Home  >  Article  >  Hardware Tutorial  >  Serious security gap uncovered at airports

Serious security gap uncovered at airports

王林
王林Original
2024-09-03 14:23:18368browse

Serious security gap uncovered at airports

The well-known security researchers Ian Carroll and Sam Curry have uncovered serious vulnerabilities in the FlyCASS system. This is a web-based management system used by smaller airlines to manage the Known Crewmember (KCM) and Access Security System (CASS).

The KCM program allows authorized flight personnel to bypass regular security checks at airports, while CASS regulates access to the cockpit of aircraft. The vulnerability discovered by the researchers allows hackers to log in as administrators through a so-called SQL injection attack, whereby any person can be added as a KCM or registered in CASS. In practice, this could allow unauthorized persons to bypass security checks and even get into the cockpit of an aircraft. FlyCASS is mainly used by US airlines. It is unclear whether european airlines are also affected.

FlyCASS has now been switched off

Following their alarming discovery, Carroll and Curry informed the US Department of Homeland Security (DHS). This was on April 24, 2024, and a day later the Department confirmed that it was looking for a solution. FlyCASS was shut down on July 5, 2024, meaning the vulnerability persisted for more than two months after the DHS was notified.

The above is the detailed content of Serious security gap uncovered at airports. For more information, please follow other related articles on the PHP Chinese website!

Statement:
The content of this article is voluntarily contributed by netizens, and the copyright belongs to the original author. This site does not assume corresponding legal responsibility. If you find any content suspected of plagiarism or infringement, please contact admin@php.cn