create account

Security Flaw in Airline Booking Allows Hackers to Change Ticket Data and More by krnel

View this thread on: hive.blogpeakd.comecency.com
· @krnel · (edited)
$16.22
Security Flaw in Airline Booking Allows Hackers to Change Ticket Data and More
### Most of the airline booking systems were designed in the 70s and 80s, and have not been updated with newer technology, leaving customers extremely vulnerable to hackers who want to gain access to the system and change the data.

<center><img src="http://www.steemimg.com/images/2016/12/29/booking-flightad594.jpg" alt="booking-flightad594.jpg" border="0"><br/><em><a href="http://www.huffingtonpost.com/2015/02/23/dont-book-flights-early_n_6646836.html">source</a></em></center>

Karsten Noh and Nemanja Nikodijevic are two researchers working for the German security firm *Security Research Labs*. Their findings were presented on Dec. 27th at the [Chaos Communication Congress 2016](https://events.ccc.de/). Their research undertook the task of assessing the security strengths and weaknesses of the three largest airline booking systems. The booking systems are called Global Distribution Systems (GDS).

These old systems from the 70s and 80s that were designed for leased lines, have been interwoven with web services but still **lack web security**.

The main seurity issues are as follows:
- Weak authentication
- Weak web services
- Abuse potential
- Invade travelersโ€™ privacy
- Steal flights
- Divert miles
- Conduct phishing/vishing

While the rest of the world is debating which second and third factor authentication systems to use, the **old GDS's do not offer even a first authentication factor**. This is the main problem that the research uncovered.

A Passenger Name Record (PNR) Locator is a six digit alphanumeric string, like 8EI29V, used to access and change the travelers information.

The problem with these, is that they are a restricted access code, meaning that parts of the sequence of characters must fall within a predetermined range. The customers last names associated with the PNR, which means that hackers can use a travelers common name to run through all the possibilities until they find the proper access code through brute fore attack.

### To demonstrate the feasibility of this security flaw, the researchers reassigned a reporter to sit next to a politician on a real flight. They also showed how a hacker can tie their own frequent flyer number to many other flights and give themselves credit for thousands of miles.

<center><img src="http://www.steemimg.com/images/2016/12/29/plane582b3.jpg" alt="plane582b3.jpg" border="0"><br/><em><a href="https://techxplore.com/news/2016-12-experts-reveal-vulnerability-airline-reservation.html">source</a></em></center>

*The problems don't stop there.*

### All of this information that they can get about you from your flight records, can be used to track you, get additional information and possibly steal your identity. 

All three of the booking systems have been advised of their security flaws, which they are working on. One of them will have corrections out shortly, while the two others have much older systems that require a full rewrite of the system.

In the meantime, you can take measures yourself to ensure that the airline your booking with uses a trusted system. Make sure that the website uses a proper brute force protection, such as captchas and retry limits per IP address. In the mid-term, the researchers say travel bookings need to implement proper secure authentication with a changeable password at the very least.

---
#### Thank you for your time and attention! I appreciate the knowledge reaching more people. Take care. Peace.

---
References:
- [Security experts reveal vulnerability with airline reservation systems](https://techxplore.com/news/2016-12-experts-reveal-vulnerability-airline-reservation.html)
- [Legacy booking systems disclose travelersโ€™ private information](https://srlabs.de/bites/travel-hacking/)

---
##### If you appreciate and value the content, please consider: 
<center>Upvoting, Sharing, and Resteeming below.</center>

[![Follow](https://www.steemimg.com/images/2016/08/30/follow2be5e.png)](https://steemit.com/@krnel) me for more content to come!

---
@krnel
2016-12-29, 5pm
๐Ÿ‘  , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , and 205 others
properties (23)
authorkrnel
permlinksecurity-flaw-in-airline-booking-allows-hackers-to-change-ticket-data-and-more
categorysecurity
json_metadata{"tags":["security","travel","business","news"],"users":["krnel"],"image":["http://www.steemimg.com/images/2016/12/29/booking-flightad594.jpg","http://www.steemimg.com/images/2016/12/29/plane582b3.jpg","https://www.steemimg.com/images/2016/08/30/follow2be5e.png"],"links":["http://www.huffingtonpost.com/2015/02/23/dont-book-flights-early_n_6646836.html","https://events.ccc.de/","https://techxplore.com/news/2016-12-experts-reveal-vulnerability-airline-reservation.html","https://srlabs.de/bites/travel-hacking/","https://steemit.com/@krnel"],"app":"steemit/0.1","format":"markdown"}
created2016-12-29 22:00:54
last_update2016-12-29 22:05:27
depth0
children6
last_payout2017-01-29 22:43:06
cashout_time1969-12-31 23:59:59
total_payout_value14.794 HBD
curator_payout_value1.429 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length4,021
author_reputation1,343,547,270,297,082
root_title"Security Flaw in Airline Booking Allows Hackers to Change Ticket Data and More"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd0
post_id2,112,803
net_rshares47,813,427,387,236
author_curate_reward""
vote details (269)
@creatr ·
Once again, Wow!, @krnel,

