<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://indianpedia.org/index.php?action=history&amp;feed=atom&amp;title=Ehraz_Ahmed</id>
	<title>Ehraz Ahmed - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://indianpedia.org/index.php?action=history&amp;feed=atom&amp;title=Ehraz_Ahmed"/>
	<link rel="alternate" type="text/html" href="https://indianpedia.org/index.php?title=Ehraz_Ahmed&amp;action=history"/>
	<updated>2026-07-30T23:28:41Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.45.4</generator>
	<entry>
		<id>https://indianpedia.org/index.php?title=Ehraz_Ahmed&amp;diff=104500&amp;oldid=prev</id>
		<title>2401:4900:4BC3:941F:EE63:FE5B:17F0:DE6 at 22:07, 4 July 2021</title>
		<link rel="alternate" type="text/html" href="https://indianpedia.org/index.php?title=Ehraz_Ahmed&amp;diff=104500&amp;oldid=prev"/>
		<updated>2021-07-04T22:07:05Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{short description|Indian Ethical hacker}}&lt;br /&gt;
{{Infobox person&lt;br /&gt;
| name               = Ehraz Ahmed&lt;br /&gt;
| birth_date         = {{birth date and age|1996|07|26}}&lt;br /&gt;
| birth_place        = [[Mysuru]], [[Karnataka]], India.&lt;br /&gt;
| education          = [[P.E.S. College of Engineering]]&lt;br /&gt;
| occupation         = {{hlist|Security Researcher|fintech professional |entrepreneur}}&lt;br /&gt;
}}&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Ehraz Ahmed&amp;#039;&amp;#039;&amp;#039; (&amp;#039;&amp;#039;&amp;#039;{{Lang-hi|{{nq| एहराज़ अहमद}}}}&amp;#039;&amp;#039;&amp;#039;, born July 26, 1996) is an [[Indian people|Indian]] [[Entrepreneurship|Entrepreneur]], [[Financial analyst|FinTech professional]] and [[Security hacker|Security Researcher]].&amp;lt;ref&amp;gt;{{Cite web|last=جمعة|first=عوض|title=منها مايكروسوفت وآبل.. تعرف على الهاكر الهندي الذي أنقذ آلاف الشركات من القراصنة|url=https://www.aljazeera.net/news/scienceandtechnology/2021/6/20/هاكر-أخلاقي-تعرف-على-روبن-هود-الهند|url-status=live|access-date=2021-06-22|website=[[Al Jazeera]]|language=ar}}&amp;lt;/ref&amp;gt; He is one of the most renowned [[White hat (computer security)|ethical hackers]] in [[India]]. He is known for securing the [[Personal data|userdata]] of over 1 billion users by detecting [[Exploit (computer security)|security flaws]] in companies like [[Facebook]], [[Justdial]], [[Bharti Airtel|Airtel]] and [[Truecaller]].&amp;lt;ref name=&amp;quot;:2&amp;quot;&amp;gt;{{Cite web|date=2021-03-25|title=Meet Ehraz Ahmed, the white hat hacker who is helping Facebook, Google and Airtel stay secure|url=https://www.cnbctv18.com/technology/meet-ehraz-ahmed-the-white-hat-hacker-who-is-helping-facebook-google-and-airtel-stay-secure-8722211.htm|url-status=live|access-date=2021-06-15|website=[[CNBC TV18]]|language=en}}&amp;lt;/ref&amp;gt; He is the CEO and founder of Voxy Wealth Management and Aspirehive.&amp;lt;ref name=&amp;quot;:1&amp;quot;&amp;gt;{{Cite web|last=Bakshi|first=Asmita|date=2020-09-05|title=Lounge Heroes {{!}} Ehraz Ahmed: The protector of your privacy|url=https://www.livemint.com/mint-lounge/features/lounge-heroes-on-a-mission-to-ensure-data-remains-secure-11599196913906.html|url-status=live|access-date=2021-06-15|website=[[Mint (newspaper)|Mint]]|language=en}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Personal life ==&lt;br /&gt;
Ahmed was born in [[Mysore|Mysuru]], [[Karnataka]], [[India]], on July 26, 1996. In 2016, He joined [[P.E.S. College of Engineering|PES College of Engineering]] to pursue [[Bachelor of Engineering|B.E.]] in [[Computer science|Computer Science]] and dropped out in 2017 to launch his [[Internet security|Web Security]] company.&amp;lt;ref name=&amp;quot;:1&amp;quot; /&amp;gt; During his 10th grade, his father survived a [[heart attack]], and later, in 2019, he underwent [[Open-Heart Surgery|open-heart surgery]].&amp;lt;ref&amp;gt;{{Cite web|date=2020-11-30|title=Airtel to Truecaller: 24-YO Has Safeguarded the Data of 700 Million App Users|url=https://www.thebetterindia.com/243614/airtel-truecaller-justdial-protect-user-data-security-mysuru-karnataka-google-facebook-ehraz-ahmed-nor41/|url-status=live|access-date=2021-06-15|website=|publisher=[[The Better India]]|language=en-US}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Career ==&lt;br /&gt;
