【】
Everybody makes mistakes at work but, leaving the no-fly list exposed on the internet seems like a really bad mess-up.
That's reportedly what happened with the U.S. airline CommuteAir. The Daily Dot reported that a Swiss hacker known as "maia arson crimew" found the unsecured server while using the specialized search engine Shodan. There was apparently a lotof sensitive information on the server, including a version of the no-fly list from four years ago. Somewhat hilariously that was reportedly found via a text file labeled "NoFly.csv." That is...not hard to guess.
A blog post from crimew titled "how to completely own an airline in 3 easy steps" cited boredom as the reason for finding the server. They were just poking around and found it.
"At this point, I've probably clicked through about 20 boring exposed servers with very little of any interest, when I suddenly start seeing some familiar words," crimew says in their blogpost. "'ACARS', lots of mentions of 'crew' and so on. Lots of words I've heard before, most likely while binge-watching Mentour Pilot YouTube videos. Jackpot. An exposed jenkins server belonging to CommuteAir."
Tweet may have been deleted
CommuteAir, a regional US airline headquartered in Ohio, confirmed the info on the server was authentic to the Daily Dot. The server has been taken offline.
Related Stories
- Delta Airlines to offer free WiFi on most domestic flights by February
- Chinese government-linked hackers stole millions in COVID funds
- Southwest Airlines is offering 25,000 rewards points to inconvenienced passengers. How to claim them.
- Kickstart a career in cybersecurity with this ethical hacking and pen testing bundle
- Hacker steals $100 million from crypto project Mango, then things get weird
"The server contained data from a 2019 version of the federal no-fly list that included first and last names and dates of birth," CommuteAir Corporate Communications Manager Erik Kane told the Daily Dot. "In addition, certain CommuteAir employee and flight information was accessible. We have submitted notification to the Cybersecurity and Infrastructure Security Agency and we are continuing with a full investigation."
The info from the server has already been poured over, with some researchers saying it shows how the list is heavily biased against Muslim people. According to Daily Dot, while there is no official number to how many names are on the no-fly list, Sen. Dianne Feinstein (D-Calif.) suggested in 2016, that over 81,000 people were on the list.
TopicsCybersecurity
相关文章

Uber's $100M settlement over drivers as contractors may not be enough
UPDATE: Sept. 7, 2016, 4:41 p.m. EDT。 A ruling in a different case on Wednesday, Sept. 7 may have ch2026-06-13
記住身體是自己的 ,一定要管住自己的嘴 ,寧可多花點時間自己做 。為了讓你做得更順利 ,小編就先來介紹下關於紅棗枸杞蒸豬肝這道菜的做法。1.豬肝買回用加了一勺醋的水泡30分鍾,其中常換水 ,或者經常用流動的水泡2026-06-13
Hawk Tuah girl's merch is already raking in lots of cash
If Hawk Tuah Girl was hesitant about her sudden overnight fame, maybe things are starting to shift n2026-06-13
每天上班累成狗?一到周末睡成豬 ?這樣的生活遲早剝奪了你的健康。雖然一周五天的工作很辛苦 ,但是周末是否該犒勞一下自己的胃呢?這時你需要安心地給自己做幾個好吃的菜品。對於此 ,小編就來為大家介紹一下蔥香瘦肉2026-06-13
Tesla's rumored P100D could make Ludicrous mode even more Ludicrous
A Tesla Model S P100D begs the question: What's more Ludicrous than Ludicrous?Right now, the biggest2026-06-13
WNBA 2024 livestream: How to watch WNBA for free from anywhere in the world
TL;DR:Live stream the 2024 WNBA season from anywhere in the world with WNBA League Pass or Prime Vid2026-06-13

最新评论