A web and mobile security assessment report that lets security analysts evaluate the World Monitor application for vulnerabilities and recommend fixes.
National Technical Research Organisation (NTRO) · Software
Signing in saves it for your whole team — everyone on your invite link sees the same two entries. Anything you shortlisted while signed out comes with you.
Decomposed from what the description asks for. Nothing added.
Vulnerability Assessment
Identify and document security flaws across authentication, APIs, and data storage.
Proof of Concept
Demonstrate safe exploitation of the discovered vulnerabilities in a controlled environment.
Impact Analysis
Assess the potential business impact and assign a severity rating to each vulnerability.
Remediation Report
Provide practical mitigation strategies and steps to fix the identified risks.
Both columns are read off the brief's own wording. Nothing here is inferred from the ministry's name.
The jury will check that you find at least one valid vulnerability with documented evidence, clear risk explanation, and practical mitigation strategies. They will also verify that you followed all testing constraints and legal guidelines.
A jury can still ask about these. Decide them deliberately rather than by accident.
Generated from the brief's own wording and the competition's published rules — never from a guess about what this ministry prefers.
Whether the organisers will provide access to the actual World Monitor application or if teams must test a mock application?
The brief never answers this, so a panel will. Whatever you decide, say it the same way twice.
Specific tools or testing frameworks required?
The brief never answers this, so a panel will. Whatever you decide, say it the same way twice.
Has any part of this been shown at a previous event, hackathon or college project?
The guidelines are explicit: your solution must not have appeared in any previous event or programme, of any sort. A recycled project is what a team under time pressure reaches for.
The brief asks for vulnerability assessment. How would you build that?
Decoded from SIH26163 itself — Identify and document security flaws across authentication, APIs, and data storage. The brief asks for it by name.
Each one is quoted from a gap in the brief, not a guess about your team.
Needs data you may not get
The problem requires assessing the World Monitor application, which is a proprietary system that students may not have access to.
What the organisers attached, and what the brief assumes you can get.
Same organisation, same year. Reading two of theirs tells you more about what they care about than reading one.
Pick what you are about to do and copy the prompt. It carries the organisers' own wording, the constraints they never spell out, and an instruction not to invent requirements they never set.
Who has this problem, what already exists, and what you would have to find out.
The brief asks for proof of concept. How would you build that?
Decoded from SIH26163 itself — Demonstrate safe exploitation of the discovered vulnerabilities in a controlled environment. The brief asks for it by name.
The brief asks for impact analysis. How would you build that?
Decoded from SIH26163 itself — Assess the potential business impact and assign a severity rating to each vulnerability. The brief asks for it by name.
The brief asks for remediation report. How would you build that?
Decoded from SIH26163 itself — Provide practical mitigation strategies and steps to fix the identified risks. The brief asks for it by name.
Why not use what already exists? Name the closest thing to this that is already running.
A team that has not named the alternative themselves is answering this for the first time in the room.
Which single thing will you demonstrate end to end, start to finish, with nothing skipped?
Ours, not a rule: a narrow thing that fully works survives questioning better than a broad thing that half works. If nobody on the team can name it, that is the finding.
Show me this working: the jury will check that you find at least one valid vulnerability with documented evidence, clear risk explanation, and practical mitigation strategies.
This is the evaluator read for your problem statement, decoded from the brief's own wording.
Show me this working: they will also verify that you followed all testing constraints and legal guidelines.
This is the evaluator read for your problem statement, decoded from the brief's own wording.