Everybody makes mistakes at work but, leaving the no-fly list exposed on the internet seems like a really bad mess-up.
That's reportedly what happened with the U.S. airline CommuteAir. The Daily Dot reported that a Swiss hacker known as "maia arson crimew" found the unsecured server while using the specialized search engine Shodan. There was apparently a lotof sensitive information on the server, including a version of the no-fly list from four years ago. Somewhat hilariously that was reportedly found via a text file labeled "NoFly.csv." That is...not hard to guess.
A blog post from crimew titled "how to completely own an airline in 3 easy steps" cited boredom as the reason for finding the server. They were just poking around and found it.
"At this point, I've probably clicked through about 20 boring exposed servers with very little of any interest, when I suddenly start seeing some familiar words," crimew says in their blogpost. "'ACARS', lots of mentions of 'crew' and so on. Lots of words I've heard before, most likely while binge-watching Mentour Pilot YouTube videos. Jackpot. An exposed jenkins server belonging to CommuteAir."
Tweet may have been deleted
CommuteAir, a regional US airline headquartered in Ohio, confirmed the info on the server was authentic to the Daily Dot. The server has been taken offline.
"The server contained data from a 2019 version of the federal no-fly list that included first and last names and dates of birth," CommuteAir Corporate Communications Manager Erik Kane told the Daily Dot. "In addition, certain CommuteAir employee and flight information was accessible. We have submitted notification to the Cybersecurity and Infrastructure Security Agency and we are continuing with a full investigation."
The info from the server has already been poured over, with some researchers saying it shows how the list is heavily biased against Muslim people. According to Daily Dot, while there is no official number to how many names are on the no-fly list, Sen. Dianne Feinstein (D-Calif.) suggested in 2016, that over 81,000 people were on the list.
TopicsCybersecurity
(责任编辑:焦點)
Wikipedia co
Apple's Tim Cook says augmented reality, not VR, is the future
All the hosts are leaving 'Great British Bake Off' but Americans should still watch
Turn off all Samsung Note devices on planes, aviation authority warns
Photos show the Blue Cut fire blazing a path of destruction in CaliforniaSamsung Galaxy Note7 teardown reveals the magic behind the phone's iris scanner
Samsung's Galaxy Note7 is touted by many reviewers as one of the best, if not the best, smartphones
...[详细]Gennifer Flowers tweets she supports Trump, will accept invitation to debate
Gennifer Flowers has made her reentry into the news surrounding the 2016 presidential race. Flowers,
...[详细]BlackBerry is back at it again with a mediocre phone
I have so many mixed feelings about BlackBerry’s DTEK50, a $300 Android-powered phone. I&rsquo
...[详细]The rise of Pepe the Frog is another sign of hate festering online
The ubiquitous green internet amphibian known as Pepe the Frog has been added to the Anti-Defamation
...[详细]You can now play 'Solitaire' and 'Tic
Google just added two new fun Easter eggs to its search results.。You can now play 。 Solitaire
。and
。 Ti
...[详细]Kevin Garnett great calls it quits after 21 seasons
Anything is possible, even the end of Kevin Garnett's storied 21-year career.Garnett — the 200
...[详细]Silicon Valley VCs raise millions for an Aussie drone mapping startup
In 2014 Rory San Miguel and Francis Vierboom made a bet that not all drone companies would actually
...[详细]Chanel debuts futuristic helmets in Paris fashion week
Spring 2017 might mark the beginning of some ultra-modern trends. On Tuesday, Chanel debuted its Spr
...[详细]
The group behind a growing list of celebrity social media breaches has struck again, this time takin
...[详细]Kevin Garnett great calls it quits after 21 seasons
Anything is possible, even the end of Kevin Garnett's storied 21-year career.Garnett — the 200
...[详细]