At the age of 14, Ahmed began his entrepreneurial career by selling [[Game server|Game hosting servers]] and started a company that later provided [[Web hosting service|web hosting]]. At 16, Ahmed was listed to 50 [[Bug bounty program|Security Researcher&amp;#039;s Hall of fame]] for detecting security flaws in companies like [[Facebook]], [[Twitter]], [[Apple Inc.|Apple]], and [[Microsoft]].&amp;lt;ref&amp;gt;{{Cite web|last=Fatima|first=Nikhat|date=2021-02-16|title=Meet Ehraz Ahmed, a Bengaluru based ethical hacker safeguarding data of 700 million app users|url=http://twocircles.net/2021feb16/441036.html|url-status=live|access-date=2021-06-15|website=|publisher=[[Two Circles]]|language=en-US}}&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;{{Cite web|last=Pioneer|first=The|title=Meet the eh-thical hacker|url=https://www.dailypioneer.com/2021/sunday-edition/meet-the-eh-thical-hacker.html|url-status=live|access-date=2021-06-15|website=[[The Pioneer (India)]]|language=en}}&amp;lt;/ref&amp;gt; In 2016, Ahmed started his [[Financial technology|FinTech]] company, Voxy Wealth Management. In 2017, he started Aspirehive, a web security company. In 2019, he safeguarded the sensitive [[Personal data|user data]] of over one billion users by finding [[Vulnerability (computing)|security flaws]] in companies like [[Bharti Airtel|Airtel]], [[Justdial]], [[Truecaller]] &amp;amp; [[SonyLIV|SonyLiv]].&amp;lt;ref name=&amp;quot;:2&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Truecaller controversy ===&lt;br /&gt;
On 21 August 2019, Ahmed found a [[Vulnerability (computing)|security flaw]] in [[Truecaller]]&amp;#039;s login process that could have allowed attackers to access virtually any [[Truecaller]] account. Ahmed demonstrated the flaw to [[Republic TV|Republic World]] by sending out a few messages on Truecaller Chat from an invalid phone number that used to be Airtel&amp;#039;s official prepaid customer care number. Later, In an email statement to [[Republic TV|Republic World]], [[Truecaller]] said it investigated the issue with the security researcher and the flaw was not reproducible.&amp;lt;ref&amp;gt;{{Cite web|last=World|first=Republic|title=Security researcher discovers major flaw in Truecaller&amp;#039;s login process|url=https://www.republicworld.com/technology-news/apps/security-researcher-discovers-major-flaw-in-truecallers-login-process.html|url-status=live|access-date=2021-06-11|website=[[Republic TV|Republic World]]|language=en}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Justdial security flaw ===&lt;br /&gt;
On 10 October 2019, Ahmed found a [[Exploit (computer security)|security flaw]] in [[Justdial]]&amp;#039;s Register [[Application programming interface|API]] that exposed over 156 million accounts. The flaw allowed [[hacker]]s to log into any [[Justdial]] account by placing the phone number in the username parameter. By doing so, this granted the [[hacker]] access to any person&amp;#039;s Justdial account.&amp;lt;ref name=&amp;quot;Exclusive: Justdial security flaw may allow hackers to breach pay accounts of 156 million users&amp;quot;&amp;gt;{{cite web|title=Exclusive: Justdial security flaw may allow hackers to breach pay accounts of 156 million users|url=https://www.moneycontrol.com/news/trends/exclusive-just-dial-security-flaw-may-allow-hackers-to-breach-pay-accounts-of-156-million-users-4514931.html|url-status=live|website=[[Moneycontrol.com|Money Control]]|accessdate=1 December 2019}}&amp;lt;/ref&amp;gt; In a filing to the [[Bombay Stock Exchange]], [[Justdial]] acknowledged the vulnerability and said it could potentially be accessed by an expert hacker to gather basic user information. The company said the flaw had been fixed and that there was no theft of data or financial loss to the company, its users or customers.&amp;lt;ref&amp;gt;{{Cite news|title=JustDial fixes bug that allowed hackers access|work=The Economic Times|url=https://economictimes.indiatimes.com/tech/internet/justdial-fixes-bug-that-allowed-hackers-access/articleshow/71533334.cms|access-date=2021-06-15}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Airtel security flaw ===&lt;br /&gt;
