10 ms·
Hacking the largest airline and hotel rewards platform (2023)
- yieldcrv 2y ago[flagged]
- alwa 2y agoI’m really impressed at the number of times they say their counterparts responded to their report in under an hour, immediately took the affected site offline, then resolved the issue quickly. That seems like an enviable operation.
- jollofricepeas 2y agoYou almost have to pull the site to stroke bounty hunter egos when you could just push a change to prod instead. If not, they are quick to bash you publicly. There’s too much hubris in the “professional” web app bug hunter community. Generally, their attitude is very “look at these stupid developers,” “developers suck at security,” or “a conspiracy is happening because company X didn’t take their app down within 10 minutes of getting my email.” It’s much more nuanced than that. I’d like to see: 1) more bounties and better paid bounties 2) less ego and much more professionalism and patience from “researchers” Both would be better for consumers.
- hansvm 2y ago> when you could just push a change to prod instead. I wonder if there's an attack vector hiding where you induce a malicious bug via an illegitimate bounty and the developers' bias against inaction.
- azeirah 2y ago100%, hacking is as much technical prowess as it is social engineering.
- Thorrez 2y agoHow about this one: https://hackerone.com/reports/745324 https://hackerone.com/reports/745324 It's a $20k bounty for simply taking a cookie that a HackerOne employee accidentally pasted when responding to a different vuln report on HackerOne.
- joatmon-snoo 2y agoSeriously! I actually can’t think of any openly documented security incident with such impressive remediation timelines. There’s a lot that has to go into fixing things on such a tight timeline too: - oncall-level alerting for your security.txt inbox - your oncall needs to either be someone who can actually take corrective action on the system in question (not easy in a large company!) or able to route the issue to the right team - the service owners need to be empowered to treat security with the appropriate severity (taking the site down so quickly speaks highly to this) Hats off to the points.com team. With any luck, this post doesn’t get too much traction and y’all won’t get flooded with bounty beggar spam.
- deleted 2y ago[deleted]
- michaelt 2y ago> - oncall-level alerting for your security.txt inbox Maybe the terminology is different in your company, but my employer has an 'operations' team which has several shifts of workers, who look after things that need 24/7 monitoring. They then triage and escalate as appropriate. That's who you'd have monitoring the security inbox, if you want round-the-clock monitoring, so nobody's getting woken several times a night by spam.
- deleted 2y ago[deleted]
- seanthemon 2y agoWe call that guy grafana alerts at ours
- TrackerFF 2y agoMakes me wonder if they (points.com) have some key-word alerts on incoming emails. I know for sure that at some companies, this would have taken hours (to days!) to detect, if the tip had come through a regular info@ or contact@ inbox.
- deleted 2y ago[deleted]
- bakje 2y agoThe article mentions a security.txt[1] which doesn't seem to contain an email address but it does contain a link[2] to a disclosure program, I'm guessing that's how they submitted all their findings? [1] https://www.points.com/.well-known/security.txt https://www.points.com/.well-known/security.txt [2] https://bugcrowd.com/plusgrade-vdp-pro https://bugcrowd.com/plusgrade-vdp-pro
- deleted 2y ago[deleted]
- remus 2y agoIt's a strange disconnect between the quality of the incident response and the extremely basic nature of many of the bugs reported. I mean SECRET_KEY='secret'?! Seriously straightforward stuff.
- toyg 2y agoWhy? One depends on development practices, the other on security-team practices. You can have a team of donkeys building a product and the sharpest hackers guarding it. Ideally best practices would trickle down, but that's not a given.
- remus 2y ago> You can have a team of donkeys building a product and the sharpest hackers guarding it. You could do but it's a pretty risky way to run a business. Obviously the real world often gets in the way, but a competent manager would look at that org structure and say "shouldn't we move some of those smart ppl on to the build team to catch issues before they're in prod? Seems awfully risky waiting until it's live to catch these bugs which could cause us massive financial harm"
- jmb99 2y agoFrom experience, a lot of talent security people really just don’t want to be developers, even if they’re good at it. It’s not always as simple as shuffling people around between teams.
