Saturday, 28 Feb 2026
Subscribe
logo
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Font ResizerAa
Data Center NewsData Center News
Search
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Data Center News > Blog > Security > Researchers say a bug let them add fake pilots to rosters used for TSA checks
Security

Researchers say a bug let them add fake pilots to rosters used for TSA checks

Last updated: September 8, 2024 6:42 pm
Published September 8, 2024
Share
The UK beefs up smart home security by going after bad default passwords
SHARE

A pair of safety researchers say they found a vulnerability in login techniques for data that the Transportation Safety Administration (TSA) makes use of to confirm airline crew members at airport safety checkpoints. The bug let anybody with a “fundamental data of SQL injection” add themselves to airline rosters, doubtlessly letting them breeze by way of safety and into the cockpit of a industrial airplane, researcher Ian Carroll wrote in a weblog publish in August.

Carroll and his associate, Sam Curry, apparently found the vulnerability whereas probing the third-party web site of a vendor referred to as FlyCASS that gives smaller airways entry to the TSA’s Identified Crewmember (KCM) system and Cockpit Entry Safety System (CASS). They discovered that once they put a easy apostrophe into the username discipline, they obtained a MySQL error.

This was a really dangerous signal, because it appeared the username was straight interpolated into the login SQL question. Positive sufficient, we had found SQL injection and had been ready to make use of sqlmap to substantiate the difficulty. Utilizing the username of ‘ or ‘1’=’1 and password of ‘) OR MD5(‘1’)=MD5(‘1, we had been capable of login to FlyCASS as an administrator of Air Transport Worldwide!

As soon as they had been in, Carroll writes that there was “no additional test or authentication” stopping them from including crew data and photographs for any airline that makes use of FlyCASS. Anybody who might need used the vulnerability may current a pretend worker quantity to get by way of a KCM safety checkpoint, the weblog says.

TSA press secretary R. Carter Langston denied that, telling Bleeping Pc that the company “doesn’t solely depend on this database to authenticate flight crew, and that “solely verified crewmembers are permitted entry to the safe space in airports.”

See also  Data Center News Roundup: Welcome to 2025

Source link

TAGGED: add, Bug, checks, fake, pilots, researchers, rosters, TSA
Share This Article
Twitter Email Copy Link Print
Previous Article Konskie, Poland - January 03, 2024: Broadcom Inc company logo displayed on mobile phone screen AT&T sues Broadcom over breach of contract, cites threat to national security
Next Article Cars talking to one another could help reduce fatal crashes on US roads Cars talking to one another could help reduce fatal crashes on US roads
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Stay ahead with real-time updates on the latest events, trends.
FacebookLike
TwitterFollow
InstagramFollow
YoutubeSubscribe
LinkedInFollow
MediumFollow
- Advertisement -
Ad image

Popular Posts

‘Metabots’ shapeshift from flat sheets into hundreds of structures

Researchers have created a category of robots constituted of skinny sheets of fabric related into…

October 16, 2025

A New Bottleneck in the Data Center Supply Chain

Simply because it appeared that the tech {hardware} provide chain was recovering from COVID-induced shortages,…

August 8, 2024

ZTE Unveils AI-Driven, Sustainable Data Center Tech at DCW Frankfurt 2025

ZTE showcases AI-driven, energy-efficient information middle improvements at DCW Frankfurt 2025, emphasizing sustainability, scalability, and…

June 7, 2025

The ICO’s role in balancing AI development

The Innovation Platform spoke with Sophia Ignatidou, Group Supervisor, AI Coverage on the Information Commissioner’s…

September 5, 2025

Arrcus upgrades ACE-AI solution for distributed AI applications at the edge

Arrcus, an organization specializing in hyperscale networking software program, has introduced upgrades to its ACE-AI…

March 1, 2024

You Might Also Like

DBS pilots system that lets AI agents make payments for customers
AI

DBS pilots system that lets AI agents make payments for customers

By saad
Debenhams pilots agentic AI commerce via PayPal integration
AI

Debenhams pilots agentic AI commerce via PayPal integration

By saad
Moving experimental pilots to AI production
AI

Moving experimental pilots to AI production

By saad
Enterprise users swap AI pilots for deep integrations
AI

Enterprise users swap AI pilots for deep integrations

By saad
Data Center News
Facebook Twitter Youtube Instagram Linkedin

About US

Data Center News: Stay informed on the pulse of data centers. Latest updates, tech trends, and industry insights—all in one place. Elevate your data infrastructure knowledge.

Top Categories
  • Global Market
  • Infrastructure
  • Innovations
  • Investments
Usefull Links
  • Home
  • Contact
  • Privacy Policy
  • Terms & Conditions

© 2024 – datacenternews.tech – All rights reserved

Welcome Back!

Sign in to your account

Lost your password?
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.
You can revoke your consent any time using the Revoke consent button.