Saturday, 7 Feb 2026
Subscribe
logo
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Font ResizerAa
Data Center NewsData Center News
Search
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Data Center News > Blog > Security > Researchers say a bug let them add fake pilots to rosters used for TSA checks
Security

Researchers say a bug let them add fake pilots to rosters used for TSA checks

Last updated: September 8, 2024 6:42 pm
Published September 8, 2024
Share
The UK beefs up smart home security by going after bad default passwords
SHARE

A pair of safety researchers say they found a vulnerability in login techniques for data that the Transportation Safety Administration (TSA) makes use of to confirm airline crew members at airport safety checkpoints. The bug let anybody with a “fundamental data of SQL injection” add themselves to airline rosters, doubtlessly letting them breeze by way of safety and into the cockpit of a industrial airplane, researcher Ian Carroll wrote in a weblog publish in August.

Carroll and his associate, Sam Curry, apparently found the vulnerability whereas probing the third-party web site of a vendor referred to as FlyCASS that gives smaller airways entry to the TSA’s Identified Crewmember (KCM) system and Cockpit Entry Safety System (CASS). They discovered that once they put a easy apostrophe into the username discipline, they obtained a MySQL error.

This was a really dangerous signal, because it appeared the username was straight interpolated into the login SQL question. Positive sufficient, we had found SQL injection and had been ready to make use of sqlmap to substantiate the difficulty. Utilizing the username of ‘ or ‘1’=’1 and password of ‘) OR MD5(‘1’)=MD5(‘1, we had been capable of login to FlyCASS as an administrator of Air Transport Worldwide!

As soon as they had been in, Carroll writes that there was “no additional test or authentication” stopping them from including crew data and photographs for any airline that makes use of FlyCASS. Anybody who might need used the vulnerability may current a pretend worker quantity to get by way of a KCM safety checkpoint, the weblog says.

TSA press secretary R. Carter Langston denied that, telling Bleeping Pc that the company “doesn’t solely depend on this database to authenticate flight crew, and that “solely verified crewmembers are permitted entry to the safe space in airports.”

See also  Report: Google Pixel phones sold with hidden surveillance software

Source link

TAGGED: add, Bug, checks, fake, pilots, researchers, rosters, TSA
Share This Article
Twitter Email Copy Link Print
Previous Article Konskie, Poland - January 03, 2024: Broadcom Inc company logo displayed on mobile phone screen AT&T sues Broadcom over breach of contract, cites threat to national security
Next Article Cars talking to one another could help reduce fatal crashes on US roads Cars talking to one another could help reduce fatal crashes on US roads
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Stay ahead with real-time updates on the latest events, trends.
FacebookLike
TwitterFollow
InstagramFollow
YoutubeSubscribe
LinkedInFollow
MediumFollow
- Advertisement -
Ad image

Popular Posts

ADT’s still unannounced security system that works with Google Nest could launch as soon as next month

All signs are pointing to an imminent launch of ADT’s new Smart Home Security System,…

January 30, 2024

Researchers integrate a quantum computer into a high-performance computing environment

The HPC cluster LEO 5 on the College of Innsbruck provides as much as 250…

July 24, 2024

Monet Raises £17M in Early-Stage Funding

Monet, a London, UK-based monetary platform enhancing cashflow administration for inventive businesses, raised £17M in…

July 24, 2025

Using AI for IT automation security

Lori MacVittie, Distinguished Engineer at F5, seems at how AI will form the way forward…

March 10, 2024

Ofqual poll highlights the value of cybersecurity in schools

A brand new Ofqual ballot has highlighted the significance of cybersecurity in colleges after it…

October 1, 2024

You Might Also Like

Moving experimental pilots to AI production
AI

Moving experimental pilots to AI production

By saad
Enterprise users swap AI pilots for deep integrations
AI

Enterprise users swap AI pilots for deep integrations

By saad
Why most enterprise AI coding pilots underperform (Hint: It's not the model)
AI

Why most enterprise AI coding pilots underperform (Hint: It's not the model)

By saad
Instacart pilots agentic commerce by embedding in ChatGPT
AI

Instacart pilots agentic commerce by embedding in ChatGPT

By saad
Data Center News
Facebook Twitter Youtube Instagram Linkedin

About US

Data Center News: Stay informed on the pulse of data centers. Latest updates, tech trends, and industry insights—all in one place. Elevate your data infrastructure knowledge.

Top Categories
  • Global Market
  • Infrastructure
  • Innovations
  • Investments
Usefull Links
  • Home
  • Contact
  • Privacy Policy
  • Terms & Conditions

© 2024 – datacenternews.tech – All rights reserved

Welcome Back!

Sign in to your account

Lost your password?
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.
You can revoke your consent any time using the Revoke consent button.