Earlier quoted context omitted.
What if they incremented a number in a url on a publicly available website?
Is this a reference to a past event? I don't get it.
Bypassing airport security via SQL injection
51–60 of 459 posts
Re: Bypassing airport security via SQL injection
#52Since they actually went past the SQL injection and then created a fake record for an employee, I'm shocked that Homeland did not come after and arrest those involved. Homeland would have been top of the list to misinterpret a disclosure and prefer to refer to the disclosure as malicious hacking instead of responsible disclosure. I'm more impressed by this than the incompetence of the actual issue.
You're not wrong, but I would have a hard time as a jury member convicting them of a CFAA violation or whatever for creating a user named "Test TestOnly" with a bright pink image instead of a photo. If they had added themselves as known crewmembers and used that to actually bypass airport screening, then yeah, they'd be in jail.
Doing this under your own name is insane.
Re: Bypassing airport security via SQL injection
#53Re: Bypassing airport security via SQL injection
#54Earlier quoted context omitted.
What if they incremented a number in a url on a publicly available website?
Is this a reference to a past event? I don't get it.
Re: Bypassing airport security via SQL injection
#55Earlier quoted context omitted.
What if they incremented a number in a url on a publicly available website?
Is this a reference to a past event? I don't get it.
Re: Bypassing airport security via SQL injection
#56Earlier quoted context omitted.
It doesn't seem particularly unique to TSA. Flying elsewhere in the world has essentially identical security screening, with all the same stupidity. I'm a little butthurt right now, in particular, about the security at Heathrow. They confiscated a bottle of whisky that we got in Edinburgh. After 10 minutes of head-scratching and consulting with a supervisor, they concluded that "it does not say 100ml" (it had "10cl"…
The problem boils down to two issues: 1. Ok, security is bad, what are you going to do? Go to different, competing security? 2. Nobody wants to be the politician that relaxes the security right before an accident, even if the accident wouldn't be prevented with tighter security anyway.
Amazingly, you can do that. SFO doesn't use the TSA, for example.
Re: Bypassing airport security via SQL injection
#57Since they actually went past the SQL injection and then created a fake record for an employee, I'm shocked that Homeland did not come after and arrest those involved. Homeland would have been top of the list to misinterpret a disclosure and prefer to refer to the disclosure as malicious hacking instead of responsible disclosure. I'm more impressed by this than the incompetence of the actual issue.
Re: Bypassing airport security via SQL injection
#58Earlier quoted context omitted.
What was surprising to me was that they didn't immediately do pre-dawn raids on the pentesters' homes and hold them without a lawyer under some provision of an anti-terror law.
that is apparently not a popular move anymore since people keep logs and have credentials, strong social media presence and readily available cloud enabled cameras. one email to any news org and whoever authorizes the raid will probably face some music. but knowing TSA, we can expect this any minute now...
That's what happened to Tulsi Gabbard: https://www.racket.news/p/the-worm-turns-house-senate-invest...
Re: Bypassing airport security via SQL injection
#59Hilarious that the entire TSA system is vulnerable to the most basic web programming error that you generally learn to avoid 10 minutes into reading about web programming- and that every decent quality web framework automatically prevents. It is really telling that they try to cover up and deny instead of fix it, but not surprising. That is a natural consequence of authoritarian thinking, which is the entire premise…
> Hilarious that the entire TSA system is vulnerable to the most basic web programming error that you generally learn to avoid 10 minutes The article mentions that FlyCASS seems to be run by one person. This isn't a matter of technical chops, this is a matter of someone who is good at navigating bureaucracy convincing the powers that be that they should have a special hook into the system. What should really be inves…
Or it's beuracracy being beuracracy. The TSA is a lot of security theater anyways.