Nisarga Adhikary, the 19-year-old cybersecurity researcher who found major flaws in CBSE’s OSM portal earlier this yearhas been named in the US Department of Justice (DoJ)’s Hall of Fame for cybersecurity. Nisarga says he was given this acknowledgement after finding a major flaw in one of DoJ’s systems.
“I found a critical vulnerability in one of their largest law enforcement systems,” Nisarga told India Today Tech. The 19-year-old could not share more details on what the vulnerability was or which system had it. But he did mention that it was fixed by the DoJ shortly after he had sent his report. “I reported the vulnerability roughly a week ago, they validated and patched this within a week and credited me on their Hall of Fame/ acknowledgements page,” he said.
On X, Nisarga Adhikary shared a screenshot from the DoJ’s acknowledgements page that names “researchers that have responsibly disclosed valid vulnerabilities” to the department.
When asked how he found a critical vulnerability, Nisarga replied, “I found this myself when browsing their site and by using some custom scripts.” Custom scripts usually refer to a programme that a researcher creates themselves to identify any major cybersecurity flaws in a system, instead of using any off-the-shelf tools.
The 19-year-old also clarified that he did not receive any payment for finding the flaw.
Nisarga says he also reported flaw to US Military
Apart from finding a flaw in the US DoJ website, Nisarga Adhikary, confirmed that he had already reported more such issues to US authorities, including the US military. “I found a vulnerability in US Department of Defense/US military system,” he explained. “I reported it and after validation, they found it was valid. Remediation is still under way though.” Remediation is a process where an organisation works on verifying and fixing a reported vulnerability.
On HackerOne, a widely used platform for reporting cybersecurity flaws, Nisarga Adhikary has received a “Thanks” from the US Department of Defense. Nisarga added that he had found more flaws that have also been reported to US authorities. He claimed that being “curious” led him to make such discoveries.
Nisarga Adhikary made waves in May this year after finding flaws in CBSE’s Online Submission of Marks (OSM) portal. At the time, he found that anyone could access answer sheets of students online without even needing to verify themselves. Following the CBSE incident, Nisarga got hired as an open-source intelligence (OSINT) and Threat Intelligence Engineer at C3iHub, IIT Kanpur.
– Ends
Source link
[ad_3]