I wish people wouldn't do shit like this on live systems like this one. Even the port scan could have had bad consequences (especially since this person did -A). By all means explore the interesting JSON object that was downloaded and yeah I'd worry about installing random stuff on my machine. I'm not talking about crashing the plane; I'm talking about crashing the IFE and me then having to sit through 10 hours of pe…
This mentality is where a lot of our current security problems come from, from IoT to critical infrastructure to ATMs, etc. Developers can't imagine someone would ever do anything nefarious on their "closed" network, so they don't bother doing more than cursory security. Then the internet shames anyone who tries to demonstrate how bad things really are.