GroovyJellybean
GroovyJellybean

I hacked my College ERP ...

I am an app developer. Actually I get angry very quickly. Whenever I get angry I either ruin my work or other people's work.

I requested to remove my fine in my college. The fine was shown without any reason and ERP admin said you have to pay.

Bug hunting is my hobby. So I hacked the whole ERP admin panel within 2 hours and removed my fine.

8mo ago
Jobs
One interview, 1000+ job opportunities
Take a 10-min AI interview to qualify for numerous real jobs auto-matched to your profile 🔑
+322 new users this month
JazzyMuffin
JazzyMuffin
TCS8mo

Good job, remember it's not the kind people who rule but the smart one, u did the right thing. Just make sure u r smart enough not to get caught, hence make sure not only remove your fine but other people's fines also, to make it look like some global software glitch or error

GroovyJellybean
GroovyJellybean

Yes I have removed my friends also

ZoomyJellybean
ZoomyJellybean
TCS8mo

Ushould join in surity domain

GroovyJellybean
GroovyJellybean

I am using that concept during Application development for increasing security.

ZoomyJellybean
ZoomyJellybean
TCS8mo

Better to move security domain instead of application development

SleepyQuokka
SleepyQuokka

Can you share how you did it ? What was your thought process when you were finding the vulnerability ? When did you find it how you gained access?

GroovyJellybean
GroovyJellybean

In starting the College provide us id and default password.. after that some time for only attendance . I have looked for one teacher id then using automation I have found 1 teacher id which is accessible and that teacher is not working there anymore . That's a red flag after that i can access the whole teacher's information and data of 25000+ students data . When I have recently gone to the fees counter I have seen the accountant id after that I just tried some default password on email . BOOM!! using that email I have forgot the password 🔑

FloatingNoodle
FloatingNoodle

Really? You hacked into the db? Lel

GroovyJellybean
GroovyJellybean

Yes .. just to clear my fine 😁 Now I am increasing my attendance without even going to college

MagicalNarwhal
MagicalNarwhal

hey ashish can u help me with mine

MagicalCupcake
MagicalCupcake

It's equivalent ro stealing and unethical.

Discover more
Curated from across