Live data from Hacker News

Bypassing airport security via SQL injection

ian.sh

241–250 of 459 posts

Re: Bypassing airport security via SQL injection

#241

Earlier quoted context omitted.

Based on the language on their site about requiring an existing CASS subscription, my guess is there was no approval at all. It appears this person has knowledge of the CASS/KCM systems and APIs, and built a web interface for them that uses the airline's credentials to access the central system. My speculation is that ARINC doesn't restrict access by network/IP, so they wouldn't directly know this tool even exists. S…

This right here people need to pay attention to gut the following reason: One person can make a lot of impact The most common thing I hear people say with respect to their jobs is: “I’m just one person, I can’t actually do anything to make things better/worse…” But it’s just wrong and there’s thousands of examples of exactly that over and over and over In this case, if this is true, it’s both amazing that: One person…

Yeah but this is not very actionable. It is like saying that one person can win the lottery.

You have to be in the right place at the right time.

Re: Bypassing airport security via SQL injection

#243

> We did not want to contact FlyCASS first > as it appeared to be operated only by one person > and we did not want to alarm them I’m not buying this. Feels more like they knew the site developer would just fix it immediately and they wanted to make a bigger splash with their findings.

Whatever their motive was, the engineering process that allowed such a common bug to sneak in is broken. If the sole developer immediately fixed it, it would have been hard to escalate the issue so that maybe someone up the chain can fix this systematically. I'm not sure such overhaul would really happen but it's more likely that it won't if not escalated.

Re: Bypassing airport security via SQL injection

#244
post #18

Hilarious that the entire TSA system is vulnerable to the most basic web programming error that you generally learn to avoid 10 minutes into reading about web programming- and that every decent quality web framework automatically prevents. It is really telling that they try to cover up and deny instead of fix it, but not surprising. That is a natural consequence of authoritarian thinking, which is the entire premise…

TBF, TSA =/= 'Trained SQL Administrator' - so we can't hold _that_ against them...

Re: Bypassing airport security via SQL injection

#245
post #24

Earlier quoted context omitted.

What was surprising to me was that they didn't immediately do pre-dawn raids on the pentesters' homes and hold them without a lawyer under some provision of an anti-terror law.

That's not really how this works. TSA is maliciously incompetent, but there is a reporting pipeline and procedure for these things that's formalized and designed to protect exactly this kind of good-faith reporting[1]. (It's very easy to believe the worst possible thing about every corner of our government, since every corner of our government has something bad about it. But it's a fundamental error to think that eve…

>'...there is a reporting pipeline and procedure...'

---

Here is the next YC: An app that uses AI to navigate all the Civil Injections and allow the easist way to contact, petition, complain, praise, poll, explain a law, measure etc ELI5.

Get OpenAI and/or Amazon (Given they run DataCenter Infra for CoIntelPro) - since they have/seek government contracts - and have Massive AI - make them create a USA-GPT.gov and its the most informed bot that will connect you to, explain, write-your-[representative/lobbiest/committee], and these companies have to provide these govGPTs in order to maintain any federal/defense contracts.

Re: Bypassing airport security via SQL injection

#246
post #18

Hilarious that the entire TSA system is vulnerable to the most basic web programming error that you generally learn to avoid 10 minutes into reading about web programming- and that every decent quality web framework automatically prevents. It is really telling that they try to cover up and deny instead of fix it, but not surprising. That is a natural consequence of authoritarian thinking, which is the entire premise…

> Hilarious that the entire TSA system is vulnerable to the most basic web programming error that you generally learn to avoid 10 minutes The article mentions that FlyCASS seems to be run by one person. This isn't a matter of technical chops, this is a matter of someone who is good at navigating bureaucracy convincing the powers that be that they should have a special hook into the system. What should really be inves…

Well my username, "\\'\truncate table user;;\''" has served me well over the years. But some sites I cannot log into for some reason.

Re: Bypassing airport security via SQL injection

#248
post #97

Earlier quoted context omitted.

I'll take that bet. How long of a time window? 1 year, 2 years?

Lets say 2 years. Email in profile.

After listening to patio11's podcast [0] with the owner of Manifold [1] I'd suggest that could be a good platform for this bet

[0] https://www.complexsystemspodcast.com/episodes/prediction-ma...

[1] https://manifold.markets/

Re: Bypassing airport security via SQL injection

#249
post #140
post #65

Earlier quoted context omitted.

In the case of msft/crowdstrike isn't this exactly the opposite of what HN rallies against? The users installed crowdstrike on their own machines. Why should microsoft be the arbiter of what a user can do to their own system?

They automatically occupy that position because in practice no user of a microsoft system can audit the entire "supply chain" of that system, unlike one built from open-source components. Any "control" someone has over "their own" system is ultimately incomplete when there is a company that owns and controls the operating system itself and has the sole power to both fix and inspect it

>no user of a microsoft system can audit the entire "supply chain" of that system,

Yes you can, you can access the source code to audit it.

https://en.wikipedia.org/wiki/Shared_Source_Initiative

Re: Bypassing airport security via SQL injection

#250

> We did not want to contact FlyCASS first > as it appeared to be operated only by one person > and we did not want to alarm them I’m not buying this. Feels more like they knew the site developer would just fix it immediately and they wanted to make a bigger splash with their findings.

This is exactly the kinda bug where you want to make a big splash though. You don't just want the guy to silently fix it, everyone in the database needs to be vetted again.
Post reply on HN