Everybody makes mistakes at work but, leaving the no-fly list exposed on the internet seems like a really bad mess-up.
That's reportedly what happened with the U.S. airline CommuteAir. The Daily Dot reported that a Swiss hacker known as "maia arson crimew" found the unsecured server while using the specialized search engine Shodan. There was apparently a lotof sensitive information on the server, including a version of the no-fly list from four years ago. Somewhat hilariously that was reportedly found via a text file labeled "NoFly.csv." That is...not hard to guess.
A blog post from crimew titled "how to completely own an airline in 3 easy steps" cited boredom as the reason for finding the server. They were just poking around and found it.
"At this point, I've probably clicked through about 20 boring exposed servers with very little of any interest, when I suddenly start seeing some familiar words," crimew says in their blogpost. "'ACARS', lots of mentions of 'crew' and so on. Lots of words I've heard before, most likely while binge-watching Mentour Pilot YouTube videos. Jackpot. An exposed jenkins server belonging to CommuteAir."
Tweet may have been deleted
CommuteAir, a regional US airline headquartered in Ohio, confirmed the info on the server was authentic to the Daily Dot. The server has been taken offline.
"The server contained data from a 2019 version of the federal no-fly list that included first and last names and dates of birth," CommuteAir Corporate Communications Manager Erik Kane told the Daily Dot. "In addition, certain CommuteAir employee and flight information was accessible. We have submitted notification to the Cybersecurity and Infrastructure Security Agency and we are continuing with a full investigation."
The info from the server has already been poured over, with some researchers saying it shows how the list is heavily biased against Muslim people. According to Daily Dot, while there is no official number to how many names are on the no-fly list, Sen. Dianne Feinstein (D-Calif.) suggested in 2016, that over 81,000 people were on the list.
TopicsCybersecurity
(责任编辑:時尚)
The five guys who climbed Australia's highest mountain, in swimwear
Tesla removes 'self
Millions of sunflowers bloom in Japan and the images are stunning.
Happy 10th Anniversary to 'Step Up,' you beautiful piece of trash
This chart shows just how high Simone Biles can jumpAly Raisman catches Simone Biles napping on a plane like a champion
Simone Biles is exhausted. She won five medals at the Summer Olympics in Rio, posed for selfies with
...[详细]Irish boxer jabs Putin on Twitter after controversial Russian win in Rio Olympics
Irish boxer Michael Conlan lost to Russia's Vladimir Nikitin by unanimous decision in the Olympics q
...[详细]LeBron James signs new contract that will make him highest
Fresh off delivering the Cleveland Cavaliers their first-ever NBA championship, LeBron James finally
...[详细]Happy 10th Anniversary to 'Step Up,' you beautiful piece of trash
Ten years ago, Step Up: The Movie hit theaters on Aug. 11, leaving intelligent audiences everywhere
...[详细]
Fiji's men's rugby sevens team has made history by defeating Great Britain and claiming the country'
...[详细]#ThrowbackThursday: Olympian edition
Before Olympians were Olympians, they were cute kids like the rest of us. Even at just a few feet ta
...[详细]U.S. Soccer's women deserve as much as the men — even when they lose
When the U.S. women's soccer team returns from the Rio Olympics, there will be no ticker-tape parade
...[详细]Niantic is cracking down on 'Pokémon Go' cheaters with permanent bans
Pokémon Goplayers, beware: Niantic is starting to get serious about cracking down on cheaters
...[详细]What brands need to know about virtual reality
Virtual reality (VR) is all the rage. Premium publishers like USA Today, the New York Times, and AOL
...[详细]Zoe Kravitz joins 'Fantastic Beasts' at the last minute
The Harry Potterspinoff Fantastic Beasts and Where to Find Them has found the one ingredient it was
...[详细]Tributes flow after death of former Singapore president S.R. Nathan

Niantic is cracking down on 'Pokémon Go' cheaters with permanent bans
