A hacker stumbled upon the no-fly list via unsecured airline server


Everybody makes mistakes at work but, leaving the no-fly list exposed on the internet seems like a really bad mess-up.

That’s reportedly what happened with the U.S. airline CommuteAir. The Daily Dot reported(Opens in a new window) that a Swiss hacker known as “maia arson crimew” found the unsecured server while using the specialized search engine Shodan. There was apparently a lot of sensitive information on the server, including a version of the no-fly list from four years ago. Somewhat hilariously that was reportedly found via a text file labeled “NoFly.csv.” That is…not hard to guess.

A blog post(Opens in a new window) from crimew titled “how to completely own an airline in 3 easy steps” cited boredom as the reason for finding the server. They were just poking around and found it.

“At this point, I’ve probably clicked through about 20 boring exposed servers with very little of any interest, when I suddenly start seeing some familiar words,” crimew says in their blogpost. “‘ACARS’, lots of mentions of ‘crew’ and so on. Lots of words I’ve heard before, most likely while binge-watching Mentour Pilot YouTube videos. Jackpot. An exposed jenkins server belonging to CommuteAir.”

CommuteAir, a regional US airline headquartered in Ohio, confirmed the info on the server was authentic to the Daily Dot. The server has been taken offline.

“The server contained data from a 2019 version of the federal no-fly list that included first and last names and dates of birth,” CommuteAir Corporate Communications Manager Erik Kane told the Daily Dot. “In addition, certain CommuteAir employee and flight information was accessible. We have submitted notification to the Cybersecurity and Infrastructure Security Agency and we are continuing with a full investigation.”

The info from the server has already been poured over, with some researchers saying(Opens in a new window) it shows how the list is heavily biased against Muslim people. According to Daily Dot(Opens in a new window), while there is no official number to how many names are on the no-fly list, Sen. Dianne Feinstein (D-Calif.) suggested in 2016, that over 81,000 people were on the list.





Source link: https://mashable.com/article/no-fly-list-leaked

Sponsors

spot_img

Latest

Shiba Inu Burn Rate Tumbles as Ethereum Whales Get Active

Blockchain data shows SHIB is the top-traded coin by ETH whales. Shiba Inu’s $BONE recently got...

Arjen Robben advises Dutch women ‘don’t go to World Cup with s*** in your pants’

Dutch football legend Arjen Robben has offered some interesting advice to the Netherlands women’s team ahead of the World Cup. The former Bayern Munich,...

Microsoft expands its pact with OpenAI in ‘multibillion dollar’ deal

Microsoft is once again pouring money into OpenAI as part of an expanded partnership. The tech giant is making a "multibillion dollar" investment...

Litecoin (LTC) Bulls Charge Past $90 Following 20% Rally

Litecoin (LTC) has recently witnessed an impressive three-day bullish streak, sparking excitement among investors as its price surged past the $91 level. The...

Fred Perpall, the first black president of Usga

At 47, Fred Perpall, a native of Dallas, Texas, was announced on Saturday as the new president of the United States Golf...