Advertisement Banner
  • Home
  • News
    • PRESS RELEASE
  • Shop
  • BUSINESS
    • CRYPTO
    • ECONOMY
    • FINANCE
    • MARKET
    • MONEY
  • TECH
    • APPS
    • GADGET
    • MOBILE
    • SCIENCE
  • SOCIAL MEDIA
  • ENTERTAINMENT
    • ARTS & THEATER
    • GAMING
    • GAMBLING
    • MOVIE
    • MUSIC
    • SHOWS
    • SPORTS
  • LIFESTYLE
    • CELEBRITY
    • CULTURE
    • Education
    • FASHION
    • FOOD
    • HEALTH
    • HISTORY
    • Nature
    • Religion
    • Shopping
    • TRAVEL
  • REAL ESTATE
  • Blog
  • Classifieds
No Result
View All Result

No products in the cart.

  • Home
  • News
    • PRESS RELEASE
  • Shop
  • BUSINESS
    • CRYPTO
    • ECONOMY
    • FINANCE
    • MARKET
    • MONEY
  • TECH
    • APPS
    • GADGET
    • MOBILE
    • SCIENCE
  • SOCIAL MEDIA
  • ENTERTAINMENT
    • ARTS & THEATER
    • GAMING
    • GAMBLING
    • MOVIE
    • MUSIC
    • SHOWS
    • SPORTS
  • LIFESTYLE
    • CELEBRITY
    • CULTURE
    • Education
    • FASHION
    • FOOD
    • HEALTH
    • HISTORY
    • Nature
    • Religion
    • Shopping
    • TRAVEL
  • REAL ESTATE
  • Blog
  • Classifieds
No Result
View All Result
No Result
View All Result
Home GAMING

The No-Fly List Has Been Leaked, Pokemon Briefly Involved

North Dakota Digital News by North Dakota Digital News
January 23, 2023
in GAMING
39 0
0
The No-Fly List Has Been Leaked, Pokemon Briefly Involved
32
SHARES
356
VIEWS
Share on TwitterShare on Facebook


Image for article titled The No-Fly List Has Been Leaked, TSA Investigating 'Cybersecurity Incident'

The Transportation Security Administration’s No-Fly List is one of the most important ledgers in the United States, containing as it does the names of people who are perceived to be of such a threat to national security that they’re not allowed on airplanes. You’d have been forgiven then for thinking that list was a tightly-guarded state secret, but lol, nope.

A Swiss hacker known as “maia arson crimew” has got hold of a copy of the list—albeit a version from a few years ago—not by getting past fortress-like layers of cybersecurity, but by…finding a regional airline that had its data lying around in unprotected servers. They announced the discovery with the photo and screenshot above, in which the Pokémon Sprigatito is looking awfully pleased with themselves.

As they explain in a blog post detailing the process, crimew was poking around online when they found that CommuteAir’s servers were just sitting there:

like so many other of my hacks this story starts with me being bored and browsing shodan (or well, technically zoomeye, chinese shodan), looking for exposed jenkins servers that may contain some interesting goods. at this point i’ve probably clicked through about 20 boring exposed servers with very little of any interest, when i suddenly start seeing some familar words. “ACARS”, lots of mentions of “crew” and so on. lots of words i’ve heard before, most likely while binge watching Mentour Pilot YouTube videos. jackpot. an exposed jenkins server belonging to CommuteAir.

Among other “sensitive” information on the servers was “NOFLY.CSV”, which hilariously was exactly what it says on the box: “The server contained data from a 2019 version of the federal no-fly list that included first and last names and dates of birth,” CommuteAir Corporate Communications Manager Erik Kane told the Daily Dot, who worked with crimew to sift through the data. “In addition, certain CommuteAir employee and flight information was accessible. We have submitted notification to the Cybersecurity and Infrastructure Security Agency and we are continuing with a full investigation.”

That “employee and flight information” includes, as crimew writes:

grabbing sample documents from various s3 buckets, going through flight plans and dumping some dynamodb tables. at this point i had found pretty much all PII imaginable for each of their crew members. full names, addresses, phone numbers, passport numbers, pilot’s license numbers, when their next linecheck is due and much more. i had trip sheets for every flight, the potential to access every flight plan ever, a whole bunch of image attachments to bookings for reimbursement flights containing yet again more PII, airplane maintenance data, you name it.

G/O Media may get a commission

Samsung Reserve

Up to $100 credit

Samsung Reserve

Reserve the next gen Samsung device
All you need to do is sign up with your email and boom: credit for your preorder on a new Samsung device.

The government is now investigating the leak, with the TSA telling the Daily Dot they are “aware of a potential cybersecurity incident, and we are investigating in coordination with our federal partners”.

If you’re wondering just how many names are on the list, it’s hard to tell. Crimew tells Kotaku that in this version of the records “there are about 1.5 million entries, but given a lot are different aliases for different people it’s very hard to know the actual number of unique people on it” (a 2016 estimate had the numbers at “2,484,442 records, consisting of 1,877,133 individual identities”).

Interestingly, given the list was uploaded to CommuteAir’s servers in 2022, it was assumed that was the year the records were from. Instead, crimew tells me “the only reason we [now] know [it] is from 2019 is because the airline keeps confirming so in all their press statements, before that we assumed it was from 2022.”

You can check out crimew’s blog here, while the Daily Dot post—which says names on the list include members of the IRA and an eight year-old—is here.



