知識

【】

字号+作者:囫圇吞棗網来源:休閑2025-02-28 23:46:20我要评论(0)

Everybody makes mistakes at work but, leaving the no-fly list exposed on the internet seems like a r

Everybody makes mistakes at work but, leaving the no-fly list exposed on the internet seems like a really bad mess-up.

That's reportedly what happened with the U.S. airline CommuteAir. The Daily Dot reported that a Swiss hacker known as "maia arson crimew" found the unsecured server while using the specialized search engine Shodan. There was apparently a lotof sensitive information on the server, including a version of the no-fly list from four years ago. Somewhat hilariously that was reportedly found via a text file labeled "NoFly.csv." That is...not hard to guess.

A blog post from crimew titled "how to completely own an airline in 3 easy steps" cited boredom as the reason for finding the server. They were just poking around and found it.

Mashable Light SpeedWant more out-of-this world tech, space and science stories?Sign up for Mashable's weekly Light Speed newsletter.By signing up you agree to our Terms of Use and Privacy Policy.Thanks for signing up!

"At this point, I've probably clicked through about 20 boring exposed servers with very little of any interest, when I suddenly start seeing some familiar words," crimew says in their blogpost. "'ACARS', lots of mentions of 'crew' and so on. Lots of words I've heard before, most likely while binge-watching Mentour Pilot YouTube videos. Jackpot. An exposed jenkins server belonging to CommuteAir."

CommuteAir, a regional US airline headquartered in Ohio, confirmed the info on the server was authentic to the Daily Dot. The server has been taken offline.


Related Stories
  • Delta Airlines to offer free WiFi on most domestic flights by February
  • Chinese government-linked hackers stole millions in COVID funds
  • Southwest Airlines is offering 25,000 rewards points to inconvenienced passengers. How to claim them.
  • Kickstart a career in cybersecurity with this ethical hacking and pen testing bundle
  • Hacker steals $100 million from crypto project Mango, then things get weird

"The server contained data from a 2019 version of the federal no-fly list that included first and last names and dates of birth," CommuteAir Corporate Communications Manager Erik Kane told the Daily Dot. "In addition, certain CommuteAir employee and flight information was accessible. We have submitted notification to the Cybersecurity and Infrastructure Security Agency and we are continuing with a full investigation."

The info from the server has already been poured over, with some researchers saying it shows how the list is heavily biased against Muslim people. According to Daily Dot, while there is no official number to how many names are on the no-fly list, Sen. Dianne Feinstein (D-Calif.) suggested in 2016, that over 81,000 people were on the list.

TopicsCybersecurity

1.本站遵循行业规范,任何转载的稿件都会明确标注作者和来源;2.本站的原创文章,请转载时务必注明文章作者和来源,不尊重原创的行为我们将追究责任;3.作者投稿可能会经我们编辑修改或补充。

相关文章
  • Slack goes down again, prompting anxiety everywhere

    Slack goes down again, prompting anxiety everywhere

    2025-02-28 23:44

  • 世預賽40強賽承辦地或發生變更 蘇州取代上海成第一選擇

    世預賽40強賽承辦地或發生變更 蘇州取代上海成第一選擇

    2025-02-28 22:39

  • 前富力主帥出任塞爾維亞主教練獲官宣 雙方簽約3年

    前富力主帥出任塞爾維亞主教練獲官宣 雙方簽約3年

    2025-02-28 22:13

  • Apple Vision Pro is coming to the US on February 2

    Apple Vision Pro is coming to the US on February 2

    2025-02-28 21:11

网友点评