ISC StormCast for Wednesday, December 28th 2016
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 28 December 2016
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, December 28, 2016 edition of the Sands and Storm Center's Stormcast. My name is Johannes Ulrich and the I'm recording from Jacksonville, Florida. |
| 0:12.5 | Each year between Christmas and New Year, the Chaos Computer Club in Germany is having its annual conference, which is very big, lots of talks |
| 0:23.4 | comparable to DevCon in the US. And all the talks are not just live streamed, but you can |
| 0:30.2 | also listen to recordings of these talks. So if you have some time this week, I recommend you take a look at the site. I'll link |
| 0:40.1 | to the respective site of the conference and the live streams in the show notes. But one talk |
| 0:48.9 | that sort of has been picked up by the press is a talk about airlines. Now in this case it's not about |
| 0:57.2 | in-flight entertainment systems, but instead about the backend systems that sort of process your |
| 1:02.7 | tickets. If you ever booked a ticket, you probably realized that you can review your record, |
| 1:08.8 | even make changes to your booking as long as you have your |
| 1:13.3 | last name, and a six-digit code, the record locator. Now, for changes, what's not about |
| 1:20.6 | in-flight entertainment system and hacking planes, but sort of the more boring part of airline |
| 1:25.3 | operations, and that's the back-end ticket systems. |
| 1:29.1 | The main issue here is you only need the last name and a record locator, which typically is a |
| 1:35.7 | six-digit string. Now, you would think there are enough combinations with six letters and |
| 1:42.6 | numbers, but it turns out these are not assigned |
| 1:46.9 | randomly sometimes they're assigned in a sequence and more importantly the backend |
| 1:53.0 | systems do actually not have a rate limit enabled so it's pretty straightforward |
| 1:58.2 | with a simple script to send millions of requests trying to |
| 2:02.2 | prude force that record locator. |
| 2:05.4 | So not as exciting as changing the throttle of an airplane, but there's something that's quite |
| 2:11.2 | difficult to fix given all the stakeholders that have to work together to really make these |
| 2:17.0 | back-end systems work. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

