Live data from Hacker News

Bypassing airport security via SQL injection

ian.sh

331–340 of 459 posts

Re: Bypassing airport security via SQL injection

#332

Earlier quoted context omitted.

Based on the language on their site about requiring an existing CASS subscription, my guess is there was no approval at all. It appears this person has knowledge of the CASS/KCM systems and APIs, and built a web interface for them that uses the airline's credentials to access the central system. My speculation is that ARINC doesn't restrict access by network/IP, so they wouldn't directly know this tool even exists. S…

Why is it critical for flight safety? It is critical for security theatre we have to endure at airports because some people have heightened neuroticism. Be that as it may, of course the error needs correction. If it really is a one man show for tool like this, it isn't even surprising that there are shortcuts.

Imagine if you could bring your own water, and drown in it! Horrifying!

Re: Bypassing airport security via SQL injection

#333

Earlier quoted context omitted.

As my good fortune would have it, I'm called to jury duty two weeks from now. I doubt I'll be sat though. Should I be, I'll keep the above in mind.

If you don't want to be sat, just mention Jury Nullification. Courts really hate that sanity check on the process. https://en.wikipedia.org/wiki/Jury_nullification

Careful, you can get into trouble for reminding jurors of their rights

https://www.independent.co.uk/climate-change/news/inner-lond...

Re: Bypassing airport security via SQL injection

#334
post #126
post #84

This shows that anyone with the slightest motivation to do harm would have zero difficulty replaying 911. The reason there aren't more terrorist attacks isn't because various security agencies around the world protect us from them. It's because there are extremely few terrorists.

I believe the biggest increase in security since 9/11, is that passengers are no longer expected to sit down and behave. Pre-9/11, the expectation was you don't draw attention to yourself, wait it out, you're going to have a long day and a story to tell. Post-9/11, the expectation is you fight for your life. Better cockpit doors and access hygiene probably come second.

> I believe the biggest increase in security since 9/11, is that passengers are no longer expected to sit down and behave.

While that may be a factor, there's never any news about this happening, except maybe shortly after 9/11 with shoe or underwear bombs.

Re: Bypassing airport security via SQL injection

#335
post #126

Earlier quoted context omitted.

I believe the biggest increase in security since 9/11, is that passengers are no longer expected to sit down and behave. Pre-9/11, the expectation was you don't draw attention to yourself, wait it out, you're going to have a long day and a story to tell. Post-9/11, the expectation is you fight for your life. Better cockpit doors and access hygiene probably come second.

Pilots are also now told to not open the cockpit door, no matter what's happening in the cabin and to land the plane. There is a near 0 change you could take control of the plane. I would be more concerned about someone bringing a bomb on board.

The thing with this hack though is that it seems to be able to greenlight someone pretending to be staff to enter the cockpit as a passenger.

Re: Bypassing airport security via SQL injection

#336
post #116
post #84

This shows that anyone with the slightest motivation to do harm would have zero difficulty replaying 911. The reason there aren't more terrorist attacks isn't because various security agencies around the world protect us from them. It's because there are extremely few terrorists.

Maybe I am a naive idiot, but I would assume that other agencies like the FBI provide some protection even if TSA is not great. I occasionally see notable examples, like the CIA being responsible for discovering planned attacks on the recent Taylor Swift concert in Vienna that was then canceled.

Not to mention international cooperation, like the Dutch secret service having agents or contacts in Ukraine after MH17 that tipped off the CIA about a possible attack on the Nord Stream pipelines.

Re: Bypassing airport security via SQL injection

#337
post #211

Guys, I think you should not have done this. You can really piss a lot of people off doing that kind of stuff.

I agree they shouldn't have written it in such a "now let me embarrass you and show how right I am" way (and they also should have shown a lot more awareness of how embarrassing this was and, also of how: while infosec is super important, there are other priorities that need to be protected in how this is disclosed, too -- especially if they are hoping for constructive engagement with the orgs involved which, like it or not, is what practical security requires, if your point in disclosing is to make a meaningful positive difference, which is really important given the scale/scope of this vulnerability), but I don't think it worked out bad for these two judging from their Twitter feeds. I don't know them, but:

Two guys from (or based in) the Midwest:

Ian did his first DEFCON talk a couple weeks ago (https://x.com/iangcarroll), and Sam (the other author), was the guy that a couple years back Google accidentally sent 200K USD to, and has 81K X followers, and was recently singing the praises of that much lauded recent PHRACK article on "Hacking means understanding the world" (that was also popular round here): https://x.com/samwcyo/status/1823571295189008601

They both seem like legit security researchers from their X feeds.

I guess that petulance-tinged adolescent attitude is like the secret handshake of the security researcher world, which sounds too disparaging -- but it's not meant to be...only that probably that's what you need to expect from folks who "understand the world", where they're smarter, what's broken, and should be fixed.

I get how that attitude rubs people the wrong way and causes more harm than good - but I don't mind it much myself - I guess I just set high expectations for the kind of impact such folks could have, and I think they could have more impact if they adopted a more professional, collegiate attitude in their way of working.

But I guess that comes with the territory. Because it's really only the "outsiders" who will sit around poking at things to figure out how they work, and how to fix em, make em better. Those who feel themselves to be "rejects' from the normal world, in sense, are always gonna carry a bit of the tinge of that perspective with them. But, whaddayagonnado? Those are really only gonna be the ones who "understand the world", so you have to rely on them. Odd couples, that pairing. Between industry and these hackers.

Re: Bypassing airport security via SQL injection

#338
post #92
post #84

This shows that anyone with the slightest motivation to do harm would have zero difficulty replaying 911. The reason there aren't more terrorist attacks isn't because various security agencies around the world protect us from them. It's because there are extremely few terrorists.

It’s also just one of those hard things to prove: is TSA actually stopping attacks like 9/11? The simple presence of them might be enough of a deterrent or we might just be extremely lucky. Seems these days the real threat is drunk passengers attacking flight attendants.

Thing is, terrorism makes people afraid, even if no attack actually happened; one theory I have is that foiled plots are not reported on. Maybe in 20-50 years some of the records will be unsealed and we'll hear about loads of foiled plots.

But the counterpoint to that is that a gunman almost succeeded in killing Trump despite showing the behaviours online and offline of your stereotypical amateur assassin.

Re: Bypassing airport security via SQL injection

#339
post #307

Earlier quoted context omitted.

This used to be a question on the Triplebyte interview almost verbatim, and a huge percentage of (even quite good) engineers got it wrong. I'd say probably <20% both salted and used a cryptographically-secure hash; MD5 specifically came up all the time. And keep in mind that we filtered substantially before this interview, so the baseline is even worse than that!

Damn. Using salts and avoiding MD5 in favour of SHA-1 was well known even around 2005. Rainbow tables were a thing even then.

How are people still learning about basic MD5 for security twenty years later? Are the resources people use that old?

Re: Bypassing airport security via SQL injection

#340
post #301
post #294

Earlier quoted context omitted.

What if you hack a system that allows you into the cockpit with no additional checks? That would be crazy...

A random person pretending to be an airline pilot in a room full of airline pilots? I don’t see it happening, they’ll get kicked out in a second.

You don't have to pretend to be a pilot. Any cabin crew is allowed in the cockpit, AFAIK
Post reply on HN