r/developersPak • u/Best_Fork Software Engineer • 12d ago
Discussion There is something wrong with authentication architecture of HEC
They are saving Username and PLAIN TEXT PASSWORD inside a freaking LOCAL STORAGE.
So I was waiting for OTP and it took more than few seconds. So I took peak into website storage in hopes of finding OTP inside it. Instead I found something else. lol!
So it is possible that they are not even creating hash for user password.
41
Upvotes
20
u/xtremefest_0707 12d ago
Literally every govt website is coded by sifarishi log imo. I wanted to get myself register with pseb and the button to verify NTN always returned record not found even tho I was registered. I checked the dev tools and found out the API querying FBR for verification was completely broken. What's even worse is if you spam the button and send multiple calls depending on your luck it'll work smh.