Providing Free and Editor Tested Software Downloads
< HOME | TUTORIALS | GEEK-CADE| WEB TOOLS | YOUTUBE | NEWSLETTER | DEALS! | FORUMS | >

MajorGeeks.com - We put the Major in Geeks!

Software Categories

All In One Tweaks
Android
Antivirus & Malware
Appearance
Back Up
Browsers
CD\DVD\Blu-Ray
Covert Ops
Drivers
Drives (SSD, HDD, USB)
Games
Graphics & Photos
Internet Tools
Linux Distros
MajorGeeks Windows Tweaks
Multimedia
Networking
Office & Productivity
System Tools

Other news

· How To and Tutorials
· Life Hacks and Reviews
· Way Off Base
· MajorGeeks Deals
· News
· Off Base
· Reviews




spread the word

· YouTube
· Facebook
· Instagram
· Twitter
· Pintrest
· RSS/XML Feeds
· News Blur
· Yahoo
· Symbaloo

about

· Top Freeware Picks
· Malware Removal
· Geektionary
· Useful Links
· About Us
· Copyright
· Privacy
· Terms of Service
· How to Uninstall

top downloads

1. GS Auto Clicker
2. Macrium Reflect FREE Edition
3. Smart Defrag
4. Visual C++ Redistributable Runtimes AIO Repack
5. Visual C++ Runtime Installer (All-In-One)
6. McAfee Removal Tool (MCPR)
7. Rufus
8. MusicBee
9. Sergei Strelec's WinPE
10. K-Lite Mega Codec Pack
More >>

top reads

Star How to Disable 1-Click Ordering on Amazon (and Avoid Surprise Charges)

Star How to Fix Shallow Paint Layer Depth in Bambu Studio

Star Aviator Betting Game Secrets: Unlock 97% RTP & Triple Your Wins

Star Windows Recall: What It Is, Why Hackers Will Love It, and How to Stay Safe

Star Star Trek Fleet Command Promo Codes: Redeem Codes for Free Shards, Blueprints And Resources

Star How To Use VLC Media Player to Trim Video Clips

Star What Is the $WinREAgent Folder and Can I Delete It?

Star Swear Your Way to Better Search Results

Star How to Get a Dark Start Menu and Taskbar in Windows 10 & 11

Star Enable, Disable, Manage, Delete or Create a System Restore Point


MajorGeeks.Com » News » December 2016 » Airline Booking Software Vulnerable to Hacking

Airline Booking Software Vulnerable to Hacking


Posted by: Timothy Weaver on 12/31/2016 01:26 PM [ comments Comments ]


Several legacy flaws have been found on the computer systems that are responsible for 90% of all airline ticketing systems.

Security Research Labs (SRL) reports that the three major booking systems, Amadeus, Sabre and Travelport, all suffer from weak authentication and web services. The reason behind these flaws is that all the Global Distributed Systems (GDS), the flight booking software, was built in the 1970s and 1980s to operate on mainframe computers and dedicated lines. However, these systems have been updated to work on the internet.

Because of these flaws, hackers would be able to obtain a wide variety of passenger data, including personally identifiable information, flights can be stolen or altered, and mileage can be swiped. The stolen information could also be used for phishing attacks.

The major flaw is that there seems to be a total lack of authentication. The authenticator is actually printed on the ticker itself.

“While the rest of the Internet is debating which second and third factors to use, GDSs do not offer a first authentication factor. Instead, the booking code (aka PNR Locator, a 6-digit alphanumeric string such as 8EI29V) is used to access and change travelers' information,” the SRL report stated.

“Two of the three main GDSs assign booking codes sequentially, further shrinking the search space. Finally, many GDS and airline web sites allow trying many thousand booking codes from a single IP address. Given only passengers' last names, their bookings codes can be found over the Internet with little effort,” the report stated.

Security Labs is proposing a simple solution that would involve only employing Captchas and limiting the number of access attempts per IP address.

Source: SCMagazine


« 11 Things You Can Do with the MacBooks Force Touch Trackpad and more @ NT Compatible · Airline Booking Software Vulnerable to Hacking · Russian Hackers Attempt Intrusion into Utilities »




Comments
comments powered by Disqus

MajorGeeks.Com » News » December 2016 » Airline Booking Software Vulnerable to Hacking

© 2000-2025 MajorGeeks.com
Powered by Contentteller® Business Edition