Bypassing airport security via SQL injection
71–80 of 401 posts
Re: Bypassing airport security via SQL injection
#72Re: Bypassing airport security via SQL injection
#73Hilarious that the entire TSA system is vulnerable to the most basic web programming error that you generally learn to avoid 10 minutes into reading about web programming- and that every decent quality web framework automatically prevents. It is really telling that they try to cover up and deny instead of fix it, but not surprising. That is a natural consequence of authoritarian thinking, which is the entire premise…
> Hilarious that the entire TSA system is vulnerable to the most basic web programming error that you generally learn to avoid 10 minutes The article mentions that FlyCASS seems to be run by one person. This isn't a matter of technical chops, this is a matter of someone who is good at navigating bureaucracy convincing the powers that be that they should have a special hook into the system. What should really be inves…
Is their name Jia Tan, by chance?
Re: Bypassing airport security via SQL injection
#74Since they actually went past the SQL injection and then created a fake record for an employee, I'm shocked that Homeland did not come after and arrest those involved. Homeland would have been top of the list to misinterpret a disclosure and prefer to refer to the disclosure as malicious hacking instead of responsible disclosure. I'm more impressed by this than the incompetence of the actual issue.
You're not wrong, but I would have a hard time as a jury member convicting them of a CFAA violation or whatever for creating a user named "Test TestOnly" with a bright pink image instead of a photo. If they had added themselves as known crewmembers and used that to actually bypass airport screening, then yeah, they'd be in jail.
Re: Bypassing airport security via SQL injection
#75Earlier quoted context omitted.
We know that backdoors can be intentional for use by 3-letter agencies. And there is plausible deniability of the bureaucracy when they can pass blame onto a single individual. Or it's beuracracy being beuracracy. The TSA is a lot of security theater anyways.
This is a bit of ridiculous comment. Who in the right mind would say a sql injection is a backdoor for a 3LA? Added, why would they use FlyCass when they could just access the data directly?
Honeypot? Legit logins are logged differently than non-legit?
Re: Bypassing airport security via SQL injection
#76Since they actually went past the SQL injection and then created a fake record for an employee, I'm shocked that Homeland did not come after and arrest those involved. Homeland would have been top of the list to misinterpret a disclosure and prefer to refer to the disclosure as malicious hacking instead of responsible disclosure. I'm more impressed by this than the incompetence of the actual issue.
If anyone from there reads the parent, they should know they have created an atmosphere where the worry of possible prosecution over responsible disclosure has the potential to scare away the best minds in our country from picking at these systems. That just means the best minds from other, potentially less friendly countries, will do the picking. I doubt they will responsibly disclose.
Re: Bypassing airport security via SQL injection
#77Earlier quoted context omitted.
> Hilarious that the entire TSA system is vulnerable to the most basic web programming error that you generally learn to avoid 10 minutes The article mentions that FlyCASS seems to be run by one person. This isn't a matter of technical chops, this is a matter of someone who is good at navigating bureaucracy convincing the powers that be that they should have a special hook into the system. What should really be inves…
Someting I’ve been thinking about, esp since that crowdstrike debacle. Why do major distributors of infrastructure (msft in case of crowdstrike, DHS/TSA here) not require that vendors with privileged software access have passed some sort of software distribution/security audit? If FlyCASS had been required to undergo basic security testing, this (specific) issue would not exist
(This is one of the reasons I'm generally pro-OSS for digital infrastructure: security quickly becomes a compliance game at the scale of government, meaning that it's more about diligently completing checklists and demonstrating that diligence than about critically evaluating a component's security. OSS doesn't make software secure, but it does make it easier for the interested public to catch things before they become crises.)
Re: Bypassing airport security via SQL injection
#78Earlier quoted context omitted.
This is a bit of ridiculous comment. Who in the right mind would say a sql injection is a backdoor for a 3LA? Added, why would they use FlyCass when they could just access the data directly?
To move someone from one place to another without an official record of the person? Honeypot? Legit logins are logged differently than non-legit?
Re: Bypassing airport security via SQL injection
#79Earlier quoted context omitted.
Depends. If no one currently cares, there is no significant structure or personnel or political change in the future several years, and they don't have any assets worth taking, and the government doesn't get any more desperate for assets to seize -- then they're out of the woods.
I doubt asset seizure is what they'd be after. I was thinking more of the "make an example out of them" mentality as an attempt to prevent others from being curious. Government entities don't tend to do well with knowing the difference of malicious hacking and responsible disclosure. The infamous governor and the View Source is a fun one to trot out as exhibit A.
Re: Bypassing airport security via SQL injection
#80> 06/04/2024: Follow-up to DHS CISO about TSA statements (no reply)
There should be a public Shitlist of Organisations that don't get the Benefit of Responsible Disclosure anymore, just a Pastebin drop linked to 4chan.