Over 140 International Airlines Affected by Major Security Breach

LASER_oneXM

Level 37
Thread author
Verified
Top Poster
Well-known
Feb 4, 2016
2,520
Potential attackers could view and change private information in flight bookings made by millions of customers of major international airlines because of a security issue in the Amadeus online booking system found by Safety Detective's Noam Rotem.

Currently, the Amadeus ticket booking system is being used by 141 international airlines which gives it control over 44% of the global online reservation market, with United Airlines, Lufthansa, and Air Canada being some of its clients.

As described by Safety Detective's research labs, the security bug was found when trying to book a flight on the EL AL airline, Israel's national carrier, which sent the security researchers "the following link to check our PNR: https://fly.elal.co.il/LOTS-OF-NUMBERS-HERE."

From there it was only a matter of changing the RULE_SOURCE_1_ID which allowed them to view any Passenger Name Record (PNR), giving them access to the passengers' names as well as to all associated flight details.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top