Delta site flaw lets passengers access others' boarding passes

Status
Not open for further replies.

Flashback

Enthusiast
Joined
Oct 29, 2006
Posts
13,246
Delta site flaw lets passengers access others' boarding passes - Security - News - iTnews.com.au

Online check-in system vulnerability discovered.

A vulnerability in the website of American airline Delta allowed the airline's passengers to view and alter other travellers' boarding passes without their knowledge.


Hackers of New York founder Dani Grant this week revealed what appears to be a direct object reference vulnerability in Delta airline's website that allows passengers of the airline to access others' boarding passes by changing the URL.


The flaw also made it possible to view boarding passes of travellers on other airlines, Grant claimed, and to check in passengers online.
 
How do they access boarding passes for passengers of other airlines?
 
How do they access boarding passes for passengers of other airlines?

Either a velnerability with Sabre (AA and DL both use Sabre) or maybe something to do with code shares? From what I read in another article it was a pretty primitive but obvious hole. Maybe so obvious that it escaped attention?
 
Read our AFF credit card guides and start earning more points now.

AFF Supporters can remove this and all advertisements

Status
Not open for further replies.

Become an AFF member!

Join Australian Frequent Flyer (AFF) for free and unlock insider tips, exclusive deals, and global meetups with 65,000+ frequent flyers.

AFF members can also access our Frequent Flyer Training courses, and upgrade to Fast-track your way to expert traveller status and unlock even more exclusive discounts!

AFF forum abbreviations

Wondering about Y, J or any of the other abbreviations used on our forum?

Check out our guide to common AFF acronyms & abbreviations.

Currently Active Users

Back
Top