Live data from Hacker News

Bypassing airport security via SQL injection

ian.sh

221–230 of 459 posts

Re: Bypassing airport security via SQL injection

#221

Earlier quoted context omitted.

That's of course the stupidest possible domain for a government website. (Or at least it's up there) Fundamentally, it has given control over the DNS records to a different country (.me == Montenegro). It's training people that really, any domain could be a government domain, you'll never know.

It's also not a government web site. It's a private company who, for some reason, my own government outsources identity verification to. Meanwhile, the authorization system the US government has built (login.gov) is deemed "insecure" by the IRS and Social Security for some inexplicable reason. (But it's fine for Trusted Traveler Programs.)

> It's a private company who, for some reason, my own government outsources identity verification to

Welcome to the neoliberal wet dream.

Re: Bypassing airport security via SQL injection

#222
> We did not want to contact FlyCASS first > as it appeared to be operated only by one person > and we did not want to alarm them

I’m not buying this. Feels more like they knew the site developer would just fix it immediately and they wanted to make a bigger splash with their findings.

Re: Bypassing airport security via SQL injection

#223
What mind-melting levels of incompetency. I would love to suggest pay raises so the Government can hire better individuals... but I worry the problem is so systemic it wouldn't do any good.

Everyone dropped the ball... and kept dropping it. The part where its handed to them on a silver platter and its essentially smacked away. Maddening.

Re: Bypassing airport security via SQL injection

#224

Earlier quoted context omitted.

> Hilarious that the entire TSA system is vulnerable to the most basic web programming error that you generally learn to avoid 10 minutes The article mentions that FlyCASS seems to be run by one person. This isn't a matter of technical chops, this is a matter of someone who is good at navigating bureaucracy convincing the powers that be that they should have a special hook into the system. What should really be inves…

Based on the language on their site about requiring an existing CASS subscription, my guess is there was no approval at all. It appears this person has knowledge of the CASS/KCM systems and APIs, and built a web interface for them that uses the airline's credentials to access the central system. My speculation is that ARINC doesn't restrict access by network/IP, so they wouldn't directly know this tool even exists. S…

If this were the case, then it seems quite plausible that the website itself was just a passthrough, and the APIs provided by ARINC would be exposed.

THis then begs the question of how ARINC passed security audit.

Re: Bypassing airport security via SQL injection

#225
post #18

Hilarious that the entire TSA system is vulnerable to the most basic web programming error that you generally learn to avoid 10 minutes into reading about web programming- and that every decent quality web framework automatically prevents. It is really telling that they try to cover up and deny instead of fix it, but not surprising. That is a natural consequence of authoritarian thinking, which is the entire premise…

[flagged]

Re: Bypassing airport security via SQL injection

#226

Earlier quoted context omitted.

Someting I’ve been thinking about, esp since that crowdstrike debacle. Why do major distributors of infrastructure (msft in case of crowdstrike, DHS/TSA here) not require that vendors with privileged software access have passed some sort of software distribution/security audit? If FlyCASS had been required to undergo basic security testing, this (specific) issue would not exist

They often do. The value of those kinds of blanket security audits is questionable, however. (This is one of the reasons I'm generally pro-OSS for digital infrastructure: security quickly becomes a compliance game at the scale of government, meaning that it's more about diligently completing checklists and demonstrating that diligence than about critically evaluating a component's security. OSS doesn't make software…

Even if these govt. security audits are checkboxes, dont they require some nominal pentesting and black box testing, which test for things like SQL injection?

That shoudl have caught these types of exposures?

Re: Bypassing airport security via SQL injection

#227
post #82

Earlier quoted context omitted.

In part yes but inevitably devolves into an ad hominem attack against the most high profile case of a guy who did it, who is now hiding in Ukraine on a Prednistrovian passport after having his conviction overturned (temporarily) giving him an escape window.

> hiding in Ukraine Huh. Uh, weird choice, given, well, you know…

Maybe not. If you claim to be living in an active warzone and go missing who would look for you?

Flee to Western Europe under an assumed identity, get taken in as a refugee?

Re: Bypassing airport security via SQL injection

#228
post #127
post #84

This shows that anyone with the slightest motivation to do harm would have zero difficulty replaying 911. The reason there aren't more terrorist attacks isn't because various security agencies around the world protect us from them. It's because there are extremely few terrorists.

> zero difficulty replaying 911. The attacks of September 11th 2001 are fundamentally not reproducible irrespective of whether there is _any_ security screening at airports. The default assumption before that morning was that a hijacked plane would fly around for a bit, then land. The default assumption afterwards is that it will be crashed if a hijacker is allowed to gain control, so the calculus on passenger interv…

We'll never have another golden age of hijacks thanks to 9/11.

Re: Bypassing airport security via SQL injection

#229

So, the trick here would be to purchase a ticket with a major airline, pack a no-no in your carry-on, and then bypass TSA security by adding yourself to the Known Crew Member list of a small airline using the third-party FlyCASS system, via the SQL-injection. You'd then board the major airline with the no-no. Is that the vulnerability?

Sounds like you get to sit in the cockpit too?

Re: Bypassing airport security via SQL injection

#230
post #193
post #146

Earlier quoted context omitted.

Everyone says this but when people say "critical thinking skills" it really means "is obvious they will willfully disobey the instructions given to them by the judge and hold their own moral/ethical code above the law." You're literally describing jury nullification in a situation where by the hypothetical judge's instructions they're obviously guilty. I might agree with you that the law is bullshit but by right you…

> hold their own moral/ethical code above the law ... I might agree with you that the law is bullshit This is the entire reason that we have trial by jury and not trial by judge . I'm not sure how this got lost over the centuries. If 12 of your peers think you did it but the law is bullshit and you shouldn't have your life destroyed because of some stupid technicality in a bullshit law, then you should walk free! I'm…

Jury is peer, not subordinate of judge, and they should keep each other in check. Some tyrannical judges don't understand this. Sometimes the judge has to be reminded he is wrong in a way he can't prove he's been reminded, however.
Post reply on HN