Live data from Hacker News

Bypassing airport security via SQL injection

ian.sh

441–450 of 459 posts

Re: Bypassing airport security via SQL injection

#441
post #439

Earlier quoted context omitted.

I’ve assumed you still have to have a ticket and they’re matching ID to the tickets in database. Anyone know otherwise? I can say, I asked the airline for a pass to accompany a passenger to their gate in ATL. If ID was enough I expect they would have told me so, but they gave me a paper pass and said it’s only good for one entrance into secured area.

I obviously can't verify it without taking undue risks, but I remember they used to ask to see the boarding pass, now they don't. Then again, if they have this system where they can match me to a flight by ID, why they need any boarding passes at all? Just ask to see my ID again when boarding the plane, no? Why boarding passes still exist if this system is in place?

Blissfully, I have not flown since 2012.

Thanks for the updated TSA experience.

Re: Bypassing airport security via SQL injection

#442
post #47

Earlier quoted context omitted.

Is this a reference to a past event? I don't get it.

In part yes but inevitably devolves into an ad hominem attack against the most high profile case of a guy who did it, who is now hiding in Ukraine on a Prednistrovian passport after having his conviction overturned (temporarily) giving him an escape window.

Weev hasn’t been in Ukraine in a good few years. He was last confirmed spotted in Transnistria before the 2022 invasion and apparently hasn’t moved on since.

His stay in Ukraine was rather brief, he was… not well liked there.

Re: Bypassing airport security via SQL injection

#443
post #439

Earlier quoted context omitted.

I obviously can't verify it without taking undue risks, but I remember they used to ask to see the boarding pass, now they don't. Then again, if they have this system where they can match me to a flight by ID, why they need any boarding passes at all? Just ask to see my ID again when boarding the plane, no? Why boarding passes still exist if this system is in place?

Blissfully, I have not flown since 2012. Thanks for the updated TSA experience.

If you have precheck, TSA is pretty much not an issue now (unless you fly out of one of badly run airports where they are massively under-provisioned) - just ID check and quick metal detector pass usually does it.

Re: Bypassing airport security via SQL injection

#444
post #319

The safety of airports and air travel compromised by a simple SQL injection ? What is it, the year 2000 ? It should be a criminal offence for whoever developed that system.

If there are any criminal charges here it will be for the reporters. Not the developers. To think otherwise is beyond naive.

I said there should be, not that there will be :)

Re: Bypassing airport security via SQL injection

#445
post #410

Earlier quoted context omitted.

> If the managers involved here can't understand why this is a huge deal Was it a huge deal though?

It was the most humongous deal if we talk about IT security. SQL injection shouldn't be a thing in today's IT landscapes. And here we are giving everyone and their mother admin access to a database where the attackers can literally get not only on a plane but also in the fucking Cockpit. So yes, big big deal.

It wasn’t an sql injection in their code. It was a third party issue.

So internally the question would probably how can you open it up responsibly.

Closing the api is probably a support nightmare; they probably gave too many rights and too little safety checks.

Re: Bypassing airport security via SQL injection

#446
It's a stupid system anyway. Corrupt airline staff can easily bypass all security checks, bring a pistol in a handbag and leave that in the cabin luggage bin for prearranged pickup by an unscrupulous passenger or any sort of shenanigans.

How do they protect against corrupt staff. It's like they're not even thinking. Why don't they just fast track staff checks.

Re: Bypassing airport security via SQL injection

#447
Xnxnxnkzjzmxnnzcskdyxk buenos días amor cómo amaneciste mi cielo bello como te fue en el estudio shdtdhdc te e dicho algo y me avisas cuando llegues a tu casa para ti gracias a Dios por tu salud te amo mucho en el trabajo de dgd Je je pero no sé dónde es eso de las cosas y te sientes por usted es que no me avisas cuando te e udbgzdh si te amo más extremo de

Re: Bypassing airport security via SQL injection

#449
post #422

Earlier quoted context omitted.

This is easily prevented by requiring at least 2 people in the cockpit at all times. Some airlines had this policy long before Germanwings happened.

There's also at least one case[1] where the locked door itself stopped someone from stopping the crash (the CA had flying experience and Mentor Pilot[2] showed that even someone with no flying experience could be instructed to autoland if they know how to use the radio. If the CA had entered earlier they might've been able to land, though most of the passengers would've still died unfortunately.) One of the more reas…

1> At 11:49, flight attendant Andreas Prodromou entered the cockpit and sat down in the captain's seat, having remained conscious by using a portable oxygen supply.

Re: Bypassing airport security via SQL injection

#450
post #69
post #14

Earlier quoted context omitted.

You're not wrong, but I would have a hard time as a jury member convicting them of a CFAA violation or whatever for creating a user named "Test TestOnly" with a bright pink image instead of a photo. If they had added themselves as known crewmembers and used that to actually bypass airport screening, then yeah, they'd be in jail.

That's what jury instructions are for. The judge can instruct the jury to ignore pretty much any facts and consider any subset of what really happened that they want. So they'd just instruct "did they access the system? Were they authorized? If the answer to the first question is yes, and to the second is no, the verdict is guilty, ignore all the rest". The jury won't be from the HN crowd, it would be random people w…

> That's what jury instructions are for. The judge can instruct the jury to ignore pretty much any facts and consider any subset of what really happened that they want. So they'd just instruct "did they access the system? Were they authorized? If the answer to the first question is yes, and to the second is no, the verdict is guilty, ignore all the rest".

The only real protection is the fact that you can vote whatever way you want and not even a judge can compel you to state your reasoning.

Post reply on HN