- udev4096 2y agoWhy would anyone even use such a predictable word for dev environment? I am baffled by this practice of not following the bare minimum security mindset even when you are just running it in a dev environment
- fragmede 2y agoBecause it's dev. Does your bathroom door have a deadbolt and a key and you lock it firmly every single time when you're home alone?
- diggan 2y agoIt seems they reacted before the team even sent over a report in one case: > Before we could even finish sending our report or see if other endpoints were accessible (e.g. adding points to a customer rewards account), the points.com team had detected our testing and had completely shut down United's production points.com website. Bummer!
- sqs 2y agoImpressively fast responses from Points.com!
- rootsudo 2y agoFun read! So close to unlimited point generation and process tickets for those fancy flights~ I would say if you wanted to generate "free" flights, which is entirely possible, learn how GDS works and the workflow for a ticket purchase and how a coupon is attached ;) but that would probably be going to far then just normal poking and secure disclosure but there is enough techdebt that if you know how one airline processes a ticket, it will work on quite a few other too! You can also do very tricky things too that would process as normal for a majority of airlines too - event though most airlines may fall onto amadeus/sabre, you'd be surprised (or not really) at the front end that will allow almost anything - and "farecodes" that could rewrite a ticket which have been exposed to customer facing endpoints that are best verified, with only an active PNR. Then again, I do recall a famous post on here about australian politician and someone jusing using view source to verify a quantas ticket.
- sushid 2y agoCan you provide a link or two so one could read up on what you've mentioned in your post?
- klausa 2y agoA lot of the knowledge is very arcane, and like, split over hundreds and thousands of flyertalk.com pages, and like... institutional knowledge of more clever travel agents. I think a lot of the "fun" that can potentially be had also requires a direct access to a GDS, which, AFAICT is on the order of ~$10k a year? And if your "tricks" are discovered, airlines have a direct way to demand payment for any shenanigans you've pulled (ADM, https://www.ana.co.jp/businesspartners/en/admacm-policy/ https://www.ana.co.jp/businesspartners/en/admacm-policy/). But perhaps OP had something different in mind, I'm curious myself now :P If you wanna really go off the deep end, try looking into "fuel dumping" community — there's a small group of people who basically have figured out a series of bugs in how fares are coded (that lets them buy flights much cheaper then intended). They use (very dumb) coded language to talk about their "findings", and are very very very unfriendly to newcomers; but it's a fascinating world to observe.
- 2y ago
- junto 2y ago> On May 2nd, 2023, we identified that the Flask session secret for the points.com global administration website used to manage all airline tenant and customer accounts was the word "secret". After discovering this vulnerability, we were able to resign our session cookies with full super administrator permissions. Seriously?
- xnorswap 2y agoThis is way more common than you'd like, here's a scenario where it can happen even without outright incompetence: Someone (or some AI) copies an example auth implementation from stackoverflow. Being sensible they realise they shouldn't put key material in source code either, so they leave "secret" in place, and pop a ticket in JIRA to update with the key material from the vault before it goes live. Employee falls ill, everything gets re-assigned. Leaves before it gets actioned and that ticket slips through the cracks, with the person taking over their duties not realising how serious "J10243: Populate secret from key vault" actually is, perhaps assuming it's currently coming from a different configuration location. There's little chance that the regular testing are discovering the flaw as the key gen based on "secret" goes live.
- bankcust08385 2y agoTragedy of the Commons often happens where there are too many developers and unclear functional or concerns ownership. Each concern needs a home, a checklist, a runbook, documentation, a support escalation path, and responsible tech or business owners.
- toyg 2y agoYou are redefining "tragedy of the commons" there... TOTC is about overusing shared resources (e.g. too many people helping themselves to a shared plate of food), not about confusing who should do what.
- bankcust08385 2y agoResponsibility is the "resource" that becomes diminished. What would you rather call it then? The bystander effect at organizational scale?
- ZephyrBlu 2y agoInsane vulnerabilities. The massive mismatches between authentication and authorization scopes are crazy. Encrypting data with "secret" as the key is also a facepalm.