On 7 December 2019, Ahmed detected a [[Exploit (computer security)|security flaw]] in [[Bharti Airtel|Airtel]]&amp;#039;s Mobile Application [[Application programming interface|API]] that exposed personal details of more than 325 million Indian users. The [[Vulnerability (computing)|vulnerability]] could have allowed [[hacker]]s to access the [[personal data]] of users by just using their mobile number. The security flaw in the [[Bharti Airtel|Airtel]] app could have provided access to information such as the name of users, emails, birthday, residential address, and the [[International Mobile Equipment Identity|IMEI number]] of the device on which the app was installed.&amp;lt;ref name=&amp;quot;:02&amp;quot;&amp;gt;{{Cite web|title=Airtel Admits Flaw in Mobile App Could&amp;#039;ve Exposed Data of Millions|url=https://gadgets.ndtv.com/telecom/news/airtel-mobile-app-api-security-flaw-discovered-customer-data-risk-patched-india-2144835|url-status=live|access-date=2019-12-18|website= [[NDTV|NDTV Gadgets 360]]|language=en}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Bharti Airtel|Airtel]] acknowledged the issue and fixed the flaw after it was notified about it by [[BBC News|BBC]]. &amp;quot;There was a technical issue in one of our testing APIs, which was addressed as soon as it was brought to our notice&amp;quot;, an [[Bharti Airtel|Airtel]] [[spokesperson]] was quoted as saying by [[BBC News|BBC]].&amp;lt;ref&amp;gt;{{Cite news|last=Nazmi|first=Shadab|date=2019-12-07|title=India phone giant fixes bug &amp;#039;affecting 300m users&amp;#039;|language=en-GB|work=[[BBC News]]|url=https://www.bbc.com/news/world-asia-india-50641608|access-date=2019-12-18}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
On 13 December 2019, [[Business Insider]] listed Airtel&amp;#039;s [[Vulnerability (computing)|Security Flaw]] as one of the Biggest Data Breaches Of 2019.&amp;lt;ref&amp;gt;{{Cite web|title=Airtel&amp;#039;s security flaw only took 15 minutes to find|url=https://www.businessinsider.in/slideshows/biggest-data-breaches-of-2019/airtels-security-flaw-only-took-15-minutes-to-find/slideshow/72465910.cms|url-status=live|access-date=2019-12-18|website=[[Business Insider]]}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Web Application for Covid detection ===&lt;br /&gt;
On 19 October 2020, Ahmed developed a [[Web application|Web Application]] to determine [[COVID-19|Covid]] infection in [[chest radiograph]]s. The [[Machine learning|machine learning model]] was trained on the [[data set]] of 7,084 [[Chest radiograph|chest X-ray]] images of patients infected with [[COVID-19]] and [[pneumonia]].&amp;lt;ref&amp;gt;{{Cite web|last1=Oct 19|first1=Shrinivasa M. / TNN / Updated|last2=2020|last3=Ist|first3=17:20|title=Karnataka: Mysuru-based researcher develops innovative X-ray scanner to determine Covid infection {{!}} Mysuru News - Times of India|url=https://timesofindia.indiatimes.com/city/mysuru/karnataka-mysuru-based-researcher-develops-innovative-x-ray-scanner-to-determine-covid-infection/articleshow/78748454.cms|url-status=live|access-date=2021-06-15|website=[[The Times of India]]|language=en}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Recent researches ==&lt;br /&gt;
On 12 November 2019, Ahmed detected a digital flaw in the [[Bounce Scooter Share|Bounceshare]] app. Exploiting one of its [[Application programming interface|Internal Application Programming Interface (API)]] allowed hackers to log into any [[Bounce Scooter Share|Bounceshare]] account, bypassing the users’ phone number into the request. In response, it returned with the Access Token and RiderId. This Access Token can then be used to access any [[Bounce Scooter Share|Bounceshare]] account.&amp;lt;ref&amp;gt;{{Cite web|title=Exclusive: Flaw Left User Data Of 2 Million Bounceshare Customers Vulnerable To Hack|url=https://www.moneycontrol.com/news/technology/exclusive-flaw-left-user-data-of-2-million-bounceshare-customers-vulnerable-to-hack-4629331.html|url-status=live|access-date=2021-06-15|website=[[Moneycontrol.com|Money Control]]}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A few days later, On 18 November 2019, Ahmed detected an [[Application programming interface|API]] flaw in [[Nykaa]] Fashion&amp;#039;s internal systems that allowed a potential attacker to log in to any user account.