Providing Free and Editor Tested Software Downloads
< HOME | TUTORIALS | GEEK-CADE| WEB TOOLS | YOUTUBE | NEWSLETTER | DEALS! | FORUMS | >

MajorGeeks.com - Because sometimes it is rocket science.

Software Categories

All In One Tweaks
Android
Antivirus & Malware
Appearance
Back Up
Browsers
CD\DVD\Blu-Ray
Covert Ops
Drivers
Drives (SSD, HDD, USB)
Games
Graphics & Photos
Internet Tools
Linux Distros
MajorGeeks Windows Tweaks
Multimedia
Networking
Office & Productivity
System Tools

Other news

· How To and Tutorials
· Life Hacks and Reviews
· Way Off Base
· MajorGeeks Deals
· News
· Off Base
· Reviews



IObit Black Friday Sale

spread the word

· YouTube
· Facebook
· Instagram
· Twitter
· Pintrest
· RSS/XML Feeds
· News Blur
· Yahoo
· Symbaloo

about

· Top Freeware Picks
· Malware Removal
· Geektionary
· Useful Links
· About Us
· Copyright
· Privacy
· Terms of Service
· How to Uninstall

top downloads

1. GS Auto Clicker
2. Macrium Reflect FREE Edition
3. Smart Defrag
4. MusicBee
5. Sergei Strelec's WinPE
6. Microsoft Visual C++ 2015-2022 Redistributable Package
7. Visual C++ Redistributable Runtimes AIO Repack
8. McAfee Removal Tool (MCPR)
9. K-Lite Mega Codec Pack
10. Tweaking.com - Windows Repair
More >>

top reads

Star All the New Features Landing in Windows 11 This December

Star Lossless vs Lossy: When FLAC, APE, and ALAC Beat MP3 and When They Don't

Star Google Search Tricks You'll Actually Use in 2025 and Beyond

Star Fresh PC Checklist: First 12 Things to Do On a New Windows 11 Machine

Star Running AI Models Locally: What They Are, Where to Find Them, and How to Get Started

Star Deciding Between Idle State, Sleep Mode, and Shutdown: What's Best for Your PC?

Star How to Fix VMware Workstation "The Update Server Could Not Be Resolved" Error Installing VMware Tools

Star How to Remove Google Gemini from Your Phone (and Your Life)

Star Windows Bloat Removal Guide: Debloat Safely and Keep What You Need

Star Windows 11 Repair Playbook: SFC, DISM, CHKDSK Without Breaking Stuff


MajorGeeks.Com » News » December 2016 » Airline Booking Software Vulnerable to Hacking

Airline Booking Software Vulnerable to Hacking


Posted by: Timothy Weaver on 12/31/2016 01:26 PM [ comments Comments ]


Several legacy flaws have been found on the computer systems that are responsible for 90% of all airline ticketing systems.

Security Research Labs (SRL) reports that the three major booking systems, Amadeus, Sabre and Travelport, all suffer from weak authentication and web services. The reason behind these flaws is that all the Global Distributed Systems (GDS), the flight booking software, was built in the 1970s and 1980s to operate on mainframe computers and dedicated lines. However, these systems have been updated to work on the internet.

Because of these flaws, hackers would be able to obtain a wide variety of passenger data, including personally identifiable information, flights can be stolen or altered, and mileage can be swiped. The stolen information could also be used for phishing attacks.

The major flaw is that there seems to be a total lack of authentication. The authenticator is actually printed on the ticker itself.

“While the rest of the Internet is debating which second and third factors to use, GDSs do not offer a first authentication factor. Instead, the booking code (aka PNR Locator, a 6-digit alphanumeric string such as 8EI29V) is used to access and change travelers' information,” the SRL report stated.

“Two of the three main GDSs assign booking codes sequentially, further shrinking the search space. Finally, many GDS and airline web sites allow trying many thousand booking codes from a single IP address. Given only passengers' last names, their bookings codes can be found over the Internet with little effort,” the report stated.

Security Labs is proposing a simple solution that would involve only employing Captchas and limiting the number of access attempts per IP address.

Source: SCMagazine


« 11 Things You Can Do with the MacBooks Force Touch Trackpad and more @ NT Compatible · Airline Booking Software Vulnerable to Hacking · Russian Hackers Attempt Intrusion into Utilities »




Comments
comments powered by Disqus

MajorGeeks.Com » News » December 2016 » Airline Booking Software Vulnerable to Hacking

© 2000-2025 MajorGeeks.com
Powered by Contentteller® Business Edition