Medianama mentioned about Indiatimes launching the womens portal iDiva last week. I checked out the site and as expected, I wasnt disappointed. Similar to other efforts from the Indiatimes factory, the portal is another lame attempt by Indiatimes to attract the online women audience. The site is simply horrible in all respects – design, content and engagement.
Even worse, the site has a major security flaw, which can be easily discovered and abused by a malicious hacker. For obvious reasons, I wont say what or how, but if you’re technically competent, you can easily figure it out.
In case you’re new to my blog, here’s another such finding I’d made for BigAdda.


if at all Indiatimes guys contact you, don’t reveal it for free!
ramesh,
seems that indiatimes folks either dont read this blog or dont believe what i say
no one’s contacted me yet about it — the more they keep this flaw unpatched, the more likely that they might end up making a fool of themselves..
Now there is no login possible without a user name and password…it says “The server http://www.idiva.com at Tomcat Manager Application requires a username and password.”