 12th of August, a Meow boot attack led to the deletion of almost all of the server data as per the blog post of the Safety Detectives. The report from a leading news agency said, “The Meow bot is a new type of cyber-attack that deletes unsecured databases that run Elasticsearch, Redis, or MongoDB servers.”

The database in question had more than 37 million (or 3.7 crore) records which included log files. The type of information exposed due to the fault contained Full Names, Age, Sex, Physical/ E-Mail Addresses, Contact Numbers, Payment Logs, UPI IDs, Train and Bus Booking details, and Travel Itinerary information. It also carried partial records of Credit and Debit Card information along with the GPS Location Information of the users.

Twitter, Zoom Slapped With Allegations Of Racial Bias In Algorithms, Twitter Says There Is More Work To Be Done
From Android 13 To Pixel Watch; Here’s What To Expect From Google’s Annual Tech Event
Twitter Employees Were Manipulated By Hackers Company Said In A Blog On Friday
Latest Telegram Update Comes With Shareable Chat Folders, Custom Wallpapers, Etc.
WhatsApp Finally Prohibits Users From Taking Screenshots Of ‘View Once’ Messages, Allow Silent Group Exits, More
Share This Article
Facebook Email Print
Byadmin
Passionate about all things tech, an extensive background in software development and a natural talent for writing, David is a seasoned technology author who has a knack for making complex tech topics simple to comprehend.
Previous Article Oracle In Talks With TikTok To Take Over Its US Operations Oracle Shows Interest In Taking Over TikTok’s US Operations after Microsoft And Twitter
Next Article WhatsApp Could Soon Make It Easier To Manage Space Taken By The App WhatsApp Looking Forward On Making It Easier To Manage Space
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Tech Talk County Light Logo

Lorem ipsum dolor sit amet elit quam aenean commodo ligula eget dolor eget natoque penatibus sociis magnis dis parturient montes quam.

CATEGORY

  • Android66
  • Gaming40
  • Hot Gadgets24
  • HOW TO36
  • iOS86
  • Mac9
  • Reviews13
  • Tech News297
  • Windows27

BROWSE BY TAGS

Support

  • PRIVACY POLICY
  • COOKIE POLICY
  • CONTACT
  • ADVERTISE

Useful Links

Top Free VPN For Android

Best VR Games For iPhone

Best VR Games For Android

Watch Wrestling Online

Best Game Boosters For Android

Best uTorrent Alternatives

Best Instagram Reels Editing Apps

Free TV Streaming Sites

Categories

  • Android
  • Gaming
  • Hot Gadgets
  • HOW TO
  • iOS
  • Mac
  • Reviews
  • Tech News
  • Windows
Get the Latest Technology News and Updates, New Launches & MoreGet the Latest Technology News and Updates, New Launches & More
Copyright © 2025 techtalkcounty.com. All rights reserved.
Join Us!
Subscribe to our newsletter and never miss our latest news, podcasts etc..
[mc4wp_form]
Zero spam, Unsubscribe at any time.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?