Bypassing airport security via SQL injection
11–20 of 459 posts
Re: Bypassing airport security via SQL injection
#12I hate the TSA with every ounce of my being and these articles reinforce why. Incompetent and useless agency that only serves to waste people's time. Can't believe it still exists; 9/11 and the Bush administration really did a number on this country.
Re: Bypassing airport security via SQL injection
#13But that isn't even relevant when you can go traipsing through the SQL query itself just by asking; wouldn't matter how well the passwords were stored.
Re: Bypassing airport security via SQL injection
#14Since they actually went past the SQL injection and then created a fake record for an employee, I'm shocked that Homeland did not come after and arrest those involved. Homeland would have been top of the list to misinterpret a disclosure and prefer to refer to the disclosure as malicious hacking instead of responsible disclosure. I'm more impressed by this than the incompetence of the actual issue.
If they had added themselves as known crewmembers and used that to actually bypass airport screening, then yeah, they'd be in jail.
Re: Bypassing airport security via SQL injection
#15Since they actually went past the SQL injection and then created a fake record for an employee, I'm shocked that Homeland did not come after and arrest those involved. Homeland would have been top of the list to misinterpret a disclosure and prefer to refer to the disclosure as malicious hacking instead of responsible disclosure. I'm more impressed by this than the incompetence of the actual issue.
That just means the best minds from other, potentially less friendly countries, will do the picking. I doubt they will responsibly disclose.
Re: Bypassing airport security via SQL injection
#16A good old SQL injection negates the entire security theatre worth probably billions a year, hilarious, but probably not all too surprising.
Re: Bypassing airport security via SQL injection
#17> We did not want to contact FlyCASS first as it appeared to be operated only by one person and we did not want to alarm them
It’s incredible (and entirely too credible) that this kind of “high security” integration could be built in such an amateur way: and a good reminder why government projects often seem to be run with more complexity than your startup devs might think is necessary.
Re: Bypassing airport security via SQL injection
#18It is really telling that they try to cover up and deny instead of fix it, but not surprising. That is a natural consequence of authoritarian thinking, which is the entire premise and culture of the TSA. Any institution that covers up and ignores existential risks instead of confronting them head on will eventually implode by consequences of its own negligence- which hopefully will happen to the TSA.
Re: Bypassing airport security via SQL injection
#19Since they actually went past the SQL injection and then created a fake record for an employee, I'm shocked that Homeland did not come after and arrest those involved. Homeland would have been top of the list to misinterpret a disclosure and prefer to refer to the disclosure as malicious hacking instead of responsible disclosure. I'm more impressed by this than the incompetence of the actual issue.
The statute of limitations is long and HSI often delays their indictment until the investigation is mostly wrapped up.
Re: Bypassing airport security via SQL injection
#20I hate the TSA with every ounce of my being and these articles reinforce why. Incompetent and useless agency that only serves to waste people's time. Can't believe it still exists; 9/11 and the Bush administration really did a number on this country.
We as a civilization are terrible at getting over things, it seems.