Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    B3 gains Andromeda’s insights and launches crypto-enabled B3PC

    June 18, 2025

    The most profitable BTC cloud mining for beginners in 2025

    June 17, 2025

    Sandbox adds trivia game templates to latest updates

    June 17, 2025
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    Comic Vibe
    Subscribe
    • Home
    • Comics
    • Gaming
    • Movies
    • TV
    • Anime
    • Toys
    • Cosplay
    • Tech
    • NFT
    • Metaverse
    • Events
    Comic Vibe
    Home»Tech»Researchers say a mistake allowed them to add fake pilots to rosters used for TSA inspections
    Tech

    Researchers say a mistake allowed them to add fake pilots to rosters used for TSA inspections

    Comic VibeBy Comic VibeSeptember 8, 2024No Comments2 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Two security researchers say they discovered a flaw in the log-in system used by the Transportation Security Administration (TSA) to authenticate airline crew members at airport security checkpoints. Researcher Ian Carroll wrote in an August blog post that the vulnerability could allow anyone with “basic knowledge of SQL injection” to add themselves to an airline roster, potentially allowing They breeze through security and into the cockpit of a commercial aircraft.

    Carroll and his partner, Sam Curry, apparently discovered the vulnerability while investigating the third-party website of a vendor called FlyCASS, which provides small airlines with access to the TSA Known Crew (KCM) system. and the Cockpit Access Security System (CASS). They discovered that when they entered a simple apostrophe in the username field, they received a MySQL error.

    This is a very bad sign because the username appears to be inserted directly into the login SQL query. Sure enough, we discovered SQL injection and were able to use sqlmap to confirm the problem. Using username’ or ‘1’=’1 and password’) OR MD5(‘1’)=MD5(‘1, we were able to log into FlyCASS as an administrator of Air Transport International!

    Once they were in, “no further checks or identity verification” prevented them from adding crew records and photos from any airlines using FlyCASS, Carroll wrote. The blog states that anyone who could potentially exploit this vulnerability could provide a false employee number to pass the KCM security checkpoint.

    TSA press secretary R. Carter Langston denied this, saying Computer beeps The agency “does not rely solely on this database to verify the identities of crew members, but only verified crew members are allowed into secure areas of the airport.”

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Comic Vibe

    Related Posts

    The ending of “Folie à Deux” comes from an abandoned idea of ​​the first film

    October 7, 2024

    Apple’s next MacBook Pro may have leaked in Russia

    October 7, 2024

    The best early October Prime Day MacBook deals: Amazon shopping at record lows

    October 7, 2024

    Samsung launches Neo QLED 4K smart TV with discounts of up to $1,755 to compete with Amazon Prime Day

    October 7, 2024
    Add A Comment

    Comments are closed.

    Our Picks
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Don't Miss
    NFT

    B3 gains Andromeda’s insights and launches crypto-enabled B3PC

    By Comic VibeJune 18, 20250

    Ethereum-based gaming protocol B3 has announced the acquisition of US PC maker Andromeda Insights, marking…

    The most profitable BTC cloud mining for beginners in 2025

    June 17, 2025

    Sandbox adds trivia game templates to latest updates

    June 17, 2025

    MoonFrost OG Mystery Box NFT Mint, Raise $275,000

    June 17, 2025
    Editors Picks
    Top Reviews
    Our Picks

    B3 gains Andromeda’s insights and launches crypto-enabled B3PC

    June 18, 2025

    The most profitable BTC cloud mining for beginners in 2025

    June 17, 2025

    Sandbox adds trivia game templates to latest updates

    June 17, 2025
    Legal Pages
    • About Us
    • Contact Us
    • Disclaimer
    • Privacy Policy
    Our Picks

    Type above and press Enter to search. Press Esc to cancel.