Last Friday, security researcher Rajshekhar Rajaharia was at home, surfing the web. He landed on the website of Justdial, a provider of local search for different services.
Rajaharia works with several law enforcement agencies to solve cyber security cases. He immediately realised something was wrong. He found the APIs (application programme interfaces) of the tablet version of Justdial’s website was exposed — this made the personal information of 100-odd million users ‘publicly accessible’.
This included information such as names, e-mail IDs, mobile numbers, genders, dates of birth, addresses, photos and occupations of the users. “Anyone having access to it (APIs) can grab all the data,” Rajaharia told Business Standard. “I immediately tried to reach the firm to alert them, but didn’t get a response immediately.”
TO READ THE FULL STORY, SUBSCRIBE NOW NOW AT JUST RS 249 A MONTH.
Subscribe To Insights
Key stories on business-standard.com are available to premium subscribers only.Already a BS Premium subscriber? Log in NOW
Or