Live data from Hacker News

Bypassing airport security via SQL injection

ian.sh

361–370 of 459 posts

Re: Bypassing airport security via SQL injection

#361
post #307

Earlier quoted context omitted.

Damn. Using salts and avoiding MD5 in favour of SHA-1 was well known even around 2005. Rainbow tables were a thing even then.

How are people still learning about basic MD5 for security twenty years later? Are the resources people use that old?

Probably because a lot of computer science programs are stuck in 90s era curricula and many don't teach web development whatsoever.

Re: Bypassing airport security via SQL injection

#362
post #351

Earlier quoted context omitted.

You don't have to pretend to be a pilot. Any cabin crew is allowed in the cockpit, AFAIK

Not just cabin crew, a lot of the time anyone flying standby is offered the jumpseat if there are no other seats available out of courtesy. Especially if they are an airline employee, but often non-employees too.

I don't think just anyone is allowed to sit in the jumpseat in the cockpit.

Re: Bypassing airport security via SQL injection

#363
post #301
post #294

Earlier quoted context omitted.

What if you hack a system that allows you into the cockpit with no additional checks? That would be crazy...

A random person pretending to be an airline pilot in a room full of airline pilots? I don’t see it happening, they’ll get kicked out in a second.

The 9/11 hijackers were trained as pilots though.

Re: Bypassing airport security via SQL injection

#364
post #332

Earlier quoted context omitted.

Imagine if you could bring your own water, and drown in it! Horrifying!

Tell you haven't read the article without telling me you haven't read the article.

??? You can bring anything you want in your KCM/CASS luggage, including a water bottle, which is not allowed through the "civilian" checkpoint

Re: Bypassing airport security via SQL injection

#365

Earlier quoted context omitted.

> The reason there aren't more terrorist attacks isn't because various security agencies around the world protect us from them. It's because there are extremely few terrorists. There's plenty of terrorists, but destabilisation of Middle East diverted them away from continental US. Wasn't that the whole point of Afghanistan and Iraq wars?

>destabilisation of Middle East diverted them away from continental US I put on my critical thinking hat and look at the timeline of "US meddling in the Middle East" and "first terror attack in the US by a middle eastern". I then notice that the years are 1948 and 1993 respectively and that wet roads actually do not cause rain after all.

I assume by 1948 you mean Israel’s declaration and subsequent war of independence. The US had nothing to do with Israel forming beyond being part of the UN vote - Britain was the architect of this part of the Middle East and is responsible for every border drawn by all nations there. This was fallout of the Ottoman Empire choosing to go to war against Western Europe and being defeated (after hundreds of years of incompetent leadership). [0]

The US did not supply Israel in any way until 2 decades later, and it was Eastern European arms dealers first, France second. The first weapons sold to Israel by the US were in 1962 (anti air missiles), followed by some tanks and aircraft later in the decade. Things ramped up considerably after 1967 due to Arab states aligning with the USSR. [1]

RFK was assassinated by a Palestinian terrorist in 1968. [2]

0. https://en.m.wikipedia.org/wiki/Partition_of_the_Ottoman_Emp...

1. https://en.m.wikipedia.org/wiki/Israel%E2%80%93United_States...

2. https://en.m.wikipedia.org/wiki/Assassination_of_Robert_F._K...

Re: Bypassing airport security via SQL injection

#366
I can't find the essay now, but I remember reading something from years and years ago: Bruce Schneier arguing that it made sense for airline pilots to go through security with everyone else, in spite of the silly appearance, because the inherent complication in implementing a two tier system would both eat up efficiency gains and unavoidably introduce security flaws.

He convinced me at the time, but I wasn't expecting such an on-the-nose demonstration.

Re: Bypassing airport security via SQL injection

#367
post #16
post #6

A good old SQL injection negates the entire security theatre worth probably billions a year, hilarious, but probably not all too surprising.

Does anyone remember Bruce Schneier and his faked boarding passes? The TSA scribble used to be the weak point of the entire system.

I don't

https://www.schneier.com/crypto-gram/archives/2003/0815.html...

https://www.schneier.com/essays/archives/2006/11/the_boardin...

Re: Bypassing airport security via SQL injection

#368
post #362
post #351

Earlier quoted context omitted.

Not just cabin crew, a lot of the time anyone flying standby is offered the jumpseat if there are no other seats available out of courtesy. Especially if they are an airline employee, but often non-employees too.

I don't think just anyone is allowed to sit in the jumpseat in the cockpit.

My dad was an airline pilot. Policy was you had to be in uniform to sit in the jump seat, and, yeah, it's not open to just anybody. If he was flying standby to get home, he would take it if no other option was open.

Re: Bypassing airport security via SQL injection

#369

Earlier quoted context omitted.

> Hilarious that the entire TSA system is vulnerable to the most basic web programming error that you generally learn to avoid 10 minutes The article mentions that FlyCASS seems to be run by one person. This isn't a matter of technical chops, this is a matter of someone who is good at navigating bureaucracy convincing the powers that be that they should have a special hook into the system. What should really be inves…

Someting I’ve been thinking about, esp since that crowdstrike debacle. Why do major distributors of infrastructure (msft in case of crowdstrike, DHS/TSA here) not require that vendors with privileged software access have passed some sort of software distribution/security audit? If FlyCASS had been required to undergo basic security testing, this (specific) issue would not exist

I've delivered software to the US government. My software has always been required to undergo security auditing.

Re: Bypassing airport security via SQL injection

#370
post #18

Hilarious that the entire TSA system is vulnerable to the most basic web programming error that you generally learn to avoid 10 minutes into reading about web programming- and that every decent quality web framework automatically prevents. It is really telling that they try to cover up and deny instead of fix it, but not surprising. That is a natural consequence of authoritarian thinking, which is the entire premise…

I find it amusing (actually more tragic than amusing) that the same politicians who tell us all day that corporations can't be trusted because they are run by people with character flaws (greed, lying, laziness, etc.); will turn around and tell us that handing more power and influence over to a government agency is a good idea. They make it sound like the job pool between the public and private sector is completely s…

What mythical private sector accountability are we talking about? A government agency didn’t build the software, it was a one man, private sector company. Maybe the moral is not outsourcing every last thing in existence?
Post reply on HN