Hacking Mumbai's Metro ChatBot and APIs for FUN π€Έπ»ββοΈ
This blog post is regarding the time when I hacked into Mumbai's Metro Booking System from ChatBot to SQLi and breaking encryption.
BackStory



What Can Go Wrong?
Web Application Bad Practices
No Obfuscation on Client/Browser Side Source Code
Application Running in Debug Mode




Want to avoid such attacks in your apps?
How to avoid such mistakes?

Conclusion
PreviousGetting Shell Access to ADB Exposed Smart Devices π²πΊβNextRandom Object Referencing IDs Still Aren't Safe in APIs π₯
Last updated