10 ms·
Hacking on a plane: Leaking data of millions and taking over any account
- cwkoss 4y agoNice catch, and kudos to you and them for the quick resolution!
- dopamean 4y agoI's kind of incredible how common this specific kind of vulnerability is. I have to assume the developers of these systems just hope that no one will notice?
- crecker 4y agoI'm not the author of the article. But I think developers thought "ahaha who's going to checkout? Someone that has developer tools in airplane? Good joke bob!"
- HideousKojima 4y agoJust because a vulnerability is common and easy to avoid won't stop lazy and/or incompetent devs from making it. I mean SQL injection is still incredibly common despite being easily mitigated by really basic knowledge and despite being handled properly by the most common data access libraries in every single programming language.
- amackera 4y agoThese types of fails are generally due to incompetence, in my experience.
- jaywalk 4y agoThis one is 100% due to incompetence. There was no attempt at anything resembling security.
- hackbinary 4y agoI'm not sure what your experience is, but mine is over multiple decades over multiple companies over multiple continents, and in general, corporate management, project management, and business analysts are not concerned about security. Instead, they are interested in delivering buttons, fields, and streamlined workflows. Technical debt and library upgrades? Os upgrades? Forget about it. They need to deliver value back to the business in terms of faster business processes. Only when the business is hacked or they fail compliance does the business leadership start to care. Blaming the people with the hands on the tools is not fair when the business will not give the resources to do their work properly.
- 20after4 4y agoThis is sadly 100% accurate, in my experience.
- brazzy 4y agoNo, the developers simply don't realize that there is a vulnerability, even though they have the required knowledge because they look at the code with the "how do I implement this feature" mindset (which is their job), not a "how could this be abused" mindset.
- marapuru 4y agoIn addition to the comment above, this mindset is strengthened by time squeezes in development. Which lead to sales, project managers and product owners who prevent developers from actually looking into this.
- rwmj 4y agoI've seen development environments that try to abstract away the underlying web mechanisms[1], which can make it very hard to tell what's really going on at the request level. Combine that with incurious developers, deadlines and a need to ship anything that works and this is what you get. [1] I'm thinking in particular of Ars Digita's second system effect Java replacement for their original Tcl environment. It tried to turn everything into late 1990s Java buzzwords and was completely opaque, as well as being comically inefficient.
- jaywalk 4y agoI can understand when there's a bug that causes something like this. It doesn't excuse it, but we all introduce bugs in code, and sometimes they're disastrous. But this? This is just straight up careless, thoughtless design with zero regard for security whatsoever. It's inexcusable.
- version_five 4y agoAirplane wifi is very much still in the "enterprise software" phase, by which I mean a lowest bidder sells it to someone who will never use it and buys it with only some corporate objective in mind. I've been using it a lot recently, across several airlines, and the experience is universally bad. It doesn't surprise me they also skimped on security
- jaywalk 4y agoAt least as far as the connectivity itself goes, Viasat's Ka-band airplane WiFi is actually really good. As luck would have it, I've got a flight coming up in a few days on a plane using the provider implicated in this article. I'll be doing some poking around myself for sure.
- dfcab 4y agoCoincidentally on a flight right right now and service is decent on United. Not fast but useable. One caveat is that it performs much better with a VPN enabled. Seems they block certain things such as Zoom and the VPN allows the use of the chat feature. Apple Music was struggling until the VPN was enabled and solid since.
- japanman425 4y ago
- Cupertino95014 4y agoWhen on any sort of public WiFi network, use a VPN. If anyone has a story about how "that's not enough" I'm eager to hear it. Can't be too careful, can we?
- jaywalk 4y agoThis has absolutely nothing to do with the fact that it was public WiFi, so your advice of using a VPN is irrelevant.
- Cupertino95014 4y agoThis has to do with being on a public network (an airplane), does it not? Maybe your outrage is over-the-top.
- petschge 4y agoAbsolutely not. This has to do with how accounts for that network are managed. Even if you use a VPN you will still have an account there and your data were at risk to this vulnerability.
