Thursday, 26 Mar 2026
Subscribe
logo
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Font ResizerAa
Data Center NewsData Center News
Search
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Data Center News > Blog > Security > Researchers say a bug let them add fake pilots to rosters used for TSA checks
Security

Researchers say a bug let them add fake pilots to rosters used for TSA checks

Last updated: September 8, 2024 6:42 pm
Published September 8, 2024
Share
The UK beefs up smart home security by going after bad default passwords
SHARE

A pair of safety researchers say they found a vulnerability in login techniques for data that the Transportation Safety Administration (TSA) makes use of to confirm airline crew members at airport safety checkpoints. The bug let anybody with a “fundamental data of SQL injection” add themselves to airline rosters, doubtlessly letting them breeze by way of safety and into the cockpit of a industrial airplane, researcher Ian Carroll wrote in a weblog publish in August.

Carroll and his associate, Sam Curry, apparently found the vulnerability whereas probing the third-party web site of a vendor referred to as FlyCASS that gives smaller airways entry to the TSA’s Identified Crewmember (KCM) system and Cockpit Entry Safety System (CASS). They discovered that once they put a easy apostrophe into the username discipline, they obtained a MySQL error.

This was a really dangerous signal, because it appeared the username was straight interpolated into the login SQL question. Positive sufficient, we had found SQL injection and had been ready to make use of sqlmap to substantiate the difficulty. Utilizing the username of ‘ or ‘1’=’1 and password of ‘) OR MD5(‘1’)=MD5(‘1, we had been capable of login to FlyCASS as an administrator of Air Transport Worldwide!

As soon as they had been in, Carroll writes that there was “no additional test or authentication” stopping them from including crew data and photographs for any airline that makes use of FlyCASS. Anybody who might need used the vulnerability may current a pretend worker quantity to get by way of a KCM safety checkpoint, the weblog says.

TSA press secretary R. Carter Langston denied that, telling Bleeping Pc that the company “doesn’t solely depend on this database to authenticate flight crew, and that “solely verified crewmembers are permitted entry to the safe space in airports.”

See also  Microsoft Is Getting a New 'Outsider' CISO | DCN

Source link

TAGGED: add, Bug, checks, fake, pilots, researchers, rosters, TSA
Share This Article
Twitter Email Copy Link Print
Previous Article Konskie, Poland - January 03, 2024: Broadcom Inc company logo displayed on mobile phone screen AT&T sues Broadcom over breach of contract, cites threat to national security
Next Article Cars talking to one another could help reduce fatal crashes on US roads Cars talking to one another could help reduce fatal crashes on US roads
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Stay ahead with real-time updates on the latest events, trends.
FacebookLike
TwitterFollow
InstagramFollow
YoutubeSubscribe
LinkedInFollow
MediumFollow
- Advertisement -
Ad image

Popular Posts

Vast Raises New Funding

Vast, a Sydney, Australia-based clear power expertise firm, raised an undisclosed quantity in new funding.…

August 11, 2025

EDGNEX Data Centers by DAMAC invests in Spain

The 22,000 sqm facility, with the dedicated energy of 40MW, is scheduled to begin operations…

October 16, 2024

Arrcus Raises $30M in Funding

Arrcus, a San Jose, CA-based hyperscale networking software program firm, raised $30M in funding. The…

July 21, 2024

Vertiv introduces compact, high-power density UPS

Vertiv has launched the Vertiv™ PowerUPS 9000, an energy-efficient, high-power density uninterruptible energy provide (UPS)…

December 4, 2024

Google’s 2 billion dollar data center in Malaysia: a game changer for global AI technology

The world of expertise is ever-evolving, and as a part of this, sure tech giants…

June 2, 2024

You Might Also Like

Could Telehouse be about to add a sixth data centre to its Docklands campus?
Global Market

Could Telehouse be about to add a sixth data centre to its Docklands campus?

By saad
Scale Computing buys Adaptiv Networks to add SD-WAN and SASE and deepen edge networking push
Edge Computing

Scale Computing buys Adaptiv Networks to add SD-WAN and SASE and deepen edge networking push

By saad
DBS pilots system that lets AI agents make payments for customers
AI

DBS pilots system that lets AI agents make payments for customers

By saad
Debenhams pilots agentic AI commerce via PayPal integration
AI

Debenhams pilots agentic AI commerce via PayPal integration

By saad
Data Center News
Facebook Twitter Youtube Instagram Linkedin

About US

Data Center News: Stay informed on the pulse of data centers. Latest updates, tech trends, and industry insights—all in one place. Elevate your data infrastructure knowledge.

Top Categories
  • Global Market
  • Infrastructure
  • Innovations
  • Investments
Usefull Links
  • Home
  • Contact
  • Privacy Policy
  • Terms & Conditions

© 2024 – datacenternews.tech – All rights reserved

Welcome Back!

Sign in to your account

Lost your password?
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.
You can revoke your consent any time using the Revoke consent button.