
Let's get startedβ¦
A few lines about IIIT Sricity;
The Indian Institute of Information Technology Sri City (IIIT Sri City) is an Institute of National Importance established in 2013 by the Ministry of Education, Government of India, in partnership with the Government of Andhra Pradesh and industry partners.
Let's re-create the scenario!!
I was searching for some good universities for my online Master's across the internetβ¦ and honestly, every review felt like a complaint box π
Then suddenly, I found this IIIT offering an online M.Tech program where GATE isn't mandatory ππ
Me: "Okay⦠now you have my attention."
So, I decided to apply for the M.Tech (Online) in Cyber Security at IIIT Sricity. While preparing to pay the admission and other feesβ¦
π¨ Intrusive thoughts activated
"What ifβ¦ I don't pay the feeβ¦ and still get in?" ππ
And just like thatβ¦
Curiosity = π―
Morals = bufferingβ¦ ππ
π» Let's move into the hack!!!
It started like every hacker movie scene:
- Burp Suite: β Open - Music: π§ ATM by Don Toliver on loop (Such a sooooothing one ποΈβ€οΈβπ₯) - Me: Feeling like Anonymousβ¦ ππ
β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β
I opened the admission form, entered the basic details, and clicked on "Proceed with Application."

I selected M.Tech in Cyber Security and started filling out the applicationβ¦
And broβ¦ this form is LONGGG π At one point I felt like I was writing UPSC exam. π

Halfway through, I even got a startup idea: "AI agent that auto-fills college applications" π
Alright alrightβ¦ back to the mission π
I uploaded all the required documents.

Finally, it asked me to select some compulsory subjects. I chose Penetration Testing (PT)β¦
The irony? I was literally doing penetration testing on the same website ππ

β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β
The payment moment πΈ
After submitting, I was redirected to the payment page where I could select different fee components. I selected everything (this was for the first semester only).
Looked at the total amount and went: "Hmm okayβ¦" "But do I really need to pay this?" π

I selected UPI and clicked PAY NOW.

β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β
Now things got interestingβ¦
I hadn't seen this payment gateway before, so I decided to explore its API documentation to understand how transactions work.
5 minutes later:
π§ Brain overloaded πEyes confused π slightly regretting life choices
So I took a breakβ¦ π«
After the break, I uploaded the document to ChatGPT and used this prompt:
"Break this document into bullet points without missing anything, in a way even a kid can understand."
β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β
Back to Burp π₯
With some clarity, I turned interception ON.
Cancelled the transaction and started analyzing requests like a crime investigatorπ΅οΈββοΈ
After a while, I found an interesting request containing parameters like:
response_code response_message error_description

At that moment, my brain said: π "These lookβ¦ editable." π
β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β
The experiment π οΈ
response_code = 1001 β 0 response_message = User declined the payment β Transaction Successful error_description = User declined the payment β Transaction Successful

Sent the modified request to the serverβ¦
Me: π Server: π€
β¦and thenβ¦
π₯ BOOOOOOM π₯

Result
The transaction was marked as successful β without actually completing the payment πΆ
During testing, I used GuerrillaMail as my email⦠and guess what?
π I even received a confirmation email πΊπ

System be like: "Payment successful sir π€R" Me "We both know that's not trueβ¦"
Notes:
This program is offered via CEP Digivarsity, which collaborates with several institutions such as IITs, IIMs, and IIITs.
It is worth noting that multiple institutions within this ecosystem seem to rely on the same payment gateway, which could have broader security implications if not properly addressed.
Disclaimer
This write-up is shared for knowledge transfer purposes only. Please don't try this on real systems without proper authorization.
(Yesβ¦ I'm looking at you ππ )
Shoutouts π
Special thanks to: Mayur Parmar, Hemant Patidar, Tarun Tandon, and Pavan Kumar Chinta
Final thoughts π
If I had put this much effort into actually paying the feeβ¦ I'd probably already have my degree by now ππ
Hope you enjoyed this write-up and learned something useful π Feel free to connect with me on LinkedIn for doubts or guidance.
Also, follow me on Medium for more content!
Thanks and byeβ¦ Happy hacking β let's hack together π¨βπ»π