A student who was denied admission to the Indian Institute of Technology Kanpur's newly launched Bachelor of Cyber Security program hacked the official websites of IIT Kanpur and IIT Madras. The student left a message on IIT Kanpur's site stating, "Site is hacked. All I need is just a fair chance." This incident surfaced earlier this week when the student publicly claimed responsibility for breaching both institutes' websites after being rejected from the undergraduate cybersecurity course.
Background on the Cybersecurity Program and Admission Process
IIT Kanpur recently introduced a Bachelor of Cyber Security program aimed at training students in the growing field of cybersecurity. Admission to this program involves a multi-step process, including an application, document submission, fee payment, and participation in a hackathon designed to assess candidates' technical skills.
The student in question completed all required steps, including paying fees and submitting proof of prior cybersecurity work. However, he was not shortlisted for the hackathon stage, which is a critical part of the selection process. IIT Kanpur's director, Manindra Agrawal, explained that the student was excluded due to a lack of prior cybersecurity experience, which is essential for success in the program.
Details of the Website Breach and Institute Response
- The student accessed certain sections of IIT Kanpur and IIT Madras official websites without authorization.
- He shared screenshots of the breach on social media platforms like X and Reddit, emphasizing that his intent was to demonstrate his skills rather than cause harm.
- IIT Kanpur initially considered filing a formal police complaint but chose to verify the student's claims and evaluate his technical abilities before proceeding.
- Senior faculty and engineers at IIT Kanpur have been assigned to counsel the student on the illegality of unauthorized system access and to discourage any future attempts.
- The institute has a history of encouraging young cybersecurity talent, having previously hired a youth who exposed vulnerabilities in the Central Board of Secondary Education’s online marking portal.
What IIT Kanpur’s Decision Means for the Student and Cybersecurity Education
Since the current admission cycle has ended, IIT Kanpur cannot admit the student immediately. However, the institute plans to invite him for a technical assessment. If he demonstrates sufficient competence, he will be offered an opportunity to join the program in the next admission cycle. This approach reflects IIT Kanpur’s willingness to recognize talent beyond formal admission criteria and to support emerging cybersecurity professionals.
The incident also highlights the challenges educational institutions face in balancing security with openness to new talent. By choosing to assess the student’s skills rather than pursue legal action, IIT Kanpur is sending a message about the value of ethical hacking and responsible disclosure when handled appropriately.
Frequently Asked Questions
Q: Why was the student denied admission to IIT Kanpur’s cybersecurity program?
A: The student was not shortlisted for the hackathon stage of the admission process because he lacked prior experience in cybersecurity, which is a key requirement for the program.
Q: What actions did IIT Kanpur take after the website hack?
A: IIT Kanpur verified the student's claims, involved senior faculty to counsel him on the illegality of unauthorized access, and decided to assess his technical skills before considering any legal action.
Q: Will the student get another chance to join the program?
A: Yes, IIT Kanpur plans to invite the student for a technical test, and if he proves his abilities, he may be admitted in the next admission cycle.
