It's interesting United Airlines is mentioned here. I am a security researcher and found vulnerabilities through the United Airlines bug bounty program last year. They pay you in miles instead of money. The problem is that they gift them to you instead of what you might get from a credit card rewards program. You end up having to pay a 2% tax on the total amount in points (at least in the US). When I made the calcula…
Hacking the largest airline and hotel rewards platform (2023)
111–120 of 122 posts
Re: Hacking the largest airline and hotel rewards platform (2023)
#112This is only tangentially related but it always blows my mind how insecure airline booking portals are. For many (most?) airlines all you need is the booking reference (PNR number) and surname to log in and see flight itinerary, contact details and, in some cases, change or cancel the booking. No password or MFA needed. The kicker is that your PNR number and surname are encoded in the barcode on your boarding pass, e…
It's worse with some. A recent trip had me create an account with an airline - I can log in and see my trips, points, name, etc... but to see the itinerary, I have to have the PNR number, which isn't anywhere in the authenticated portal area. It's only delivered by email, once AFIACT. I thought I'd lost it at first - couldn't find it for a while (went to spam apparently). But... if I'm logged in via user/pass... why…
Re: Hacking the largest airline and hotel rewards platform (2023)
#113Earlier quoted context omitted.
A lot of the knowledge is very arcane, and like, split over hundreds and thousands of flyertalk.com pages, and like... institutional knowledge of more clever travel agents. I think a lot of the "fun" that can potentially be had also requires a direct access to a GDS, which, AFAICT is on the order of ~$10k a year? And if your "tricks" are discovered, airlines have a direct way to demand payment for any shenanigans you…
I thought fuel dumping is a thing from the past? I have been able to save USD 500 with a VPN (booked Aeroflot ticket advertised on Russian google with a Russian IP). I am able to read a little bit Cyrillic so I was able to go through the booking. Citibank then blocked my CC and called me. Did everything again and got the ticket for USD 1000 instead of USD 1500. Good experience with switching languages on sites. I was…
"blogs" ruined a lot of tricks and fun for some; but my understanding from observing the FT thread is that there are still people involved, just on a much smaller scale.
Re: Hacking the largest airline and hotel rewards platform (2023)
#114Earlier quoted context omitted.
Because it's dev. Does your bathroom door have a deadbolt and a key and you lock it firmly every single time when you're home alone?
Whilst you are being facetious, deadbolting a bathroom door is really really dangerous. Bathrooms have a high risk of life threatening accidents and any locks should be bypassable indicators - this is why most have a coin unlock on the outside. Many countries have regulations requiring bathrooms to be unlockable from the outside without a key, and the external doors to be unlockable from the inside without a key. Dea…
> Deadbolting a bathroom is also pointless - there is nothing to protect.
Pedantically, many people keep medicines in their bathroom and if you happen to have any recreationally-usable drugs, they'd be one of the first things to go in a lot of robberies. Or, sadly, be taken by your teenager or seemed-to-be-normal friend.
Re: Hacking the largest airline and hotel rewards platform (2023)
#115Earlier quoted context omitted.
It's often a violation of both government laws and insurance contracts, if you knowingly expose that much financial information to a proven vulnerability. There are businesses where if you suffer a theft, you shut everything down and run a stocktake. For example, an arms dealer. And there are times credit card providers shut down - because there is a known vulnerability, and they have to immediately mitigate, or lose…
Ok, but shutting down the website because of legal/moral responsibility to protect customer info is very different than doing so because of the “real money involved”, which is what commenter dewey was responding to. You can choose to just take the fraud cost hit in the latter case.
Re: Hacking the largest airline and hotel rewards platform (2023)
#116Earlier quoted context omitted.
Whilst you are being facetious, deadbolting a bathroom door is really really dangerous. Bathrooms have a high risk of life threatening accidents and any locks should be bypassable indicators - this is why most have a coin unlock on the outside. Many countries have regulations requiring bathrooms to be unlockable from the outside without a key, and the external doors to be unlockable from the inside without a key. Dea…
I guess I should go check if I can unlock my (regular lock) bathroom door from outside! > Deadbolting a bathroom is also pointless - there is nothing to protect. Pedantically, many people keep medicines in their bathroom and if you happen to have any recreationally-usable drugs, they'd be one of the first things to go in a lot of robberies. Or, sadly, be taken by your teenager or seemed-to-be-normal friend.
Re: Hacking the largest airline and hotel rewards platform (2023)
#117Is taking the website offline really necessary? If the vulnerability has been there for 1 year or so already, what harm does it being there for 1 year and an hour do? Also, maybe it's not clear to me exactly what is getting taken down, but I'm amazed that the chain from "person reading email" to "person that is permitted to take down the website" moves so quickly (or that the latter right is given so low in the hiera…
Re: Hacking the largest airline and hotel rewards platform (2023)
#118Earlier quoted context omitted.
Why would anyone even use such a predictable word for dev environment? I am baffled by this practice of not following the bare minimum security mindset even when you are just running it in a dev environment
Because it's dev. Does your bathroom door have a deadbolt and a key and you lock it firmly every single time when you're home alone?
Re: Hacking the largest airline and hotel rewards platform (2023)
#119Re: Hacking the largest airline and hotel rewards platform (2023)
#120Earlier quoted context omitted.
I thought fuel dumping is a thing from the past? I have been able to save USD 500 with a VPN (booked Aeroflot ticket advertised on Russian google with a Russian IP). I am able to read a little bit Cyrillic so I was able to go through the booking. Citibank then blocked my CC and called me. Did everything again and got the ticket for USD 1000 instead of USD 1500. Good experience with switching languages on sites. I was…
Fuel dumping is probably a much smaller deal then it was a few years back! "blogs" ruined a lot of tricks and fun for some; but my understanding from observing the FT thread is that there are still people involved, just on a much smaller scale.
Bullet train tickets in Germany are expensive. You were able to buy them online in the Czech Republic for a fraction of the price. Like Prague->Brussels 20 Euro. You don't have to use the whole ticket, you boarded in Frankfurt and went to Brussels for 20 Euro.
Gone....