Live data from Hacker News

Bypassing airport security via SQL injection

ian.sh

321–330 of 459 posts

Re: Bypassing airport security via SQL injection

#321

Earlier quoted context omitted.

> Hilarious that the entire TSA system is vulnerable to the most basic web programming error that you generally learn to avoid 10 minutes The article mentions that FlyCASS seems to be run by one person. This isn't a matter of technical chops, this is a matter of someone who is good at navigating bureaucracy convincing the powers that be that they should have a special hook into the system. What should really be inves…

Based on the language on their site about requiring an existing CASS subscription, my guess is there was no approval at all. It appears this person has knowledge of the CASS/KCM systems and APIs, and built a web interface for them that uses the airline's credentials to access the central system. My speculation is that ARINC doesn't restrict access by network/IP, so they wouldn't directly know this tool even exists. S…

Why is it critical for flight safety? It is critical for security theatre we have to endure at airports because some people have heightened neuroticism.

Be that as it may, of course the error needs correction. If it really is a one man show for tool like this, it isn't even surprising that there are shortcuts.

Re: Bypassing airport security via SQL injection

#322
post #126

Earlier quoted context omitted.

I believe the biggest increase in security since 9/11, is that passengers are no longer expected to sit down and behave. Pre-9/11, the expectation was you don't draw attention to yourself, wait it out, you're going to have a long day and a story to tell. Post-9/11, the expectation is you fight for your life. Better cockpit doors and access hygiene probably come second.

I would argue, the most effective change post 9/11, is the reinforcement of cockpit doors, and stricter cockpit access procedures.

Which, ironically, made it impossible to prevent this crash: https://en.wikipedia.org/wiki/Germanwings_Flight_9525

Re: Bypassing airport security via SQL injection

#323
post #92

Earlier quoted context omitted.

It’s also just one of those hard things to prove: is TSA actually stopping attacks like 9/11? The simple presence of them might be enough of a deterrent or we might just be extremely lucky. Seems these days the real threat is drunk passengers attacking flight attendants.

Have they caught and arrested any would-be bad guys? Should be pretty easy to verify.

They foiled these guys: https://www.youtube.com/watch?v=IHfiMoJUDVQ

Re: Bypassing airport security via SQL injection

#324

Earlier quoted context omitted.

Pretty much, although most TsA check lines no longer require even a boarding pass- so in theory you could pack a bomb with you then bypass all the security theater with this.

My presumption was that when you give TSA your ID and they scan it, their systems check that there’s a boarding pass in your name (and DOB)?

Boarding pass checks etc are independent of the security checks. At least security never checked my boarding pass or ID, it was usually a step before and after security checks.

Re: Bypassing airport security via SQL injection

#325

Earlier quoted context omitted.

Based on the language on their site about requiring an existing CASS subscription, my guess is there was no approval at all. It appears this person has knowledge of the CASS/KCM systems and APIs, and built a web interface for them that uses the airline's credentials to access the central system. My speculation is that ARINC doesn't restrict access by network/IP, so they wouldn't directly know this tool even exists. S…

Why is it critical for flight safety? It is critical for security theatre we have to endure at airports because some people have heightened neuroticism. Be that as it may, of course the error needs correction. If it really is a one man show for tool like this, it isn't even surprising that there are shortcuts.

Gaining access to the normally-locked flight deck jump seat seems like a pretty big potential flight safety threat to me.

Re: Bypassing airport security via SQL injection

#326
post #84

This shows that anyone with the slightest motivation to do harm would have zero difficulty replaying 911. The reason there aren't more terrorist attacks isn't because various security agencies around the world protect us from them. It's because there are extremely few terrorists.

> The reason there aren't more terrorist attacks isn't because various security agencies around the world protect us from them. It's because there are extremely few terrorists. There's plenty of terrorists, but destabilisation of Middle East diverted them away from continental US. Wasn't that the whole point of Afghanistan and Iraq wars?

>destabilisation of Middle East diverted them away from continental US

I put on my critical thinking hat and look at the timeline of "US meddling in the Middle East" and "first terror attack in the US by a middle eastern".

I then notice that the years are 1948 and 1993 respectively and that wet roads actually do not cause rain after all.

Re: Bypassing airport security via SQL injection

#327
post #303
post #192

Earlier quoted context omitted.

I once got called into jury duty and sat through jury selection. On that day, protesters were outside the courthouse calling awareness to jury nullification, so the judge brought it up. He said something like: "jury nullification is a constitutional right, but you waive those rights when you take the oath of a juror. It is not an option to you." I really wanted to say "but that constitutional right is not my right, i…

I don't know your case, but the term "rape" has been legally expanded a lot from what we might imagine when we hear the word "rape" (forceful sexual act). Legally it can mean a case where a man met a women in a bar, she was not drunk and wanted to go home with him. She explicitly consented. Later it ends up that she was using a fake ID to get into the bar, she was only 17.9 years old in a state where the age of conse…

YMMV but I don't think in my state either of those things would be tried as just "rape".

If there's no force/threats/drugs etc involved and the minor consents, it's charged as statutory rape which is different than capital-R rape.

Statutory rape can be a felony, but in cases like an 18 year old and a 17.5 year old having sex it's a misdemeanor and realistically 99.999% of the time it happens there are no charges

Re: Bypassing airport security via SQL injection

#328
post #59

Earlier quoted context omitted.

We know that backdoors can be intentional for use by 3-letter agencies. And there is plausible deniability of the bureaucracy when they can pass blame onto a single individual. Or it's beuracracy being beuracracy. The TSA is a lot of security theater anyways.

This is a bit of ridiculous comment. Who in the right mind would say a sql injection is a backdoor for a 3LA? Added, why would they use FlyCass when they could just access the data directly?

I have to say I admire the linguistic beauty of your turning Three-Letter Agency into a three-letter acronym.

Re: Bypassing airport security via SQL injection

#329

Earlier quoted context omitted.

> The reason there aren't more terrorist attacks isn't because various security agencies around the world protect us from them. It's because there are extremely few terrorists. There's plenty of terrorists, but destabilisation of Middle East diverted them away from continental US. Wasn't that the whole point of Afghanistan and Iraq wars?

>destabilisation of Middle East diverted them away from continental US I put on my critical thinking hat and look at the timeline of "US meddling in the Middle East" and "first terror attack in the US by a middle eastern". I then notice that the years are 1948 and 1993 respectively and that wet roads actually do not cause rain after all.

Not that it changes your point much, but you could probably look back to 1990. One of the WTC conspirators had assassinated a rabbi (an American who, to put it very lightly, had personally meddled in the middle east). Coincidentally since so many folks upthread are talking about jury nullification, the resulting trial is sometimes considered an example.

Re: Bypassing airport security via SQL injection

#330

> We did not want to contact FlyCASS first > as it appeared to be operated only by one person > and we did not want to alarm them I’m not buying this. Feels more like they knew the site developer would just fix it immediately and they wanted to make a bigger splash with their findings.

I came here to say this. Totally uncalled for not to contact the site first that had these holes and instead go to homeland security.
Post reply on HN