Security researchers say they were able to add employees at will to a databases used by the TSA to authenticate airline employees.
A pair of security researchers say they discovered a vulnerability in login systems for records that the Transportation Security Administration uses to verify airline crew members at airport security checkpoints. The bug let anyone with a “basic knowledge of SQL injection” add themselves to airline rosters, potentially letting them breeze through security and into the cockpit of a commercial airplane, researcher Ian Carroll wrote in a blog post in August.
> This was a very bad sign, as it seemed the username was directly interpolated into the login SQL query. Sure enough, we had discovered SQL injection and were able to use sqlmap to confirm the issue.
United States Latest News, United States Headlines
Similar News:You can also read news stories similar to this one that we have collected from other news sources.
TSA sees rise in 'Cat Eyes' weapons, slowing security checkpointsTSA officers say they are seeing a proliferation of “cat eyes” weapons being carried into checkpoints, in turn slowing security lines.
Read more »
Bitunix Announces Major Security Upgrade: $5 Million Insurance Backed by UK-Based Security PartnerCrypto Blog
Read more »
Tulsi Gabbard Placed on TSA Terror Watchlist, Hawaii Lawmakers Demand ExplanationSee multiple perspectives from Racket News, KITV 4, and The Daily Signal at AllSides.com.
Read more »
Here are the US airports that get the most TSA complaintsSome airports appear to be particularly stressful when it comes to traveler screening, based on TSA complaints from passengers in a new study.
Read more »
What Happens to Your Toiletries After TSA Confiscates ThemOver 2,300 items that passengers are forced to throw out under the assumption they could be bombs are being given to the needy.
Read more »
What Looks Like an Innocent iPhone Was Confiscated by TSA—Can You See Why?The seemingly normal item was hiding a secret that made it a potential danger to passengers.
Read more »