Live data from Hacker News

Hacking on a plane: Leaking data of millions and taking over any account

rez0.blog

21–30 of 91 posts

Re: Hacking on a plane: Leaking data of millions and taking over any account

#22

Earlier quoted context omitted.

This has to do with being on a public network (an airplane), does it not? Maybe your outrage is over-the-top.

Absolutely not. This has to do with how accounts for that network are managed. Even if you use a VPN you will still have an account there and your data were at risk to this vulnerability.

> The impact of these two bugs was signifcant. It was access to first name, last name, address, and email of the user as well as last 4 digits, expiration date, billing name, and address of the credit cards.

Assuming you're a black hat exploiting this bug, what can you do, if the target is using a VPN?

I don't know what "address of the credit cards" means, but let's assume it's the target's home address.

You don't get their credit card number or security code. You don't get access information on any of their web accounts. Correct?

If you spy on their internet activity during the flight, it's all encrypted. You won't learn anything.

However, you do have the ability to change their password, so they can't get into their own account anymore.

You could also bill all your own activity to their account. I don't know if you can bill other things to the account.

You could get access to whatever data was stored in that account. I don't know what that would be, other than when & how much you used it in the past.

Is this a complete summary of the potential damage?

Since there's no Reply button for the two answers to this:

Neither of them answer my last question ("is this a complete summary..."). Should I assume it is?

And I never said "oh but the data leak isn't really that bad of a vulnerability" -- you did.

Re: Hacking on a plane: Leaking data of millions and taking over any account

#23
post #2

I's kind of incredible how common this specific kind of vulnerability is. I have to assume the developers of these systems just hope that no one will notice?

These types of fails are generally due to incompetence, in my experience.

This one is 100% due to incompetence. There was no attempt at anything resembling security.

Re: Hacking on a plane: Leaking data of millions and taking over any account

#24
post #2

I's kind of incredible how common this specific kind of vulnerability is. I have to assume the developers of these systems just hope that no one will notice?

No, the developers simply don't realize that there is a vulnerability, even though they have the required knowledge because they look at the code with the "how do I implement this feature" mindset (which is their job), not a "how could this be abused" mindset.

Re: Hacking on a plane: Leaking data of millions and taking over any account

#25

Earlier quoted context omitted.

so many "pentests" are: * run scanner * print out report not a lot of deep diving

Yep. It's a shame. I once (long ago :)) alerted our CTO to an ongoing attack in production after seeing some obviously attack-oriented requests coming in and hitting our gateway. It became a pretty high-visibility incident for about 20 minutes until a manager spoke up that his "pen test" was being performed. Looking into the "testing" that was occurring they were attempting to scan for decade-old PHP bugs in a set of…

So, to try and add some value to this conversation vs just reporting a personal anecdote... Do people here have suggestions for actually-good white-hat companies?

Can you recommend companies that you've personally worked with who employ knowledgeable security engineers (hackers) to perform real penetration tests and conduct valuable security scans resulting in value-add reports your engineering team can work with?

Not looking for naming and shaming...but rather "Who doesn't suck at doing this?".

Re: Hacking on a plane: Leaking data of millions and taking over any account

#26
post #10

How is something like this not picked up in a pen test? Can only assume there never has been..

Probably because a lot of pen testing is security theatre.

More likely: the pentest report that was made because it was mandatory ended up in someone's drawer.

Re: Hacking on a plane: Leaking data of millions and taking over any account

#27

Earlier quoted context omitted.

Absolutely not. This has to do with how accounts for that network are managed. Even if you use a VPN you will still have an account there and your data were at risk to this vulnerability.

> The impact of these two bugs was signifcant. It was access to first name, last name, address, and email of the user as well as last 4 digits, expiration date, billing name, and address of the credit cards. Assuming you're a black hat exploiting this bug, what can you do, if the target is using a VPN? I don't know what "address of the credit cards" means, but let's assume it's the target's home address. You don't ge…

You completely missed what this vulnerability is. It has nothing to do with intercepting another user's traffic. The checkout page in question actually uses SSL anyway, so it's not even possible absent some sort of MITM attack.

This has to do with API endpoints that exposed customer information and allowed password changes without checking that the request was coming from the customer. The customer didn't have to be logged in to the account, or even on the flight in the first place. If they had an account, it was exposed.

Re: Hacking on a plane: Leaking data of millions and taking over any account

#28

Earlier quoted context omitted.

Absolutely not. This has to do with how accounts for that network are managed. Even if you use a VPN you will still have an account there and your data were at risk to this vulnerability.

> The impact of these two bugs was signifcant. It was access to first name, last name, address, and email of the user as well as last 4 digits, expiration date, billing name, and address of the credit cards. Assuming you're a black hat exploiting this bug, what can you do, if the target is using a VPN? I don't know what "address of the credit cards" means, but let's assume it's the target's home address. You don't ge…

None of the impact of having your data leaked from your account is in any way modified by using a VPN for your data traffic while you are on the airplane. Hence the initial reply of that your suggestions of a VPN is irrelevant. Don't try to change this into a "oh but the data leak isn't really that bad of a vulnerability" after having lost that argument.

Re: Hacking on a plane: Leaking data of millions and taking over any account

#29
post #9

Earlier quoted context omitted.

Airplane wifi is very much still in the "enterprise software" phase, by which I mean a lowest bidder sells it to someone who will never use it and buys it with only some corporate objective in mind. I've been using it a lot recently, across several airlines, and the experience is universally bad. It doesn't surprise me they also skimped on security

At least as far as the connectivity itself goes, Viasat's Ka-band airplane WiFi is actually really good. As luck would have it, I've got a flight coming up in a few days on a plane using the provider implicated in this article. I'll be doing some poking around myself for sure.

Coincidentally on a flight right right now and service is decent on United. Not fast but useable. One caveat is that it performs much better with a VPN enabled. Seems they block certain things such as Zoom and the VPN allows the use of the chat feature. Apple Music was struggling until the VPN was enabled and solid since.

Re: Hacking on a plane: Leaking data of millions and taking over any account

#30
Not related to the content of the article, but to the presentation: that art work in the header is spot on, except maybe for what appears to be tree branches in the window. I think we are witnessing how generative are killing photo stock business.
Post reply on HN