Skip to Main Content
Talk Intermediate First Talk

Hacking India's Largest Exam System

Proposal status is Approved
Session Description

Hi, I want to give a talk on how I hacked India's largest exam system (CBSE). i'll walk through how i found the vulnerability, the technical mistakes that made exploitation possible, the disclosure process with cert-in and relevant stakeholders, and the challenges researchers face when reporting security flaws in public institutions.

the talk will also explore larger questions: why do critical systems continue to fail basic security reviews? what incentives exist for researchers to report vulnerabilities responsibly? and how can india build a healthier relationship between security researchers and public-sector organizations?


also would like to highlight my usage of open source tools and how critical infrastructure can benefit from FOSS.


A major focus of the session is demonstrating how accessible open source tooling can be used to evaluate the security of large-scale public infrastructure. Throughout the assessment I relied primarily on FOSS tools for reconnaissance, enumeration, testing and validation, highlighting how developers, students and organizations can build effective security workflows without expensive commercial software.


Link: https://ni5arga.com/blog/posts/hacking-cbse


i will walk the audience through various vulnerabilities like hardcoded master password in JS bundle, client-side OTP validation, missing route guards, bypassing auth with fake tokens into localStorage, password reset without old password verification, systemic IDOR across the entire API, SQL injection to RCE via xp_cmdshell, publicly listable S3 bucket, re-evaluation portal PII leak etc.



A lot of famous personalities and organizations like [Deedy Das](https://x.com/deedydas/status/2059131444346425354), [Satish Acharya](https://x.com/satishacharya/status/2059224148845768781), [Internet Freedom Foundation](https://x.com/internetfreedom/status/2059267815690088454) tweeted about it & this blog has been featured in news reports by multiple media outlets:

- [India Today](https://www.indiatoday.in/education-today/news/story/cbse-osm-portal-vulnerability-claims-surface-with-teens-detailed-blog-post-2917243-2026-05-26)

- [BBC News](https://www.bbc.com/news/articles/cy42e8eljpno)

- [NDTV](https://www.ndtv.com/education/cbse-osm-portal-had-critical-vulnerabilities-ethical-hacker-told-ndtv-he-alerted-board-months-earlier-11550090)

- [Times of India](https://timesofindia.indiatimes.com/education/news/cbse-faces-fresh-scrutiny-after-teen-researcher-alleges-critical-flaws-in-osm-portal-claims-class-12-marks-could-be-altered/articleshow/131330616.cms)

- [The Hindu BusinessLine](https://www.thehindubusinessline.com/news/education/government-should-take-cybersecurity-more-seriously-says-ethical-hacker-on-cbse-osm-flaws/article71024371.ece)

- [ThePrint](https://theprint.in/feature/19-student-hacked-cbses-osm-portal-vulnerabilities/2942305/)

- [News18](https://www.news18.com/viral/ex-google-engineer-calls-out-cbses-osm-portal-absolute-embarrassment-after-hacker-exposes-major-security-flaws-ws-l-10113830.html)

- [Hindustan Times](https://www.hindustantimes.com/htcity/leisure/this-teen-hacked-into-cbse-s-osm-portal-while-preparing-for-boards-says-this-is-just-a-hobby-101779875877374.html)

- [Financial Express](https://www.financialexpress.com/india-news/cbse-portal-very-easy-to-exploit-class-12-hacker-says-he-didnt-expect-amateur-vulnerabilities-exclusivenbsp/4252095/)

- [Times Now](https://www.timesnownews.com/education/exclusive-i-have-enough-proof-19-year-old-defends-claims-of-security-flaws-in-cbse-osm-portal-article-154408591)

- [CNBC TV18](https://www.cnbctv18.com/videos/education/cbse-on-screen-marking-controversy-hacker-security-claims-experts-divided-19914723.htm)

- [Moneycontrol](https://www.moneycontrol.com/technology/big-blunder-how-a-cbse-student-uncovered-a-security-flaw-in-a-national-exam-portal-article-13932552.html)

- [IFF Blog](https://internetfreedom.in/when-the-exam-itself-can-be-hacked-iff-writes-to-the-ministry-of-education-and-cert-in-on-the-cbse-on-screen-marking-disclosure/)

- [Medianama](https://www.medianama.com/2026/05/223-cert-in-vulnerabilities-cbse-online-marking-portal/)

- [Free Press Journal](https://www.freepressjournal.in/education/fpj-exclusive-meet-nisarga-the-19-year-old-ethical-hacker-who-flagged-alleged-cbse-portal-issues-in-february-2026)

- [Careers360](https://news.careers360.com/cbse-osm-portal-hacker-nisarga-adhikary-vulnerabilities-report-meaning-class-12-checking-result-onmark-co-in-cybersecurity)

Key Takeaways
  1. Learn how multiple individually exploitable flaws can combine into a complete attack chain.
  2. Understand common authentication, authorization and access control failures seen in production web applications.
  3. See practical applications of open source security tools for reconnaissance, testing and validation.
  4. Learn responsible vulnerability disclosure practices through a real-world case study involving CERT-In and public institutions.
  5. Take away concrete recommendations for building and reviewing secure applications, especially those handling sensitive public data and critical infrastructure.
  6. How the researcher <> government team reporting pipeline is broken.


References

Session Categories

Other

Which track are you applying for?

Security

Speakers

Nisarga Adhikary osint & threat intelligence engineer | c3ihub, iit kanpur

hi, i'm nisarga. i love to code & hack around.

i'm heavily interested in foss and i love cybersecurity ^_^

you can reach out to me at hello[at]nisarga.me and i can be found on github as @ni5arga

currently working as an osint & threat intelligence engineer @ iit kanpur. also, i’m a foss hack ‘26 winner and a technical contributor of the fossunited platform.

Nisarga Adhikary
https://ni5arga.com