时间:2026-01-06 19:14:44 来源:网络整理编辑:時尚
Everybody makes mistakes at work but, leaving the no-fly list exposed on the internet seems like a r
Everybody makes mistakes at work but, leaving the no-fly list exposed on the internet seems like a really bad mess-up.
That's reportedly what happened with the U.S. airline CommuteAir. The Daily Dot reported that a Swiss hacker known as "maia arson crimew" found the unsecured server while using the specialized search engine Shodan. There was apparently a lotof sensitive information on the server, including a version of the no-fly list from four years ago. Somewhat hilariously that was reportedly found via a text file labeled "NoFly.csv." That is...not hard to guess.
A blog post from crimew titled "how to completely own an airline in 3 easy steps" cited boredom as the reason for finding the server. They were just poking around and found it.
"At this point, I've probably clicked through about 20 boring exposed servers with very little of any interest, when I suddenly start seeing some familiar words," crimew says in their blogpost. "'ACARS', lots of mentions of 'crew' and so on. Lots of words I've heard before, most likely while binge-watching Mentour Pilot YouTube videos. Jackpot. An exposed jenkins server belonging to CommuteAir."
Tweet may have been deleted
CommuteAir, a regional US airline headquartered in Ohio, confirmed the info on the server was authentic to the Daily Dot. The server has been taken offline.
"The server contained data from a 2019 version of the federal no-fly list that included first and last names and dates of birth," CommuteAir Corporate Communications Manager Erik Kane told the Daily Dot. "In addition, certain CommuteAir employee and flight information was accessible. We have submitted notification to the Cybersecurity and Infrastructure Security Agency and we are continuing with a full investigation."
The info from the server has already been poured over, with some researchers saying it shows how the list is heavily biased against Muslim people. According to Daily Dot, while there is no official number to how many names are on the no-fly list, Sen. Dianne Feinstein (D-Calif.) suggested in 2016, that over 81,000 people were on the list.
TopicsCybersecurity
Dramatic photo captures nun texting friends after Italy earthquake2026-01-06 19:01
殺瘋了 !羅馬尼亞聯賽球員2分鍾內轟2記超級世界波2026-01-06 18:25
似曾相識?李鐵5年前點評高家軍 :感覺球員力量使不出來2026-01-06 18:17
曝C羅施壓索帥:每輪聯賽都首發 來曼聯隻為奪獎杯2026-01-06 18:16
Pokémon Go is so big that it has its own VR porn parody now2026-01-06 18:04
殺瘋了!羅馬尼亞聯賽球員2分鍾內轟2記超級世界波2026-01-06 17:07
足協杯南粵足球寄望深足 卡洛斯:郜林身體不適但無大礙2026-01-06 16:58
國足教練組或對陣容可進一步補強 不存在歸化球員使用限製2026-01-06 16:48
Two states took big steps this week to get rid of the tampon tax2026-01-06 16:29
利物浦VS沃特福德首發:紅箭三俠出戰 阿利森缺陣2026-01-06 16:29
Tyler, the Creator helped Frank Ocean celebrate 'Blonde' release in a delicious way2026-01-06 19:11
曼聯VS萊斯特城首發 :C羅B費領銜眾星 桑喬出戰2026-01-06 19:07
國足歸化之惑 :隊內認為3人不足以踢全場 使用人數未設限2026-01-06 18:24
印度女足亞洲杯明年1月正常舉辦 中國隊女足主帥仍未確定2026-01-06 18:08
Nancy Pelosi warns colleagues after info hacked2026-01-06 18:08
穆帥 :我的工作比阿萊格裏更難 我必須去適應球隊2026-01-06 17:20
隊史首次!拜仁半場已5球領先藥廠 火力全開創紀錄2026-01-06 16:59
穆帥:我的工作比阿萊格裏更難 我必須去適應球隊2026-01-06 16:47
Satisfy your Olympics withdrawals with Nike's latest app2026-01-06 16:46
亞洲杯預選賽24支球隊誕生 將爭奪11個正賽名額2026-01-06 16:29