Live data from Hacker News

Bypassing airport security via SQL injection

ian.sh

71–80 of 401 posts

Re: Bypassing airport security via SQL injection

#72
i wonder if TSA will audit the entire list, also it opens up more questions too like how long accounts remain active? are they simply assuming each airline will update pilot status? they clearly haven't been treating this sytem as important it seems.

Re: Bypassing airport security via SQL injection

#73
post #18

Hilarious that the entire TSA system is vulnerable to the most basic web programming error that you generally learn to avoid 10 minutes into reading about web programming- and that every decent quality web framework automatically prevents. It is really telling that they try to cover up and deny instead of fix it, but not surprising. That is a natural consequence of authoritarian thinking, which is the entire premise…

> Hilarious that the entire TSA system is vulnerable to the most basic web programming error that you generally learn to avoid 10 minutes The article mentions that FlyCASS seems to be run by one person. This isn't a matter of technical chops, this is a matter of someone who is good at navigating bureaucracy convincing the powers that be that they should have a special hook into the system. What should really be inves…

> FlyCASS seems to be run by one person

Is their name Jia Tan, by chance?

Re: Bypassing airport security via SQL injection

#74
post #14
post #9

Since they actually went past the SQL injection and then created a fake record for an employee, I'm shocked that Homeland did not come after and arrest those involved. Homeland would have been top of the list to misinterpret a disclosure and prefer to refer to the disclosure as malicious hacking instead of responsible disclosure. I'm more impressed by this than the incompetence of the actual issue.

You're not wrong, but I would have a hard time as a jury member convicting them of a CFAA violation or whatever for creating a user named "Test TestOnly" with a bright pink image instead of a photo. If they had added themselves as known crewmembers and used that to actually bypass airport screening, then yeah, they'd be in jail.

But would it really matter if they were convicted, after being in jail for who knows how long awaiting trial, losing their job, etc?

Re: Bypassing airport security via SQL injection

#75
post #59

Earlier quoted context omitted.

We know that backdoors can be intentional for use by 3-letter agencies. And there is plausible deniability of the bureaucracy when they can pass blame onto a single individual. Or it's beuracracy being beuracracy. The TSA is a lot of security theater anyways.

This is a bit of ridiculous comment. Who in the right mind would say a sql injection is a backdoor for a 3LA? Added, why would they use FlyCass when they could just access the data directly?

To move someone from one place to another without an official record of the person?

Honeypot? Legit logins are logged differently than non-legit?

Re: Bypassing airport security via SQL injection

#76
post #9

Since they actually went past the SQL injection and then created a fake record for an employee, I'm shocked that Homeland did not come after and arrest those involved. Homeland would have been top of the list to misinterpret a disclosure and prefer to refer to the disclosure as malicious hacking instead of responsible disclosure. I'm more impressed by this than the incompetence of the actual issue.

If anyone from there reads the parent, they should know they have created an atmosphere where the worry of possible prosecution over responsible disclosure has the potential to scare away the best minds in our country from picking at these systems. That just means the best minds from other, potentially less friendly countries, will do the picking. I doubt they will responsibly disclose.

I personally don't comprehend how these people are taking such a huge risks. Once bureaucrat wakes one morning in the wrong mood and your life is ruined at least for the next decade, maybe forever. Why would anyone do it - just for the thrill of it? I don't think they even got paid for it?

Re: Bypassing airport security via SQL injection

#77

Earlier quoted context omitted.

> Hilarious that the entire TSA system is vulnerable to the most basic web programming error that you generally learn to avoid 10 minutes The article mentions that FlyCASS seems to be run by one person. This isn't a matter of technical chops, this is a matter of someone who is good at navigating bureaucracy convincing the powers that be that they should have a special hook into the system. What should really be inves…

Someting I’ve been thinking about, esp since that crowdstrike debacle. Why do major distributors of infrastructure (msft in case of crowdstrike, DHS/TSA here) not require that vendors with privileged software access have passed some sort of software distribution/security audit? If FlyCASS had been required to undergo basic security testing, this (specific) issue would not exist

They often do. The value of those kinds of blanket security audits is questionable, however.

(This is one of the reasons I'm generally pro-OSS for digital infrastructure: security quickly becomes a compliance game at the scale of government, meaning that it's more about diligently completing checklists and demonstrating that diligence than about critically evaluating a component's security. OSS doesn't make software secure, but it does make it easier for the interested public to catch things before they become crises.)

Re: Bypassing airport security via SQL injection

#78
post #75

Earlier quoted context omitted.

This is a bit of ridiculous comment. Who in the right mind would say a sql injection is a backdoor for a 3LA? Added, why would they use FlyCass when they could just access the data directly?

To move someone from one place to another without an official record of the person? Honeypot? Legit logins are logged differently than non-legit?

yes, they _definitely_ need to access flycass to achieve this. Almost certainly no other way.

Re: Bypassing airport security via SQL injection

#79

Earlier quoted context omitted.

Depends. If no one currently cares, there is no significant structure or personnel or political change in the future several years, and they don't have any assets worth taking, and the government doesn't get any more desperate for assets to seize -- then they're out of the woods.

I doubt asset seizure is what they'd be after. I was thinking more of the "make an example out of them" mentality as an attempt to prevent others from being curious. Government entities don't tend to do well with knowing the difference of malicious hacking and responsible disclosure. The infamous governor and the View Source is a fun one to trot out as exhibit A.

Asset seizure is not because the government needs the money. It's because you need the money to pay for lawyers, legal experts, etc., and if your assets are seized, you can't - so you are much easier to pressure into making a quick guilty plea and get another successful prosecution added to the list. Of course, the whole process is the punishment as usual, but the asset seizure also plays an important coercive role there.

Re: Bypassing airport security via SQL injection

#80
> 05/17/2024: Follow-up to DHS CISO about TSA statements (no reply)

> 06/04/2024: Follow-up to DHS CISO about TSA statements (no reply)

There should be a public Shitlist of Organisations that don't get the Benefit of Responsible Disclosure anymore, just a Pastebin drop linked to 4chan.

Post reply on HN