Serious security issue with IRCTC website

The login form of the IRCTC web site is being submitted over HTTP in plain text. This is a very serious issue since both your user ID and password could be sniffed by someone. One thing that I observed was that they have a HTTPS server running and this server is capable of receiving login requests. I think it was a bug in the code that the developer gave the URL as HTTP instead of HTTPS.

How to overcome the issue? This is not a clean approach but works fine. You can copy and paste the URL "" in your browser. Replace the XXX with your user ID and YYY with your password.

I tried to send a feedback about this to the site admin or someone in charge. Pathetic ... I could not find any link/email address in that website to do this. Hopefully someone from IRCTC will read this blog and fix the issue.


Lavnish said...

hhmmmm nice finding buddy
sad but true... the government websites in country of techies ... guess thats why china is easily attacking indian government servers

more at

Mayank said...
This comment has been removed by the author.
Mayank said...

Good catch, and I found another serious security problem here:

PRK said...

Wait a minute! Do you say that they send the password as plain text in the URL?

pleh said...

Bhanu said...


Thanks for posting such a great information on India railways, but I think the main issue with IRCTC is the REFUND.
The refund policy is very bad, it may take more then 3-4 months even after many followups via emails and even send a written complaint to the GM of Indian Railways.. This is the only drawback, our Govt. should take some action and improve the refund policy so that customer do not face at least refund problem.