Source link

Tweet8Share13Share3Share
Previous Post

AFC, NFC Championship Games To Feature Stellar Quarterbacks

Next Post

THE MUSICAL ADVENTURES OF FLAT STANLEY at Dallas Children's Theater

North Dakota Digital News

North Dakota Digital News

Next Post
THE MUSICAL ADVENTURES OF FLAT STANLEY at Dallas Children's Theater

THE MUSICAL ADVENTURES OF FLAT STANLEY at Dallas Children's Theater

Discussion about this post

Bismarck
◉
14°
Cloudy
8:15 am5:35 pm CST
Feels like: 9°F
Wind: 4mph WNW
Humidity: 82%
Pressure: 30.34"Hg
UV index: 0
ThuFriSat
34/21°F
25/-6°F
-2/-17°F
Weather forecast Bismarck, North Dakota ▸
You Might Survive a Nuclear Blast—if You Have the Right Shelter
SCIENCE

You Might Survive a Nuclear Blast—if You Have the Right Shelter

by North Dakota Digital News
January 25, 2023
8K and 4K videos from the Samsung Galaxy S23 Ultra posted on the web
MOBILE

8K and 4K videos from the Samsung Galaxy S23 Ultra posted on the web

by North Dakota Digital News
January 25, 2023
‘GoldenEye 007’ will hit Switch and Xbox on January 27th
GADGET

‘GoldenEye 007’ will hit Switch and Xbox on January 27th

by North Dakota Digital News
January 25, 2023
APPS

Follow us. We design📱mobile apps 🌐WebsitesHave an awesome project?Let’s chat👋info@qclay.design

by North Dakota Digital News
January 25, 2023
How to Answer Interview Questions About Career Goals
MONEY

How to Answer Interview Questions About Career Goals

by North Dakota Digital News
January 25, 2023
2022-12-13 | OTCQX:USMT | Press Release
PRESS RELEASE

2023-01-25 | TSXV:NBM | Press Release

by North Dakota Digital News
January 25, 2023
Ticketmaster blames bots for botched Taylor Swift sale. Senator says it’s ‘unbelievable’ and company must ‘figure this out.’
MARKET

Ticketmaster blames bots for botched Taylor Swift sale. Senator says it’s ‘unbelievable’ and company must ‘figure this out.’

by North Dakota Digital News
January 25, 2023
Links 1/25/2023 | naked capitalism
ECONOMY

Links 1/25/2023 | naked capitalism

by North Dakota Digital News
January 25, 2023
ETH Falls Below $1,600 as Relative Strength Sinks – Market Updates Bitcoin News
CRYPTO

ETH Falls Below $1,600 as Relative Strength Sinks – Market Updates Bitcoin News

by North Dakota Digital News
January 25, 2023
Global Transportation Leader DSV Places Hypertruck ERX™ Order
PRESS RELEASE

Global Transportation Leader DSV Places Hypertruck ERX™ Order

by North Dakota Digital News
January 25, 2023
Echo and the Bunnymen – Live @ Roxian Theatre 9/19/22 – Full Concert
ARTS & THEATER

Echo and the Bunnymen – Live @ Roxian Theatre 9/19/22 – Full Concert

by North Dakota Digital News
January 25, 2023
Darktide’s Xbox Release Delayed So PC Version Can Be Fixed
GAMING

Darktide’s Xbox Release Delayed So PC Version Can Be Fixed

by North Dakota Digital News
January 25, 2023

About Us

North Dakota Digital News

Category

  • APPS
  • ARTS & THEATER
  • BUSINESS
  • CELEBRITY
  • CRYPTO
  • CULTURE
  • ECONOMY
  • Education
  • ENTERTAINMENT
  • FASHION
  • FINANCE
  • FOOD
  • GADGET
  • Gambling
  • GAMING
  • HEALTH
  • HISTORY
  • LIFESTYLE
  • MARKET
  • MOBILE
  • MONEY
  • MOVIE
  • MUSIC
  • Nature
  • News
  • PRESS RELEASE
  • REAL ESTATE
  • Religion
  • SCIENCE
  • Shopping
  • SHOWS
  • SPORTS
  • TECH
  • TRAVEL
SCIENCE

You Might Survive a Nuclear Blast—if You Have the Right Shelter

January 25, 2023
MOBILE

8K and 4K videos from the Samsung Galaxy S23 Ultra posted on the web

January 25, 2023
GADGET

‘GoldenEye 007’ will hit Switch and Xbox on January 27th

January 25, 2023

© 2022 northdakotadigitalnews.com

No Result
View All Result
  • Home
  • News
    • PRESS RELEASE
  • Shop
  • BUSINESS
    • CRYPTO
    • ECONOMY
    • FINANCE
    • MARKET
    • MONEY
  • TECH
    • APPS
    • GADGET
    • MOBILE
    • SCIENCE
  • SOCIAL MEDIA
  • ENTERTAINMENT
    • ARTS & THEATER
    • GAMING
    • GAMBLING
    • MOVIE
    • MUSIC
    • SHOWS
    • SPORTS
  • LIFESTYLE
    • CELEBRITY
    • CULTURE
    • Education
    • FASHION
    • FOOD
    • HEALTH
    • HISTORY
    • Nature
    • Religion
    • Shopping
    • TRAVEL
  • REAL ESTATE
  • Blog
  • Classifieds

© 2022 northdakotadigitalnews.com

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In