Are you a victim of VAS activation without your concern have you ever been charged for the VAS service what you have never used ?Do you know it can be a mischief played on you by your friend.

Also Read

  • Make Telecom Talk My Trusted Source
  • Source of Google
  • Source of Google

A avid TT reader Gaurav Sharma who hails from Sangrur in Punjab has come up with a so called major bug in RCOM portal which exposes Rcom web security level the bug shows any user in a public domain can activate and deactivate any VAS service of Reliance Mobile

So what is the bug all about ? To make this bug work on should be online via Rcom apn which is RCOMNET once connected you should open a unique url (Link not attached on purpose).

The url consist of appID , reqID and mdn  this is where the bug is appID stands for the VAS service like for 101 it stands for music station and it differ from one VAS service to another, reqID is used to subscriber and unsubscribe a service take for example reqID=1 is use to activate the service and reqID=2 is use to deactivate the service and mdn is the mobile number of user.

While testing we tested the same bug on our very own RCOM  Mobile Number 90223030** and we were able to activate Reliance Mobile music station service remotely.