DeFi Daily News
Tuesday, November 18, 2025
Advertisement
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos
No Result
View All Result
DeFi Daily News
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos
No Result
View All Result
DeFi Daily News
No Result
View All Result
Home Other News Tech

Researchers discover bug allowing fake pilots to be added to TSA check rosters

Wes Davis by Wes Davis
September 8, 2024
in Tech
0 0
0
Researchers discover bug allowing fake pilots to be added to TSA check rosters
0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on Telegram
Listen to this article

A pair of security researchers, Ian Carroll and Sam Curry, made a startling discovery regarding a vulnerability in the login systems used by the Transportation Security Administration (TSA) to verify airline crew members at airport security checkpoints. This bug allowed individuals with basic knowledge of SQL injection to manipulate the systems, potentially granting unauthorized access to airline rosters and security checkpoints, posing a serious threat to airline safety and security.

Carroll and Curry uncovered the vulnerability while investigating a third-party website belonging to FlyCASS, a vendor that provides access to the TSA’s Known Crewmember (KCM) and Cockpit Access Security System (CASS) for smaller airlines. By inserting a simple apostrophe into the username field, they triggered a MySQL error, indicating that the username was directly inserted into the login SQL query, making it susceptible to SQL injection attacks.

Upon further investigation, Carroll and Curry confirmed the presence of SQL injection and were able to exploit the vulnerability using tools like sqlmap. By inputting specific credentials, they managed to gain administrator access to the FlyCASS system, granting them unrestricted control over airline crew records and photos.

Once inside the system, Carroll noted that there were no additional security checks or authentication measures in place, allowing them to freely manipulate crew records and photos for any airline using FlyCASS. This posed a grave security risk, as unauthorized individuals could potentially exploit the vulnerability to gain access to secure airport areas, compromising airline safety protocols.

In response to these findings, TSA press secretary R. Carter Langston denied the severity of the issue, stating that the agency does not solely rely on the compromised database for flight crew authentication. Langston reassured the public that only verified crew members are granted access to secure airport areas, downplaying the potential risks associated with the vulnerability.

<DeFi Daily News> is your go-to source for the latest updates and trending news articles in the world of decentralized finance. Stay informed and stay ahead of the curve with DeFi Daily News!

In conclusion, the discovery of this vulnerability in the TSA’s login systems highlights the critical importance of robust cybersecurity measures in aviation and transportation industries. The ease with which Carroll and Curry were able to exploit the system underscores the need for continuous vigilance and proactive security protocols to safeguard sensitive data and infrastructure from potential threats. While the TSA’s response may downplay the severity of the issue, it serves as a stark reminder of the ever-evolving nature of cyber threats and the constant need for organizations to prioritize cybersecurity practices and risk mitigation strategies. By staying informed and adopting best practices in cybersecurity, we can help mitigate the risks posed by vulnerabilities like the one uncovered by Carroll and Curry, ensuring the safety and security of critical systems and services.



Source link

Tags: AddedAllowingbugCheckDiscoverFakepilotsResearchersrostersTSA
ShareTweetShare
Previous Post

#1 Secret To True Wealth [BitBoy Crypto Sunday Sermon]

Next Post

Experts Predict Legal Challenges for Meme Coin Takeover Teams – Decrypt

Next Post
Experts Predict Legal Challenges for Meme Coin Takeover Teams – Decrypt

Experts Predict Legal Challenges for Meme Coin Takeover Teams - Decrypt

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Search

No Result
View All Result
  • Trending
  • Comments
  • Latest
rewrite this title Ripple News: First U.S. Spot XRP ETF Surpasses 0 Million in Assets

rewrite this title Ripple News: First U.S. Spot XRP ETF Surpasses $100 Million in Assets

October 26, 2025
rewrite this title and make it good for SEO MEXC Vs KuCoin 2025: Which Exchange Is Better?

rewrite this title and make it good for SEO MEXC Vs KuCoin 2025: Which Exchange Is Better?

October 26, 2025
rewrite this title Soft Washed Pleated Comforter Set from .99 at Kohl’s!

rewrite this title Soft Washed Pleated Comforter Set from $19.99 at Kohl’s!

November 15, 2024
rewrite this title with good SEO Arthur Hayes Claims Bull Market Still In Play: Monetary Policy

rewrite this title with good SEO Arthur Hayes Claims Bull Market Still In Play: Monetary Policy

November 5, 2025
Stock market today: S&P 500 set to build on record high as Powell kicks off semiannual testimony

Stock market today: S&P 500 set to build on record high as Powell kicks off semiannual testimony

July 9, 2024
rewrite this title and make it good for SEO”Stop taking actions that harm America”: US Commerce Secretary sends stern message to India

rewrite this title and make it good for SEO”Stop taking actions that harm America”: US Commerce Secretary sends stern message to India

September 28, 2025
rewrite this title Benzema: More support for Mbappe will boost his goal threat – Soccer News

rewrite this title Benzema: More support for Mbappe will boost his goal threat – Soccer News

November 18, 2025
rewrite this title PTechnology To Launch Its Own Token for Secure Voice and Video Calls in 170+ Countries

rewrite this title PTechnology To Launch Its Own Token for Secure Voice and Video Calls in 170+ Countries

November 18, 2025
rewrite this title Gabe Newell Makes Waves at Steam Machine Week With 1 of World's Biggest Superyachts

rewrite this title Gabe Newell Makes Waves at Steam Machine Week With 1 of World's Biggest Superyachts

November 18, 2025
rewrite this title and make it good for SEOAbidur Chowdhury, celebrated designer behind iPhone Air, leaves Apple

rewrite this title and make it good for SEOAbidur Chowdhury, celebrated designer behind iPhone Air, leaves Apple

November 18, 2025
rewrite this title Two Technical Signals Hinting at a Bitcoin Bear Market – Decrypt

rewrite this title Two Technical Signals Hinting at a Bitcoin Bear Market – Decrypt

November 17, 2025
rewrite this title Why Are Bitcoin, Ethereum And XRP Prices Crashing Hard Today?

rewrite this title Why Are Bitcoin, Ethereum And XRP Prices Crashing Hard Today?

November 17, 2025
DeFi Daily

Stay updated with DeFi Daily, your trusted source for the latest news, insights, and analysis in finance and cryptocurrency. Explore breaking news, expert analysis, market data, and educational resources to navigate the world of decentralized finance.

  • About Us
  • Blogs
  • DeFi-IRA | Learn More.
  • Advertise with Us
  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2024 Defi Daily.
Defi Daily is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos

Copyright © 2024 Defi Daily.
Defi Daily is not responsible for the content of external sites.