We use cookies on this website to provide a user experience that’s more tailored to you. By continuing to use the website, you are giving your consent to receive cookies on this site. Read more about our Cookie Policy and Privacy Policy.

I accept

Avaleht > Infomaterjalid > Blogi

2018-11-02

Hong Kong Airlines leaks passengers' personal information

Infoturve

Hong Kong Airlines leaks passengers' personal information

It is suspected that Hong Kong Airlines has a serious loophole in the e-boarding pass issued. By modifying the e-boarding pass URL, the boarding pass number and flight details of another passenger are disclosed. Important personal data such as passenger name, date of birth, passport number and expiry date can also be checked with the information via the official website of airline.

This vulnerability is one of the Open Web Application Security Project (OWASP)’s Top 10 vulnerabilities – A5:2017 “Broken Access Control”, programmers expose insecure direct object references. The airlines in the event did not encode the passenger information on the e-boarding pass, which results in the possibility of unauthorized access to important personal data of other passengers by modifying the e-boarding pass URL.

We recommend that when processing sensitive data, strict monitoring and identity authorization verification are required to reduce the risk of unauthenticated or unauthorized access exploiting by hackers. In addition, it is a best practice to perform a regular full assessment to enterprises’ network infrastructure and web applications which identifies potentially damaging vulnerabilities and threats.


Võtke ühendust
Ettevõtte nimetus:
Kontaktisiku nimi:
Ametikoht:
Kontakttelefon:

-

E-posti aadress:
Märkused

Kinnitamiseks lohistage

Tooted ja Teenused
Euroopa lahendused Võrgustiku loomine Infoturve Pilvelahendused Pilvandmekeskus Internetiteenused Haldatavad teenused
Lahendused
Arhitektuur, projekteerimine ja ehitus Autotööstus BFSI Logistika ja transport Tootmine Õigus- ja raamatupidamisteenused Jaemüük Healthcare
Tehnoloogia ja teenused
Konsultatsiooniteenused Klienditeenindus
Infomaterjalid
Teenuste brozüürid Uued pakkumised Videod Valge raamat Edulood Blogi
Firmast
Meie firma Globaalsed ökosüsteemi partnerid Uudised Akrediteerimised ja auhinnad Karjäär
Võtke ühendust

Üldtelefon:
+3726223399
Müük:
+3726223360

Tehniline abi +372 622 33 90

Võtke ühendust

Jälgi meid

Copyright © 中信國際電訊(信息技術)有限公司 CITIC Telecom International CPC Limited

Täname Teid päringu eest.


Võtame Teiega peagi ühendust.
Kuidas saada ühendust
Helistage meile

372 622 33 99

Kirjutage meile

Saatke meile oma küsimus