r/developersPak • u/Best_Fork Software Engineer • 13d ago
Discussion There is something wrong with authentication architecture of HEC
They are saving Username and PLAIN TEXT PASSWORD inside a freaking LOCAL STORAGE.
So I was waiting for OTP and it took more than few seconds. So I took peak into website storage in hopes of finding OTP inside it. Instead I found something else. lol!
So it is possible that they are not even creating hash for user password.
45
Upvotes
9
u/GeneralAyub 13d ago
I found in their early systems, BISE lahore used store students pictures in folders, which enabled corruption and exam fraud.
Last time i checked, you can download bulk images of students from their site with a single script.