Delta site flaw lets passengers access others' boarding passes

Status
Not open for further replies.

Flashback

Enthusiast
Joined
Oct 29, 2006
Messages
10,977
Points
1,530
Delta site flaw lets passengers access others' boarding passes - Security - News - iTnews.com.au

Online check-in system vulnerability discovered.

A vulnerability in the website of American airline Delta allowed the airline's passengers to view and alter other travellers' boarding passes without their knowledge.


Hackers of New York founder Dani Grant this week revealed what appears to be a direct object reference vulnerability in Delta airline's website that allows passengers of the airline to access others' boarding passes by changing the URL.


The flaw also made it possible to view boarding passes of travellers on other airlines, Grant claimed, and to check in passengers online.
 
Get paid up to 25% in real cash from your everyday purchases from leading companies such as Virgin Australia, Booking.com, Coles, Apple, Microsoft and much more. Free to join and no catches!

AFF Supporters can remove this and all advertisements

AMX001595_Travel-Insider_1100x260

JohnK

Veteran Member
Joined
Mar 22, 2005
Messages
43,731
Points
3,070
How do they access boarding passes for passengers of other airlines?
 

eastwest101

Established Member
Joined
Oct 26, 2010
Messages
3,169
Points
705
How do they access boarding passes for passengers of other airlines?

Either a velnerability with Sabre (AA and DL both use Sabre) or maybe something to do with code shares? From what I read in another article it was a pretty primitive but obvious hole. Maybe so obvious that it escaped attention?
 
Status
Not open for further replies.
Top