- jsemrau 2y agoSomeone didn't bother reading my carefully prepared memo on commonly-used passwords. Now, then, as I so meticulously pointed out, the four most-used passwords are: love, sex, secret, and...
- S04dKHzrKT 2y agohunter2
- Phemist 2y agoYou are being downvoted because your comment only shows up as ****, which is not a significant contribution to the conversation.
- kalev 2y agopassword????
- wrboyce 2y agogod.
- bankcust08385 2y agoSo would your holiness care to change her password? Once upon a time, I ran ypcat passwd and piped it into John the Ripper on the CompSci Linux cluster at one of the University of California campuses. Within 90s, I had amassed passwords of over 40 users including several lecturers and a tenured professor. The CS IT shop's mistake was running NIS+ rather than something like LDAP + Kerberos. Edit: ... god
- dawnerd 2y agoAges ago I was tasked with migrating a site for a famous workout instructor. I noticed they stored passwords in plain text. His along with a shocking number of user accounts all used just his first name as the password.
- deleted 2y ago[deleted]
- deleted 2y ago[deleted]
- openplatypus 2y agoThe secret was "secret".
- sangeeth96 2y agoI've always felt most such rewards program portals and apps were more hack-jobs than serious applications and thus, would be riddled with issues like these. I'm from India and I see many of these sites come and go all the time but not a single one has inspired confidence in me about keeping my data safe. For example, even the topmost cards here (HDFC Diners/Infinia) have a shoddy website, mostly a reskinned version of their generic rewards platform/partner. And I'm not just hand-waving here cause there are many forums that discuss taking advantage of their bad implementations to maximize returns. Even when one eventually gets patched, another springs up.
- grecy 2y ago> I've always felt most such rewards program portals and apps were more hack-jobs than serious applications It’s easy to figure out which way any system goes. Does it generate revenue or cost money? The former will be a serious application, the latter a hack job
- kredd 2y agoJust did a mental test of this theory through past projects I’ve consulted for, and it seemed the opposite. I’ve seen hack jobs generating about $1M/day, as a second product of the company. And seen very mature serious applications barely breaking even.
- chatmasta 2y agoThis makes sense because a hack job that generates money is more likely to stay online than a hack job that makes no money.
- chatmasta 2y agoThe whole point of these rewards programs is to share your data (bookings, itineraries, employment, email, travel class, etc.) with as many partners as possible. So at the end of the day, a data leak is only marginally worse than the expected behavior. (Obviously this doesn’t lessen the impact of vulnerabilities that allow malicious actors to charge you, steal your points, amend your bookings, or access your travel data in real time. But for read-only queries, an attacker won’t get much more access than a paying partner of the program could get.)
- matteason 2y agoThis is only tangentially related but it always blows my mind how insecure airline booking portals are. For many (most?) airlines all you need is the booking reference (PNR number) and surname to log in and see flight itinerary, contact details and, in some cases, change or cancel the booking. No password or MFA needed. The kicker is that your PNR number and surname are encoded in the barcode on your boarding pass, easily scannable with a phone app. If you ever post a boarding pass online you're unintentionally doxxing yourself and potentially letting people screw with your flights. I've seen celebrities do this, and during the Cloudstrike outage one tech CEO posted his handwritten boarding pass on Twitter with the PNR in full view. https://krebsonsecurity.com/2017/08/why-its-still-a-bad-idea-to-post-or-trash-your-airline-boarding-pass/ https://krebsonsecurity.com/2017/08/why-its-still-a-bad-idea...
- dustypotato 2y agoMaybe it was after boarding the flight? I still find it convenient . It's not that hard to keep the PNR number and surname. The reason it's so open is that there's an Identity check at the next stage where you can't use them if you're faking.
- callmeal 2y agoThe concern is more about DOSing - using a pnr and last name, you can view (and in some cases, cancel) online via the airlines web site.
