Found CBSE portal vulnerabilities in 20 minutes, not afraid of FIR: Teen ethical hacker Nisarga Adhikary

 

New Delhi: Nineteen-year-old ethical hacker Nisarga Adhikary on Saturday spoke exclusively to IANS and alleged flaws in the CBSE portal, saying that it took him just 20 minutes to identify vulnerabilities.

This comes as fresh questions have emerged over the security of CBSE’s digital infrastructure after Adhikary alleged that answer sheets and question papers stored on an AWS bucket were publicly accessible online.

The claim comes amid ongoing scrutiny of CBSE’s On-Screen Marking (OSM) system and days after Adhikary’s disclosures about vulnerabilities in CBSE-linked digital platforms triggered a nationwide debate over the Board’s technology ecosystem.

Nisarga Adhikary also IANS spoke on various aspects of hacking, shortcomings in the CBSE portal, how he breached the security protocol, and several other issues.

Here is the full interview:

IANS: You are an ethical hacker. How did you come to know about the anomalies in the CBSE portal?

Nisarga Adhikary: So, I have an extensive background in security research and all. When CBSE launched its portal and issued its circulars and everything, I started digging deeper. I found the portal link, and it was open to the public.

After I found the portal link, I started examining what information I had about the portal and used it for reconnaissance. I found the front-end code for the site in JavaScript, but it was around 9,000 lines of code. So, I used some AI-assisted tools to go through it and found that it contained a master code password.

With that master password, you could access any evaluator’s account as long as you had the user ID. I managed to obtain some evaluators’ user IDs through Google searches and other sources. After that, I was able to log into those accounts.

I saw that I was able to access evaluator papers and generate grades. During that time, I also found 45 other vulnerabilities and reported them to CBSE, but they did not respond. The master password issue was one thing, but the other 44 vulnerabilities I reported were also still there.

I waited for three months until the results were declared and then went public with the information. After going public, I discovered additional vulnerabilities that gave me access to nearly 30 million scanned answer sheets, databases, and more. So, yeah, that’s it, I guess.

IANS: Were you able to breach the security protocol of the CBSE server to establish its vulnerability?

Nisarga Adhikary: I was able to breach the security protocol. They did not have a proper security protocol. It was not properly audited and all.

IANS: How did you breach the security protocol? How did you know that it was vulnerable to a cyberattack?

Nisarga Adhikary: It was pretty easy to identify the vulnerabilities. You could tell that there was not much experience involved in this field. I found the issues very quickly. It took me around 20 minutes.

Then I started testing and exploiting them in a good way, in an ethical manner, and reported everything.

IANS: CBSE has filed an FIR over attacks on its portal.

Nisarga Adhikary: Yeah, that’s different. They experienced a DDoS attack on their PBR portal. None of us, those who researched this issue with me carried out any DDoS attack because it’s a pretty pointless thing to do and it doesn’t work very well.

IANS: Are you worried about the FIR?

Nisarga Adhikary: No, I’m not. I’m in touch with some people connected with CBSE and some people from the cyber community. I’m not afraid at all.

IANS: What are your suggestions to CBSE, and what can it further improve?

Nisarga Adhikary: I think they should start taking security reports more seriously because this is not a one-off case with CERT or CBSE. They do not take security reports seriously and do not treat security with the importance it deserves.

In the agreement they had published publicly, it was mentioned that COEM needed to conduct audits and VAPT testing before taking the site into production. I’m pretty sure that didn’t happen. The site was taken into production without proper audits and security checks.

I hope those security checks are taken more seriously in the future. I also hope they seek more advice from experts and strengthen their overall cybersecurity practices.

–IANS

OSM controversy: Centre names Lokhande Sitaram as CBSE chairperson, Varun Bhardwaj secretary

New Delhi: In a major administrative reshuffle amid mounting controversy over the Central Board of Secondary Education's (CBSE) On-Screen Marking (OSM) system, the Central government on Tuesday appointed senior IAS...

Centre shunts out CBSE Chairman and Secretary over OSM row, probe panel set up

New Delhi: In a significant clampdown, the Central government on Tuesday transferred CBSE Chairman and Secretary and formed an inquiry committee to conduct a thorough probe into the On-Screen marking...

CBSE re-evaluation portal open till June 6; Aadhaar authentication must for additional security

New Delhi: The Central Board of Secondary Education (CBSE) on Tuesday activated its online portal for Class 12 students seeking verification of issues in scanned answer sheets and re-evaluation of...

Dharmendra Pradhan must resign immediately or PM should sack him: Digvijaya Singh

New Delhi:In an exclusive interview with IANS, veteran Congress leader, Rajya Sabha Member, and former Madhya Pradesh Chief Minister Digvijaya Singh launched a scathing attack on the ruling BJP-led government....

JEE Advanced 2026 results: Shubham Kumar from IIT Delhi zone secures AIR 1

New Delhi: The Indian Institute of Technology (IIT) Roorkee has announced the results of the Joint Entrance Examination (JEE) Advanced 2026, bringing an end to days of anticipation for engineering...

CBSE row: Rahul Gandhi interacts with Class 12 student Vedant, mocks ‘anti-national’ slur

New Delhi: Leader of Opposition in Lok Sabha Rahul Gandhi on Sunday continued his attack on the Union Education Ministry and the CBSE over Class 12 evaluation discrepancies by posting...

SC seeks Centre, CBSE response on plea challenging three-language mandate

New Delhi: The Supreme Court on Wednesday agreed to examine the validity of the Central Board of Secondary Education’s (CBSE) revised three-language formula mandating Class 9 students to study three...

Dharmendra Pradhan sends for IIT experts to resolve CBSE website glitches

New Delhi: Union Education Minister Dharmendra Pradhan has decided to rope in professors and technical experts from the Indian Institute of Technology Madras and IIT Kanpur to help the CBSE...

NSUI protests in Delhi over NEET paper leak; seeks Dharmendra Pradhan’s resignation, ban on NTA

New Delhi: The National Students' Union of India (NSUI), on Monday staged protests in Delhi and Uttar Pradesh over the alleged NEET paper leak issue, demanding the resignation of Union...

NEET case: CBI arrests NTA-appointed teacher from Pune for Biology paper leak

New Delhi: In the NEET UG 2026 exam scandal, the CBI has arrested an NTA-appointed senior Botany teacher from Pune, as she is suspected to be the co-mastermind behind the...

Rajasthan NEET leak: Dad pays Rs 10 lakh for paper, son scores only 107 marks

Jaipur: The investigation into the National Eligibility-cum-Entrance Test-Undergraduate 2026 paper leak case has taken a significant turn, with the Central Bureau of Investigation uncovering fresh details about the alleged racket...

NEET-2025 under scanner as five Rajasthan ‘average academic’ siblings clear exam

Jaipur: Was the NEET-UG 2025 examination really free and fair? Did a paper leak racket continue operating even after last year's controversy? And how did five academically average siblings suddenly...

Read Previous

Kota seer Devanand Maharaj stabbed to death inside monastery; body found in pool of blood

Read Next

US shoots down Iranian drones, strikes radar sites

WP2Social Auto Publish Powered By : XYZScripts.com