This is incredibly disturbing but actionable information. Thank You! ๐Ÿ˜„๐Ÿ˜‡๐Ÿ˜„
<a href="https://goo.gl/UnnylV" target="_blank">
  <img src="http://i.giphy.com/xnfneJm878rPa.gif" alt="@creatr" style="border:0;">
</a>
๐Ÿ‘  
properties (23)
authorcreatr
permlinkre-krnel-security-flaw-in-airline-booking-allows-hackers-to-change-ticket-data-and-more-20161229t231845246z
categorysecurity
json_metadata{"tags":["security"],"users":["krnel"],"image":["http://i.giphy.com/xnfneJm878rPa.gif"],"links":["https://goo.gl/UnnylV"]}
created2016-12-29 23:18:45
last_update2016-12-29 23:18:45
depth1
children0
last_payout2017-01-29 22:43:06
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length236
author_reputation136,627,187,742,915
root_title"Security Flaw in Airline Booking Allows Hackers to Change Ticket Data and More"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id2,113,345
net_rshares125,511,952,537
author_curate_reward""
vote details (1)
@karenb54 ·
I'm in the UK and private information isn't so  private anymore, seems our Government wants to know everything we do
๐Ÿ‘  
properties (23)
authorkarenb54
permlinkre-krnel-security-flaw-in-airline-booking-allows-hackers-to-change-ticket-data-and-more-20161229t222343179z
categorysecurity
json_metadata{"tags":["security"]}
created2016-12-29 22:24:42
last_update2016-12-29 22:24:42
depth1
children1
last_payout2017-01-29 22:43:06
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length116
author_reputation713,685,122,311,590
root_title"Security Flaw in Airline Booking Allows Hackers to Change Ticket Data and More"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id2,112,973
net_rshares125,509,797,769
author_curate_reward""
vote details (1)
@krnel ·
Indeed they do.
properties (22)
authorkrnel
permlinkre-karenb54-re-krnel-security-flaw-in-airline-booking-allows-hackers-to-change-ticket-data-and-more-20161229t222716438z
categorysecurity
json_metadata{"tags":["security"]}
created2016-12-29 22:27:15
last_update2016-12-29 22:27:15
depth2
children0
last_payout2017-01-29 22:43:06
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length15
author_reputation1,343,547,270,297,082
root_title"Security Flaw in Airline Booking Allows Hackers to Change Ticket Data and More"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id2,112,992
net_rshares0
@kkay1961 · (edited)
Thank you, good information. My personal experience as a traveler for about 15 years is I have never had a hacking or personal data issue using many airlines. That is not to say these issue aren't real or shouldn't be addressed. Constent improvement is what it is all about. Again great article.
properties (22)
authorkkay1961
permlinkre-krnel-security-flaw-in-airline-booking-allows-hackers-to-change-ticket-data-and-more-20170101t153651608z
categorysecurity
json_metadata{"tags":["security"]}
created2017-01-01 15:36:54
last_update2017-01-01 15:38:30
depth1
children1
last_payout2017-01-29 22:43:06
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length295
author_reputation24,582,846,603
root_title"Security Flaw in Airline Booking Allows Hackers to Change Ticket Data and More"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id2,132,643
net_rshares0
@krnel ·
Yeah I'm not sure the hackers are doing this, or knew about it, but it's there for now.
properties (22)
authorkrnel
permlinkre-kkay1961-re-krnel-security-flaw-in-airline-booking-allows-hackers-to-change-ticket-data-and-more-20170101t165401484z
categorysecurity
json_metadata{"tags":["security"]}
created2017-01-01 16:54:00
last_update2017-01-01 16:54:00
depth2
children0
last_payout2017-01-29 22:43:06
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length87
author_reputation1,343,547,270,297,082
root_title"Security Flaw in Airline Booking Allows Hackers to Change Ticket Data and More"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id2,133,170
net_rshares0
@mranderson ·
Thanks for sharing another example of how centralization fails humans.
๐Ÿ‘  
properties (23)
authormranderson
permlinkre-krnel-security-flaw-in-airline-booking-allows-hackers-to-change-ticket-data-and-more-20161229t220718863z
categorysecurity
json_metadata{"tags":["security"]}
created2016-12-29 22:07:18
last_update2016-12-29 22:07:18
depth1
children0
last_payout2017-01-29 22:43:06
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length70
author_reputation4,004,740,218,138
root_title"Security Flaw in Airline Booking Allows Hackers to Change Ticket Data and More"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id2,112,848
net_rshares125,509,797,769
author_curate_reward""
vote details (1)