Where is my Train : Tracking to Hacking !

Anil Tom
4 min readMar 17, 2020

Hello guys,

I am Anil Tom . Since it’s been a long time that I have written a blog, I thought of writing one today. Here, I am sharing some of my findings in one of the Google acquisition domains.

Where is my Train

“Where Is My Train” by Sigmoid Labs Pvt. Ltd., is a unique app for Trains, that displays live running status of trains and up-to-date schedules. The app can function offline without Internet or GPS. It is rated №1 travel app in India.

The Story

On December 10, 2018 Google acquired Sigmoid Labs Pvt Ltd, and Where Is My Train hence became a part of Google. According to the Google VRP rule, one can report vulnerabilities to Google after 6 months from acquisition date. I had always been fond of hunting in acquisition domains, so I did some recon on their website whereismytrain.in but could not find any vulnerabilities.

The Real Story begins here 😉

One day one of my friends travelling to Bangalore from Chennai wanted me to pick him from the station so he shared his train status through Where Is My Train application. When I saw…

--

--