Indian Railway has implemented the world's dumbest captcha
18 points| techaddict009 | 12 years ago
Just found how dumb the developers of the Indian Railway are.
Visit: http://www.indianrail.gov.in/pnr_Enq.html
And just select the captcha using Mouse. You will get what I actually mean.
[+] [-] codegeek|12 years ago|reply
[+] [-] namelezz|12 years ago|reply
[+] [-] nacs|12 years ago|reply
[+] [-] girish_h|12 years ago|reply
The Indian Railways runs one of the largest ecommerce sites in India - a site that has seen a consistent YoY growth over the last few years since its launched. Last year, they are believed to have earned a revenue of nearly 100M USD.
The guys who built their reservation system have very good engineering chops - in fact these systems hit peak load of about a million queries (every day) during 10 AM - 12 noon (IST) when users and reservation agents try to access the site irctc.co.in from browsers / mobile / reservation counters etc.
The "captcha" was not even in this page a month back. The "PNR Enquiry" for which this page is intended is a feature that can be accessed through SMS & also from the irctc website. This is possibly the least visited page in indianrail.gov.in
I have been an active user of both irctc.co.in & indianrail.gov.in over the last 7-8 years and have seen how these sites have grown.
[+] [-] phaus|12 years ago|reply
That being said, your defense of the site makes it sound even worse. Not only is the captcha horrible, but it took them almost all the way until 2014 to even implement one.
It is quite possible to have exceptionally good engineering chops and still be completely clueless when it comes to security.
I hope that the rest of the code powering this $100 million annual eCommerce traffic isn't as fundamentally flawed from a security aspect.
[+] [-] krapp|12 years ago|reply
[+] [-] user24|12 years ago|reply
They work because spammers often don't target specific sites but just run generic bots.
As soon as you throw something, even trivial, in the way, the spambots give up.
It wouldn't work for a high-value target of course.
If Indian Railway is a high-value target, then maybe they're just trying a 'dumb' solution and keeping an eye on spam to see if they need to put something cleverer in place.
[+] [-] techaddict009|12 years ago|reply
[+] [-] kwhitefoot|12 years ago|reply
It isn't just the dev who is incompetent, the problem is the system in which he is working.
[+] [-] krapp|12 years ago|reply
And viewing the source it looks like they have multiple head and body tags.
[+] [-] ahmedmzl|12 years ago|reply
The outsourcing provider is corrupt as a whole or the ministry didnt pay the outsourcing provider well.
The ministry gets a lot of money for the projects and find the cheapest and corrupt outsourcing provider they could find out in the market so that they spend and also get the money back through backdoors.
But do note that the developers of the main booking site irctc.co.in may not be the same as the developers of indianrail.gov.in
Security and Usability has not been a major concern for the government websites. If you want the worst designed bus booking website then take a look here: http://www.tnstc.in/TNSTCOnline/
[+] [-] korvenadi|12 years ago|reply
[+] [-] girish_h|12 years ago|reply
http://forbesindia.com/article/leaderhip-awards-2013/rakesh-...
[+] [-] dapatil|12 years ago|reply
[+] [-] mattwritescode|12 years ago|reply
[+] [-] factorialboy|12 years ago|reply
[+] [-] vasundhar|12 years ago|reply