How to own an airline in 3 easy steps and grab the TSA nofly list along the way
1–10 of 677 posts
Re: How to own an airline in 3 easy steps and grab the TSA nofly list along the way
#2Corresponding news story: https://www.dailydot.com/debug/no-fly-list-us-tsa-unprotecte...
Re: How to own an airline in 3 easy steps and grab the TSA nofly list along the way
#3Seriously? I know like none of the tools or terms they used, like wtf is shodan?
In general the author doesn't seem to follow the white hat guidelines, and I'd be worried what they've done is quite illegal (possibly on a federal level if the nofly list is so secret)
Re: How to own an airline in 3 easy steps and grab the TSA nofly list along the way
#4Re: How to own an airline in 3 easy steps and grab the TSA nofly list along the way
#5> with pretty much no skill required Seriously? I know like none of the tools or terms they used, like wtf is shodan? In general the author doesn't seem to follow the white hat guidelines, and I'd be worried what they've done is quite illegal (possibly on a federal level if the nofly list is so secret)
shodan[1] is a search engine that deals in hosts and ip addresses rather than web pages, and is a goldmine for finding everything from exposed ip webcams to jenkins instances.
Re: How to own an airline in 3 easy steps and grab the TSA nofly list along the way
#6Headline buries the real lede a bit in my opinion; the author has gotten a snapshot of the no-fly list from 2019. Presumably the system under attack processes more up-to-date versions of it regularly. Corresponding news story: https://www.dailydot.com/debug/no-fly-list-us-tsa-unprotecte...
There were also prod AWS credentials in the files exposed in Jenkins.
Re: How to own an airline in 3 easy steps and grab the TSA nofly list along the way
#7Re: How to own an airline in 3 easy steps and grab the TSA nofly list along the way
#8This is clearly on the darker side of gray-hat. Hate to be preachy but anyone seeking to emulate this sort of attack-finding should consider their ethical obligations as a computer scientist and follow best practices for responsible disclosure. It appears this was completely ignored here, including sharing stolen sensitive data of normal people with whoever can plead a case.
Re: How to own an airline in 3 easy steps and grab the TSA nofly list along the way
#9This is clearly on the darker side of gray-hat. Hate to be preachy but anyone seeking to emulate this sort of attack-finding should consider their ethical obligations as a computer scientist and follow best practices for responsible disclosure. It appears this was completely ignored here, including sharing stolen sensitive data of normal people with whoever can plead a case.
Moreover, depending on the contents of the list, this likely offers proof of what is generally suspected, that the no fly list is a form of discrimination and authoritarian overreach, targeting people that haven't been convicted of a crime but are "suspected" due to race, religion, etc. The whole thing is probably unconstitutional/illegal, but it's hard to prove that since it's been secret.
This seems like a clear case of hacktivism- trying to expose an unethical government program for what it is, so that it can be stopped.
Re: How to own an airline in 3 easy steps and grab the TSA nofly list along the way
#10This is clearly on the darker side of gray-hat. Hate to be preachy but anyone seeking to emulate this sort of attack-finding should consider their ethical obligations as a computer scientist and follow best practices for responsible disclosure. It appears this was completely ignored here, including sharing stolen sensitive data of normal people with whoever can plead a case.
Yeah cause we should totally have a top secret no fly list