The TSA's response here is childish and embarrassing, although perhaps unsurprising given the TSA's institutional disinterest in actual security. It's interesting to see that DHS seemingly (initially) handled the report promptly and professionally, but then failed to maintain top-level authority over the fix and disclosure process.
[flagged]
Bypassing airport security via SQL injection
381–390 of 459 posts
Re: Bypassing airport security via SQL injection
#382Earlier quoted context omitted.
This right here people need to pay attention to gut the following reason: One person can make a lot of impact The most common thing I hear people say with respect to their jobs is: “I’m just one person, I can’t actually do anything to make things better/worse…” But it’s just wrong and there’s thousands of examples of exactly that over and over and over In this case, if this is true, it’s both amazing that: One person…
Yeah but this is not very actionable. It is like saying that one person can win the lottery. You have to be in the right place at the right time.
Re: Bypassing airport security via SQL injection
#383The TSA's response here is childish and embarrassing, although perhaps unsurprising given the TSA's institutional disinterest in actual security. It's interesting to see that DHS seemingly (initially) handled the report promptly and professionally, but then failed to maintain top-level authority over the fix and disclosure process.
It’s very hard for management, even IT managers, to fully understand what such things mean. I’ve seen huge issues, like exposed keys, being treated as a small issue. While an outdated js library, or lack of ip6 support being escalated. I’m sure TSA and their partners wants to downplay potential exposure, I’m also sure it’s hard for a lot of their managers to fully understand what the vulnerability entails (most likel…
Edit: Fixed a double negative (previously: This is the Transportation SECURITY Agency. If the managers involved here can't understand why this is a huge deal, they're not exceptionally unqualified for their jobs.)
Re: Bypassing airport security via SQL injection
#384Guys, I think you should not have done this. You can really piss a lot of people off doing that kind of stuff.
Reminds me of the guy that created a simple one-page website to make fake boarding passes, only to get into controlled areas of airports (not to actually fly). 'd
Re: Bypassing airport security via SQL injection
#385Earlier quoted context omitted.
What was surprising to me was that they didn't immediately do pre-dawn raids on the pentesters' homes and hold them without a lawyer under some provision of an anti-terror law.
There's still _plenty_ of time for that to happen. I wouldn't want to be this person right now. I like my dog alive.
Re: Bypassing airport security via SQL injection
#386Earlier quoted context omitted.
Is this a reference to a past event? I don't get it.
In part yes but inevitably devolves into an ad hominem attack against the most high profile case of a guy who did it, who is now hiding in Ukraine on a Prednistrovian passport after having his conviction overturned (temporarily) giving him an escape window.
Re: Bypassing airport security via SQL injection
#387Earlier quoted context omitted.
The md5 part of the sqli is added by the pentester, likely because they needed a call that would end in a parenthesis within the injection parameter
There is already a call to MD5 in the original query; see the first image in the article, which they apparently obtained by submitting ' as the username: https://images.spr.so/cdn-cgi/imagedelivery/j42No7y-dcokJuNg...
Re: Bypassing airport security via SQL injection
#388Earlier quoted context omitted.
A random person pretending to be an airline pilot in a room full of airline pilots? I don’t see it happening, they’ll get kicked out in a second.
The 9/11 hijackers were trained as pilots though.
Re: Bypassing airport security via SQL injection
#389Earlier quoted context omitted.
Authentication and authorization, and especially on the web, is one of those things that has never been implemented well. I hate every single piece of software, every standard, every library, every approach I have come into contact with from this domain. I am so glad I have nothing to do with this field anymore. It makes me angry even thinking about it.
Be the change you want to see in the world.
It is one thing to write the needed software, it is a much bigger task to convince enough companies that they need a different approach to this problem.
However, what I can offer is that if someone has the backing to actually make a difference in this market, I'll volunteer 50 hours to act as a reviewer and test developer. But that is if your project is backed by someone I believe can make a difference.
Re: Bypassing airport security via SQL injection
#390Earlier quoted context omitted.
I would argue, the most effective change post 9/11, is the reinforcement of cockpit doors, and stricter cockpit access procedures.
Which, ironically, made it impossible to prevent this crash: https://en.wikipedia.org/wiki/Germanwings_Flight_9525