4

Hacker finds copy of TSA no-fly list on exposed cloud storage

 1 year ago
source link: https://siliconangle.com/2023/01/22/hacker-finds-copy-tsa-no-fly-list-exposed-cloud-storage/
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.
neoserver,ios ssh client

Hacker finds copy of TSA no-fly list on exposed cloud storage

noflylistleaks.jpg
SECURITY

A copy of the U.S. Transportation Security Administration’s “no-fly list” has been found by a Swiss hacker exposed on the open internet in yet another case of misconfigured cloud storage.

First reported by The Daily Dot, the exposure of the database was found by a Swiss hacker known as “maia arson crimew” on a server run by regional airline CommuteAir LLC. The hacker spotted the exposed data using Shodan, a search engine used to locate servers exposed to the internet.

The server run by CommuteAir, which primarily runs regional flights for United Airlines Inc., was found to be exposing the private information of almost 1,000 employees along with a file labeled “NoFly.csv.” The file contained 1.5 million records in total, including names and dates of birth, although allowing for aliases, the total number of unique records in the database is believed to be lower.

Notable entries in the database include Russian arms dealer Viktor Bout, the same arms dealer handed over to Russia in return for a basketball player Brittney Griner, including 16 aliases he is believed to use. Other records included suspected members of the Irish Republican Army.

In response to the report, CommuteAir said that it had taken down the database and does not believe that any customer information was exposed based on an initial investigation. “The server contained data from a 2019 version of the federal no-fly list that included first and last names and dates of birth,” a spokesperson said. “In addition, certain CommuteAir employee and flight information was accessible.”

The news, which broke over the weekend, has not been well-received. Dan Bishop, a Republican congressman who serves on the House Homeland Security Committee, said on Twitter that Congress “will be coming for answers” and noted that “besides the fact that the list is a civil liberties nightmare, how was this info so easily accessible?”

The answer to his question was yet another case of an Amazon Web Services Inc. user not securing storage. The explanation may seem simple, but the hacker details it on a blog. It happens so often that it’s impossible to keep up with cases, be it that they don’t usually expose the TSA no-fly list.

“Unsecured public-facing servers are an attacker’s bread-and-butter and an organization’s nightmare,” Sammy Migues, principal scientist at Synopsys Software Integrity Group, told SiliconANGLE. “This is especially true when the server is unsecured long enough to appear in connected-device search engines such as Shodan and ZoomEye.”

In this case, he added, it appears that the unsecured server was running Jenkins, which provides automation for software development toolchains. “With some exploration and lateral movement, it appears there was access to production systems that held sensitive information, including an older version of a U.S. no-fly list,” he said.

Photo: Michael Ball/Wikimedia Commons

A message from John Furrier, co-founder of SiliconANGLE:

Show your support for our mission by joining our Cube Club and Cube Event Community of experts. Join the community that includes Amazon Web Services and Amazon.com CEO Andy Jassy, Dell Technologies founder and CEO Michael Dell, Intel CEO Pat Gelsinger and many more luminaries and experts.

Join Our Community 

Click here to join the free and open Startup Showcase event.

“TheCUBE is part of re:Invent, you know, you guys really are a part of the event and we really appreciate your coming here and I know people appreciate the content you create as well” – Andy Jassy

We really want to hear from you, and we’re looking forward to seeing you at the event and in theCUBE Club.

Click here to join the free and open Startup Showcase event.


About Joyk


Aggregate valuable and interesting links.
Joyk means Joy of geeK