Connect with us

Hi, what are you looking for?

Fibonacci Tech News

Researchers say a bug let them add fake pilots to rosters used for TSA checks

Illustration by Carlo Cadenas / The Verge

A pair of security researchers say they discovered a vulnerability in login systems for records that the Transportation Security Administration (TSA) uses to verify airline crew members at airport security checkpoints. The bug let anyone with a “basic knowledge of SQL injection” add themselves to airline rosters, potentially letting them breeze through security and into the cockpit of a commercial airplane, researcher Ian Carroll wrote in a blog post in August.

Carroll and his partner, Sam Curry, apparently discovered the vulnerability while probing the third-party website of a vendor called FlyCASS that provides smaller airlines access to the TSA’s Known Crewmember (KCM) system and Cockpit Access Security System (CASS). They found that…

Continue reading…

You May Also Like

Fibonacci Stock News

In the previous technical note, it was categorically mentioned that while the markets may attempt to inch higher, they may not form anything beyond...

Fibonacci Investing News

Chris Edwards Many American cities need more low‐​income housing, but governments reduce supply and raise construction costs with regulations, taxes, and bureaucracy. The Wall...

Fibonacci Tech News

Illustration by Alex Castro / The Verge The question of who gets to regulate crypto has some answers, as a judge has ruled the...

Fibonacci Tech News

Image: Brazil Climate Summit At the moment I arrived at the Brazil Climate Summit event, it felt like home to me. As I opened...