- fer 2y agoThe issue here is interoperability. PNR identifier and last name is the only reasonable key to use when a single PNR is meant to be shared among the GDS, the IT provider, the traveler and companions, hotels, car rentals companies, travel agencies and countless other players in the market (sometimes several of each at the same time). But it's also true it relies on the traveler keeping the PNR reference secret. Adding MFA would involve adding new segments to all sorts of EDI messages, more complex booking/ticketing/cancelling flows, and getting all those companies on the same page so shit works without impact. It'd be possible and an impressive engineering effort, but also a royal PITA given all the moving parts in the travel industry. The few times I had to cancel/rebook or similar I was next to the counter with my ID, but I can think that having people call you and/or send an email for you to click to confirm is easier and has less friction than revamping the whole GDS industry and their (ducks) legacy B2B interoperation.
- n4r9 2y agoDoes anyone know what sort of market share points.com has in this space? It's always interesting to spot correlations between market fragility and a lack of competition (as in the case of the recent Crowdstrike and CDK Global outages).
- deleted 2y ago[deleted]
- bogtog 2y agoIs taking the website offline really necessary? If the vulnerability has been there for 1 year or so already, what harm does it being there for 1 year and an hour do? Also, maybe it's not clear to me exactly what is getting taken down, but I'm amazed that the chain from "person reading email" to "person that is permitted to take down the website" moves so quickly (or that the latter right is given so low in the hierarchy).
- simondotau 2y agoGiven the real money involved, keeping it online with this flaw in place isn’t an option.
- dewey 2y agoIt is a very real option. If it's not being exploited by hundreds of people right now and you make more money keeping the site up vs. what you lose in "fraud" it makes sense to keep it running. Just like you don't shut down your store if someone stole some merchandise or how credit cards just factor fraud into the fees.
- shakna 2y agoIt's often a violation of both government laws and insurance contracts, if you knowingly expose that much financial information to a proven vulnerability. There are businesses where if you suffer a theft, you shut everything down and run a stocktake. For example, an arms dealer. And there are times credit card providers shut down - because there is a known vulnerability, and they have to immediately mitigate, or lose their insurance.
- jessriedel 2y agoOk, but shutting down the website because of legal/moral responsibility to protect customer info is very different than doing so because of the “real money involved”, which is what commenter dewey was responding to. You can choose to just take the fraud cost hit in the latter case.
- 486sx33 2y agoIs this why / when airmiles when bankrupt and get bought out at the 11th hour by BMO? https://newsroom.bmo.com/2023-03-10-BMO-Confirms-Agreement-to-Acquire-LoyaltyOnes-AIR-MILES-Reward-Program-Business https://newsroom.bmo.com/2023-03-10-BMO-Confirms-Agreement-t...
- Marsymars 2y agoThere was nothing abrupt about the Air Miles bankruptcy, they'd been in long-term decline and had lost nearly all of their major partners by that point. I called the BMO purchase months before it happened.
- sova 2y agoIt's so funny to me, this is normally read aloud as "security vulnerabilities disclosed after patching" but in reality this is a natural part of how software is made. You make compromises. Terrible ones. Security ones. In the beginning. Not always, but some places, some applications, some websites, some languages, sometimes you make some concessions for sake of simplicity or prototyping or proof-of-concept'ing that ends up making it all the way to prod. And then these "vulnerabilities" are really things that mean your company grew way faster than you anticipated, and lucky for you some ethical hackers "exploited" these concessions, first.
- xyst 2y agoIt’s amazing to me that these well known attack vectors are still possible today. Reading about directory traversal in 2023-2024 is like a blast from the past.
- Banditoz 2y agoAnyone know of other blogs similar to Sam Curry's web API exploitation stuff?
- soygem 2y agoThe image is a probably an img2imgd pepe dealer :)
- billy99k 2y agoIt's interesting United Airlines is mentioned here. I am a security researcher and found vulnerabilities through the United Airlines bug bounty program last year. They pay you in miles instead of money. The problem is that they gift them to you instead of what you might get from a credit card rewards program. You end up having to pay a 2% tax on the total amount in points (at least in the US). When I made the calculations, I am actually paying more in taxes on the points than if I just paid for the flights myself. They end up being almost completely worthless.
- junar 2y agoRelevant post: https://blog.docbert.org/united-airlines-bug-bounty/ https://blog.docbert.org/united-airlines-bug-bounty/
- sarahwoodssarah 2y ago[dead]
- ystdhjs 2y ago[flagged]