- Cupertino95014 4y ago> The impact of these two bugs was signifcant. It was access to first name, last name, address, and email of the user as well as last 4 digits, expiration date, billing name, and address of the credit cards. Assuming you're a black hat exploiting this bug, what can you do, if the target is using a VPN? I don't know what "address of the credit cards" means, but let's assume it's the target's home address. You don't get their credit card number or security code. You don't get access information on any of their web accounts. Correct? If you spy on their internet activity during the flight, it's all encrypted. You won't learn anything. However, you do have the ability to change their password, so they can't get into their own account anymore. You could also bill all your own activity to their account. I don't know if you can bill other things to the account. You could get access to whatever data was stored in that account. I don't know what that would be, other than when & how much you used it in the past. Is this a complete summary of the potential damage? Since there's no Reply button for the two answers to this: Neither of them answer my last question ("is this a complete summary..."). Should I assume it is? And I never said "oh but the data leak isn't really that bad of a vulnerability" -- you did.
- 8jy89hui 4y agoThe author did not mention if they were rewarded by the bug bounty program. A vulnerability of this severity surely requires a reward of some sort. Does anyone have any more information about whether or not this person was compensated for their work?
- boringg 4y agoAnd how much they were compensated is also interesting...
- slim 4y agolet's play the guessing game :) the fact that he mentions the bounty but not the reward means he probably got a reward. If he did not get one, he would have mentioned it. it was not a ridiculous amount because 1. he would have refused it and talked about it. 2. the money was good enough for him to comply and not cite the companies was it a large amount ? it could be the reason why he's not telling it. Companies don't want to be spammed by script kiddies attracted by the "largest reward in town".
- fsckboy 4y agoyou need to turn this into something like the "your solution to spam will not work because:" copypasta
- LiamPa 4y agoHow is something like this not picked up in a pen test? Can only assume there never has been..
- amackera 4y agoProbably because a lot of pen testing is security theatre.
- photon12 4y agoSince this is specifically related to accepting payment, one would hope this infrastructure has received adequate security testing as required by PCI standards. In practice, PCI standards compliance is a mess of people selling "point and click compliance solutions," companies being too big to be properly audited, code churn between audits, companies misleading auditors or hiding key data. Security theater is especially pervasive in PCI compliance.
- batch12 4y agoTo your point - Although the post discusses possible PCI implications, I don't think exposing last 4 and PII alone are enough to run afoul of the requirements (at least 3.2 as far as I remember). We would need the full PAN or CVV or evidence that this was being stored improperly, etc. If I recall, a company can store first 6 and last 4 in plaintext. With that said, these problems may indicate bigger issues that would violate the DSS, he may have found more that wasn't written about, or I could just be mistaken.
- jacquesm 4y agoMore likely: the pentest report that was made because it was mandatory ended up in someone's drawer.
- deleted 4y ago[deleted]
- jesuspiece 4y agoso many "pentests" are: * run scanner * print out report not a lot of deep diving
- throwaway019254 4y ago> Monday (November 21st) the airline was made aware of the issue > Wednesday (November 23rd) resolution has already been tested and deployed That's a pretty nice response time - compared to some big companies that are asking security researchers to not disclose vulnerability for six months.
- sbuccini 4y agoEspecially since the vuln was in a third-party system so the airline couldn't push a fix themselves.
- birdman3131 4y agoDepends on if it was a security issue or a config issue. From the end user's perspective they can look the same.
- Bluecobra 4y agoYeah is really refreshing, I was expecting the worst like the OP getting banned/sued by the airline and detained by the TSA.
- heavyset_go 4y agoIf I was the author, I'd be kept up at night by the idea of being kidnapped in the middle of the night and whisked off to some black site, however likely or unlikely that is.
- YeBanKo 4y agoNot related to the content of the article, but to the presentation: that art work in the header is spot on, except maybe for what appears to be tree branches in the window. I think we are witnessing how generative are killing photo stock business.
- LiamPa 4y agoI think they are supposed to be the ‘wing’
- goblinux 4y agoEw yeah the more you look at it the weirder it gets. Like what's between his fingers, or what is that keyboard layout? Is that supposed to be cash sitting on the armrest, or like a plane ticket?
- ok_dad 4y agoIs he wearing a hoodie or a down jacket, and why is his neck wrap thingie seems to be integrated into the hoodie. Also, he seems to be wearing some sort of leather harness or backpack. Weird stuff!
