Tuesday, 16 Dec 2025
Subscribe
logo
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Font ResizerAa
Data Center NewsData Center News
Search
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Data Center News > Blog > Security > Researchers say a bug let them add fake pilots to rosters used for TSA checks
Security

Researchers say a bug let them add fake pilots to rosters used for TSA checks

Last updated: September 8, 2024 6:42 pm
Published September 8, 2024
Share
The UK beefs up smart home security by going after bad default passwords
SHARE

A pair of safety researchers say they found a vulnerability in login techniques for data that the Transportation Safety Administration (TSA) makes use of to confirm airline crew members at airport safety checkpoints. The bug let anybody with a “fundamental data of SQL injection” add themselves to airline rosters, doubtlessly letting them breeze by way of safety and into the cockpit of a industrial airplane, researcher Ian Carroll wrote in a weblog publish in August.

Carroll and his associate, Sam Curry, apparently found the vulnerability whereas probing the third-party web site of a vendor referred to as FlyCASS that gives smaller airways entry to the TSA’s Identified Crewmember (KCM) system and Cockpit Entry Safety System (CASS). They discovered that once they put a easy apostrophe into the username discipline, they obtained a MySQL error.

This was a really dangerous signal, because it appeared the username was straight interpolated into the login SQL question. Positive sufficient, we had found SQL injection and had been ready to make use of sqlmap to substantiate the difficulty. Utilizing the username of ‘ or ‘1’=’1 and password of ‘) OR MD5(‘1’)=MD5(‘1, we had been capable of login to FlyCASS as an administrator of Air Transport Worldwide!

As soon as they had been in, Carroll writes that there was “no additional test or authentication” stopping them from including crew data and photographs for any airline that makes use of FlyCASS. Anybody who might need used the vulnerability may current a pretend worker quantity to get by way of a KCM safety checkpoint, the weblog says.

TSA press secretary R. Carter Langston denied that, telling Bleeping Pc that the company “doesn’t solely depend on this database to authenticate flight crew, and that “solely verified crewmembers are permitted entry to the safe space in airports.”

See also  Report: Google Pixel phones sold with hidden surveillance software

Source link

TAGGED: add, Bug, checks, fake, pilots, researchers, rosters, TSA
Share This Article
Twitter Email Copy Link Print
Previous Article Konskie, Poland - January 03, 2024: Broadcom Inc company logo displayed on mobile phone screen AT&T sues Broadcom over breach of contract, cites threat to national security
Next Article Cars talking to one another could help reduce fatal crashes on US roads Cars talking to one another could help reduce fatal crashes on US roads
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Stay ahead with real-time updates on the latest events, trends.
FacebookLike
TwitterFollow
InstagramFollow
YoutubeSubscribe
LinkedInFollow
MediumFollow
- Advertisement -
Ad image

Popular Posts

BCS expands utilities division with new service lines

BCS, famend for its international information centre consultancy, has strategically expanded its Utilities Division, introducing…

August 13, 2025

Rippling Raises $200M in Financing

Rippling, a San Francisco, CA-based workforce administration startup, raised $200M in new financing. The corporate…

April 23, 2024

Husqvarna Group to Acquire InCeres

Husqvarna Group, a Stockholm, Sweden-based firm which makes a speciality of manufacturing revolutionary merchandise and…

August 23, 2024

Tracking user logins on Linux

The command under experiences on common (not system) customers – people with residence directories in…

September 18, 2024

Sedna Communications, a London, UK-based received $10M in Growth investment from CIBC Innovation Basking.

Sedna Communications, a London, UK-based AI-driven platform for maritime and provide chain companies, acquired $10M…

April 5, 2025

You Might Also Like

Enterprise users swap AI pilots for deep integrations
AI

Enterprise users swap AI pilots for deep integrations

By saad
Why most enterprise AI coding pilots underperform (Hint: It's not the model)
AI

Why most enterprise AI coding pilots underperform (Hint: It's not the model)

By saad
Instacart pilots agentic commerce by embedding in ChatGPT
AI

Instacart pilots agentic commerce by embedding in ChatGPT

By saad
Nvidia’s Upbeat Forecast Soothes Fears of AI Bubble
Security

Nvidia’s Upbeat Forecast Soothes Fears of AI Bubble

By saad
Data Center News
Facebook Twitter Youtube Instagram Linkedin

About US

Data Center News: Stay informed on the pulse of data centers. Latest updates, tech trends, and industry insights—all in one place. Elevate your data infrastructure knowledge.

Top Categories
  • Global Market
  • Infrastructure
  • Innovations
  • Investments
Usefull Links
  • Home
  • Contact
  • Privacy Policy
  • Terms & Conditions

© 2024 – datacenternews.tech – All rights reserved

Welcome Back!

Sign in to your account

Lost your password?
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.
You can revoke your consent any time using the Revoke consent button.