Comment on Exposing Critical Vulnerabilities in CBSE's On-Screen Marking PortalComments−triceratops3moBig oof.A master password shipped in client-side JS.A fake OTP authentication process - "the server sends the OTP back...and the [client code] compares what you typed against that value locally before letting you through"And it gets worse after that.−crossroadsguy3moThese are features in our land of the brave.
Comments
Big oof.
A master password shipped in client-side JS.
A fake OTP authentication process - "the server sends the OTP back...and the [client code] compares what you typed against that value locally before letting you through"
And it gets worse after that.
These are features in our land of the brave.