Community › Forums › Legal Advice India › Found a vulnerability in a government portal, is it ok to mention the name of the organization?
- This topic has 13 replies, 8 voices, and was last updated 1 year, 4 months ago by
User_82ee2b71.
Viewing 7 reply threads
-
AuthorPosts
-
-
UUser_82ee2b71
PARTICIPANT
February 7, 2025 at 2:59 pmI recently discovered a critical vulnerability on a government website that was exposing sensitive user data, including mobile numbers, home addresses, names, and billing details. If exploited by a malicious actor, this could have led to a significant data breach.After identifying the issue, I responsibly reported it, and the vulnerability has since been fixed.
My question is: **Am I allowed to mention the name of the organization and the type of data that was exposed in a LinkedIn post to showcase my cybersecurity skills?**
I want to ensure that I am not in any legal trouble. Any insights from the community on responsible disclosure practices would be helpful.
-
LLuckybear8410
PARTICIPANT
February 7, 2025 at 3:13 pmI wouldnโt post it on LinkedIn-
UUser_82ee2b71
OP
February 7, 2025 at 3:21 pmthanx for your opinion
-
-
UUser_c75747a7
PARTICIPANT
February 7, 2025 at 3:14 pmI would first contact the department whoโs website has issues.-
UUser_82ee2b71
OP
February 7, 2025 at 3:21 pmdepartment will never allow neither resolve the issue, I took help of cert-in organization to fix this issue.
-
-
UUser_2172e2f2
PARTICIPANT
February 7, 2025 at 3:20 pmAsk them for bounty-
UUser_82ee2b71
OP
February 7, 2025 at 3:23 pmno government organisations paya bounty :/
-
-
UUser_0cc26242
PARTICIPANT
February 7, 2025 at 3:48 pmIf it doesn’t get viral, then no point in posting it. If it does there might be other issues. If I would have been in your shoes then I would mention this in an interview as a cool story kind of thing. -
UUser_62110ee9
PARTICIPANT
February 7, 2025 at 3:50 pmno option but to report it on certin. maybe tweet or post on linkedin after the issues been resolved if you really really want to.-
UUser_82ee2b71
OP
February 7, 2025 at 3:54 pmyes, issue has been fixed. Just wanted to know if I can mention that government organisation.for example:
I’ve seen many people mentioning their findings of irctc in twitter or news channel
-
-
MMightykomal1002
PARTICIPANT
February 7, 2025 at 4:32 pm2lpa engineer hits again ๐คฃ-
UUser_82ee2b71
OP
February 7, 2025 at 4:33 pmHi 50lpa can you also hit?
-
-
UUser_94f82857
PARTICIPANT
February 7, 2025 at 4:59 pmGet a written approval from the organisation before you disclose it.-
UUser_82ee2b71
OP
February 7, 2025 at 5:00 pmThanks
-
-
-
AuthorPosts
Viewing 7 reply threads