&amp;lt;ref name=&amp;quot;Nykaa fixes a data security bug&amp;quot;&amp;gt;{{cite news|title=Nykaa fixes a data security bug|url=https://economictimes.indiatimes.com/small-biz/startups/newsbuzz/nykaa-fixes-a-data-security-bug/articleshow/72101784.cms|url-status=live|website=[[The Economic Times]]|accessdate=3 December 2019|last1=Kar|first1=Sanghamitra}}&amp;lt;/ref&amp;gt;&amp;lt;ref name=&amp;quot;Flaws in code put customer data of four consumer internet platforms at risk&amp;quot;&amp;gt;{{cite web|title=Flaws in code put customer data of four consumer internet platforms at risk|url=https://www.livemint.com/companies/start-ups/security-expert-pokes-holes-in-consumer-internet-platforms-11573963913626.html|url-status=live|website=[[Mint (newspaper)|Mint]]|date=17 November 2019|accessdate=3 December 2019}}&amp;lt;/ref&amp;gt; And on 23 November 2019, Ahmed discovered a [[Exploit (computer security)|security flaw]] in [[Truecaller]] that exposed user data as well as system and location information. [[Truecaller]] confirmed this information in a statement to [[Gadgets 360|Gadgets360]] and fixed the flaw.&amp;lt;ref&amp;gt;{{Cite web|title=Truecaller Flaw Allowed Attackers Harvest IP Addresses, Other User Data|url=https://gadgets.ndtv.com/apps/news/truecaller-api-flaw-user-profile-picture-url-avatarurl-attack-ip-address-2137354|url-status=live|access-date=2021-06-15|website= [[NDTV|NDTV Gadgets 360]]|language=en}}&amp;lt;/ref&amp;gt; The security vulnerability allowed [[hacker]]s to inject malicious links as URLs for the profile picture, exploiting anyone who would view the attacker&amp;#039;s profile by search or through a pop-up. This [[Application programming interface|API]] flaw would, in turn, allow the [[hacker]]s to steal IP addresses along with other user data.&amp;lt;ref name=&amp;quot;:0&amp;quot;&amp;gt;{{Cite web|last1=weeks|first1=Natasha Mathur 3|last2=Day|first2=1|date=2019-11-26|title=Researcher Discovered A Critical Security Flaw In The Truecaller App|url=https://in.mashable.com/tech/8839/researcher-discovered-a-critical-security-flaw-in-the-truecaller-app|url-status=live|access-date=2019-12-18|website=[[Mashable|Mashable India]]|language=en-in}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A few weeks later, On 20 December 2019, Ahmed found a [[Vulnerability (computing)|security flaw]] in [[Sony Liv|SonyLiv]] that allowed [[Hacker|attackers]] to fetch sensitive user information such as profile picture, email address, date of birth, name, and phone number of its registered users.&amp;lt;ref&amp;gt;{{Cite web|title=SonyLIV Fixes Flaw That Could Allow Attackers to Fetch User Information|url=https://gadgets.ndtv.com/apps/news/sonyliv-api-flaw-fix-user-information-attack-app-update-2151958|url-status=live|access-date=2019-12-20|website= [[NDTV|NDTV Gadgets 360]]|language=en}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
On 23 October 2020, Ahmed found a [[Vulnerability (computing)|security flaw]] in Thrillophilia&amp;#039;s API exposing sensitive user data of 2 million registered users. The flaw allowed [[hacker]]s to fetch sensitive [[Personal data|user data]] of any registered user bypassing their email address in the cURL request.&amp;lt;ref&amp;gt;{{Cite web|title=Security lapse puts data of Thrillophilia&amp;#039;s registered users at risk|url=https://www.cnbctv18.com/travel/security-lapse-puts-data-of-thrillophilias-registered-users-at-risk-7252261.htm|url-status=live|access-date=2021-06-15|website=[[CNBC TV18]]|language=en-US}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
On 16 June 2021, Ahmed found a [[Vulnerability (computing)|security flaw]] in Lazypay that allowed hackers to obtain user data such as their full name, gender, date of birth, and phone number.&amp;lt;ref&amp;gt;{{Cite web|title=LazyPay Users&amp;#039; Sensitive Data Could Have Been Revealed by a Security Flaw|url=https://gadgets.ndtv.com/internet/news/lazypay-security-flaw-vulnerability-fix-payu-2465220|access-date=2021-06-22|website=NDTV Gadgets 360|language=en}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
{{Reflist}}&lt;br /&gt;
&lt;br /&gt;
{{DEFAULTSORT:Ahmed, Ehraz}}&lt;br /&gt;
[[Category:Hackers]]&lt;br /&gt;
[[Category:Living people]]&lt;br /&gt;
[[Category:1996 births]]&lt;br /&gt;
[[Category:Indian businesspeople]]&lt;br /&gt;
[[Category:Businesspeople from Mysore]]&lt;/div&gt;</summary>
		<author><name>2401:4900:4BC3:941F:EE63:FE5B:17F0:DE6</name></author>
	</entry>
</feed>