- goblinux 4y agoAlso what is that seat back, is it his backpack or has he pulled the emergency flotation device out from under his seat already?
- jshchnz 4y agocrazy how this makes it all the way to production, I wonder how long this vulnerability was exposed...
- noduerme 4y agoOnce a user is logged in, is including their username or userID routine API responses considered bad practice? I don't see why it should be, if everything you can do with that username requires an active login token. The fact that you could put in an email address in lieu of a username/userID seems irrelevant; lots of systems allow email addresses as a username. What stands out about this to me is: We see in both requests the same `uxd_id` field. This looks to be a temporary login key or validation key generated by the server, that the client would probably use to validate further requests or validate a password change request from that username. It's different in the email than in the live server response so they are generated in different sessions. So... 1) The email reset has two calls. What does the author mean that the first call validates the user's auth? If this is a "forgot password" link for a user who's not logged in, there should be no existing auth (unless that old uxdID functions as a permanent password, but even then, it should be specific to the user). That link should go to a page that issues a new email with a temporary validation token that's tied to the specific user and then emailed back to that user's email address. Unless you could intercept the named user's email there should be no way to know the new token and reset the password. 2) If, on the other hand, it was a reset pass call with the user already logged in, why is the server not checking that uxd_id matches the active login session which also matches the user whose password is to be changed? What's the point of the uxd_id field in the PUT call if not to check that calling user == authorized user == user whose password should be changed? Who would write something like that? For that reason, this looks more like a backdoor for testing password resets that was unintentionally left open. Am I misunderstanding something about the way this thing is taking tokens to change passwords...? Or is what's described really as simple as "system doesn't check if uxd_id matches user's email on an active session"?
- glyphosate 4y agoYes, it's as simple as the back end not validating that the user id and email address in the requests are tied to the active session. It's a very common mistake, often happens when devs try to roll their own session management/access control functionality
- japanman425 4y ago
- t3estabc 4y ago
- plastiquebeech 4y agoNot surprising, airplane wifi has always been ridiculously insecure. Back in the day, when it was first rolling out, you could (theoretically ofc) join the plane's network and scan for MAC addresses, then clone someone else's for free access. I think the authentication is a bit more sophisticated these days, but it's clear that these providers treat security as an afterthought. At least the one in the article had a bug bounty program and responded quickly, I guess. Unrelated, I think it's funny that the AI artist put a little picture of a house on the airplane's interior wall in the article's header image. Maybe plane trips would be more bearable if the cabins didn't look like a utopian abbatoir's waiting room.
- lxgr 4y ago> Back in the day, when it was first rolling out, you could (theoretically ofc) join the plane's network and scan for MAC addresses, then clone someone else's for free access. Given that the MAC address is the only thing the access point has to tie your packets to a (paid) session in an unencrypted network, I'd expect this to still work today, or am I missing anything? OWE [1] might help in this scenario (if it‘s possible to reliably bind that to a login session somehow), but that's pretty new, and given how long upgrade cycles on airplane hardware are, I wouldn't count on seeing that within the next couple of years. [1] https://en.wikipedia.org/wiki/Opportunistic_Wireless_Encryption https://en.wikipedia.org/wiki/Opportunistic_Wireless_Encrypt...
- sys_64738 4y agoI think the way that airlines handle this is to squash as many seats together as possible so it's not possible to open your laptop to do hacking. Problem solved!
- anaganisk 4y agoOr even better invest in standing tech and cram like a subway, and fire all the stewardess, make it remote piloted and outsource to the south asian countries to fly it. Security + revenue + cost cuts. All in one shot.
- leoqa 4y agoYou need 3 remote (contract) pilots, the plane only responds to a quorum of synchronized inputs. Then you can drive the price down as you let them fly multiple planes at the same time. Perhaps even a gig economy play here.
- japanman425 4y ago
- icecap12 4y agoI know the guys at the AISAC - great resource for the cyber folks working in the Aviation industry.
- brigandish 4y ago> I tried customer_id … That also worked! What did you try exactly? There's several of these "I changed X and got Y" without ever showing what X is, just alluding to it. That grinds my gears in any blog post, perhaps only second to not stating which version/system some code is running against.
- pcthrowaway 4y agoYet another great writeup by a security researcher who realized they could exploit a system by modifying a request in-flight.