Live data from Hacker News

Hacking the largest airline and hotel rewards platform (2023)

samcurry.net

111–120 of 122 posts

Re: Hacking the largest airline and hotel rewards platform (2023)

#111

It's interesting United Airlines is mentioned here. I am a security researcher and found vulnerabilities through the United Airlines bug bounty program last year. They pay you in miles instead of money. The problem is that they gift them to you instead of what you might get from a credit card rewards program. You end up having to pay a 2% tax on the total amount in points (at least in the US). When I made the calcula…

Relevant post: https://blog.docbert.org/united-airlines-bug-bounty/

Re: Hacking the largest airline and hotel rewards platform (2023)

#112

This is only tangentially related but it always blows my mind how insecure airline booking portals are. For many (most?) airlines all you need is the booking reference (PNR number) and surname to log in and see flight itinerary, contact details and, in some cases, change or cancel the booking. No password or MFA needed. The kicker is that your PNR number and surname are encoded in the barcode on your boarding pass, e…

It's worse with some. A recent trip had me create an account with an airline - I can log in and see my trips, points, name, etc... but to see the itinerary, I have to have the PNR number, which isn't anywhere in the authenticated portal area. It's only delivered by email, once AFIACT. I thought I'd lost it at first - couldn't find it for a while (went to spam apparently). But... if I'm logged in via user/pass... why…

Because then they'd have to `SELECT *` on an unindexed field...

Re: Hacking the largest airline and hotel rewards platform (2023)

#113
post #11

Earlier quoted context omitted.

A lot of the knowledge is very arcane, and like, split over hundreds and thousands of flyertalk.com pages, and like... institutional knowledge of more clever travel agents. I think a lot of the "fun" that can potentially be had also requires a direct access to a GDS, which, AFAICT is on the order of ~$10k a year? And if your "tricks" are discovered, airlines have a direct way to demand payment for any shenanigans you…

I thought fuel dumping is a thing from the past? I have been able to save USD 500 with a VPN (booked Aeroflot ticket advertised on Russian google with a Russian IP). I am able to read a little bit Cyrillic so I was able to go through the booking. Citibank then blocked my CC and called me. Did everything again and got the ticket for USD 1000 instead of USD 1500. Good experience with switching languages on sites. I was…

Fuel dumping is probably a much smaller deal then it was a few years back!

"blogs" ruined a lot of tricks and fun for some; but my understanding from observing the FT thread is that there are still people involved, just on a much smaller scale.

Re: Hacking the largest airline and hotel rewards platform (2023)

#114

Earlier quoted context omitted.

Because it's dev. Does your bathroom door have a deadbolt and a key and you lock it firmly every single time when you're home alone?

Whilst you are being facetious, deadbolting a bathroom door is really really dangerous. Bathrooms have a high risk of life threatening accidents and any locks should be bypassable indicators - this is why most have a coin unlock on the outside. Many countries have regulations requiring bathrooms to be unlockable from the outside without a key, and the external doors to be unlockable from the inside without a key. Dea…

I guess I should go check if I can unlock my (regular lock) bathroom door from outside!

> Deadbolting a bathroom is also pointless - there is nothing to protect.

Pedantically, many people keep medicines in their bathroom and if you happen to have any recreationally-usable drugs, they'd be one of the first things to go in a lot of robberies. Or, sadly, be taken by your teenager or seemed-to-be-normal friend.

Re: Hacking the largest airline and hotel rewards platform (2023)

#115
post #69

Earlier quoted context omitted.

It's often a violation of both government laws and insurance contracts, if you knowingly expose that much financial information to a proven vulnerability. There are businesses where if you suffer a theft, you shut everything down and run a stocktake. For example, an arms dealer. And there are times credit card providers shut down - because there is a known vulnerability, and they have to immediately mitigate, or lose…

Ok, but shutting down the website because of legal/moral responsibility to protect customer info is very different than doing so because of the “real money involved”, which is what commenter dewey was responding to. You can choose to just take the fraud cost hit in the latter case.

That's why people aim for the legal costs to be commensurate with the possible gain they will miss out on. Many corporate penalties are small enough that mathematically, it's absolutely worth simply breaking the law all the time.

Re: Hacking the largest airline and hotel rewards platform (2023)

#116

Earlier quoted context omitted.

Whilst you are being facetious, deadbolting a bathroom door is really really dangerous. Bathrooms have a high risk of life threatening accidents and any locks should be bypassable indicators - this is why most have a coin unlock on the outside. Many countries have regulations requiring bathrooms to be unlockable from the outside without a key, and the external doors to be unlockable from the inside without a key. Dea…

I guess I should go check if I can unlock my (regular lock) bathroom door from outside! > Deadbolting a bathroom is also pointless - there is nothing to protect. Pedantically, many people keep medicines in their bathroom and if you happen to have any recreationally-usable drugs, they'd be one of the first things to go in a lot of robberies. Or, sadly, be taken by your teenager or seemed-to-be-normal friend.

I guess medicine storage is an interesting cultural thing - I've always known them to be stored in the kitchen!

Re: Hacking the largest airline and hotel rewards platform (2023)

#117
post #59

Is taking the website offline really necessary? If the vulnerability has been there for 1 year or so already, what harm does it being there for 1 year and an hour do? Also, maybe it's not clear to me exactly what is getting taken down, but I'm amazed that the chain from "person reading email" to "person that is permitted to take down the website" moves so quickly (or that the latter right is given so low in the hiera…

I expect the report triggered something in a contract somewhere and they were obligated to take it offline knowing there was an issue.

Re: Hacking the largest airline and hotel rewards platform (2023)

#118

Earlier quoted context omitted.

Why would anyone even use such a predictable word for dev environment? I am baffled by this practice of not following the bare minimum security mindset even when you are just running it in a dev environment

Because it's dev. Does your bathroom door have a deadbolt and a key and you lock it firmly every single time when you're home alone?

No, but the bathroom does have a lock that can be used from the inside. Not a door that has a window in it and a lock that can be controlled from both sides of the door.

Re: Hacking the largest airline and hotel rewards platform (2023)

#120
post #113

Earlier quoted context omitted.

I thought fuel dumping is a thing from the past? I have been able to save USD 500 with a VPN (booked Aeroflot ticket advertised on Russian google with a Russian IP). I am able to read a little bit Cyrillic so I was able to go through the booking. Citibank then blocked my CC and called me. Did everything again and got the ticket for USD 1000 instead of USD 1500. Good experience with switching languages on sites. I was…

Fuel dumping is probably a much smaller deal then it was a few years back! "blogs" ruined a lot of tricks and fun for some; but my understanding from observing the FT thread is that there are still people involved, just on a much smaller scale.

Enjoy while it last. Some Idiot always has to make a blog post to collect some ad revenue or some attention. People don't understand that you can only use a loophole, if few people know about it.

Bullet train tickets in Germany are expensive. You were able to buy them online in the Czech Republic for a fraction of the price. Like Prague->Brussels 20 Euro. You don't have to use the whole ticket, you boarded in Frankfurt and went to Brussels for 20 Euro.

Gone....

Post reply on HN