Live data from Hacker News

Bypassing airport security via SQL injection

ian.sh

51–60 of 459 posts

Re: Bypassing airport security via SQL injection

#51
post #47

Earlier quoted context omitted.

What if they incremented a number in a url on a publicly available website?

Is this a reference to a past event? I don't get it.

It's an incredibly basic form of pen testing. For example, this reply page URL refers to id=41393364, which is presumably your comment. So what happens if I replace it with a different number? Probably something innocent, but maybe not.

Re: Bypassing airport security via SQL injection

#52
post #14
post #9

Since they actually went past the SQL injection and then created a fake record for an employee, I'm shocked that Homeland did not come after and arrest those involved. Homeland would have been top of the list to misinterpret a disclosure and prefer to refer to the disclosure as malicious hacking instead of responsible disclosure. I'm more impressed by this than the incompetence of the actual issue.

You're not wrong, but I would have a hard time as a jury member convicting them of a CFAA violation or whatever for creating a user named "Test TestOnly" with a bright pink image instead of a photo. If they had added themselves as known crewmembers and used that to actually bypass airport screening, then yeah, they'd be in jail.

Yeah so best case you spend tens of thousands on lawyers and probably win.

Doing this under your own name is insane.

Re: Bypassing airport security via SQL injection

#55
post #47

Earlier quoted context omitted.

What if they incremented a number in a url on a publicly available website?

Is this a reference to a past event? I don't get it.

In part yes but inevitably devolves into an ad hominem attack against the most high profile case of a guy who did it, who is now hiding in Ukraine on a Prednistrovian passport after having his conviction overturned (temporarily) giving him an escape window.

Re: Bypassing airport security via SQL injection

#56

Earlier quoted context omitted.

It doesn't seem particularly unique to TSA. Flying elsewhere in the world has essentially identical security screening, with all the same stupidity. I'm a little butthurt right now, in particular, about the security at Heathrow. They confiscated a bottle of whisky that we got in Edinburgh. After 10 minutes of head-scratching and consulting with a supervisor, they concluded that "it does not say 100ml" (it had "10cl"…

The problem boils down to two issues: 1. Ok, security is bad, what are you going to do? Go to different, competing security? 2. Nobody wants to be the politician that relaxes the security right before an accident, even if the accident wouldn't be prevented with tighter security anyway.

> 1. Ok, security is bad, what are you going to do? Go to different, competing security?

Amazingly, you can do that. SFO doesn't use the TSA, for example.

Re: Bypassing airport security via SQL injection

#57
post #9

Since they actually went past the SQL injection and then created a fake record for an employee, I'm shocked that Homeland did not come after and arrest those involved. Homeland would have been top of the list to misinterpret a disclosure and prefer to refer to the disclosure as malicious hacking instead of responsible disclosure. I'm more impressed by this than the incompetence of the actual issue.

I mean... they still might if the wrong people end up getting embarrassed by this. The wheels of bureaucracy are slow.

Re: Bypassing airport security via SQL injection

#58
post #24

Earlier quoted context omitted.

What was surprising to me was that they didn't immediately do pre-dawn raids on the pentesters' homes and hold them without a lawyer under some provision of an anti-terror law.

that is apparently not a popular move anymore since people keep logs and have credentials, strong social media presence and readily available cloud enabled cameras. one email to any news org and whoever authorizes the raid will probably face some music. but knowing TSA, we can expect this any minute now...

Why bother if they could just put everyone involved on the "dangerous terrorist" list which has zero controls and zero accountability because "national security"?

That's what happened to Tulsi Gabbard: https://www.racket.news/p/the-worm-turns-house-senate-invest...

Re: Bypassing airport security via SQL injection

#59
post #18

Hilarious that the entire TSA system is vulnerable to the most basic web programming error that you generally learn to avoid 10 minutes into reading about web programming- and that every decent quality web framework automatically prevents. It is really telling that they try to cover up and deny instead of fix it, but not surprising. That is a natural consequence of authoritarian thinking, which is the entire premise…

> Hilarious that the entire TSA system is vulnerable to the most basic web programming error that you generally learn to avoid 10 minutes The article mentions that FlyCASS seems to be run by one person. This isn't a matter of technical chops, this is a matter of someone who is good at navigating bureaucracy convincing the powers that be that they should have a special hook into the system. What should really be inves…

We know that backdoors can be intentional for use by 3-letter agencies. And there is plausible deniability of the bureaucracy when they can pass blame onto a single individual.

Or it's beuracracy being beuracracy. The TSA is a lot of security theater anyways.

Post reply on HN