U.S. ‘No Fly List’ Leaks After Being Left in an Unsecured Airline Server

TL;DR

As first reported by The Daily Dot, a Swiss hacker known as maia arson crimew discovered the list on an unsecured Jenkins server one night while poking around on Shodan, a search engine that lets people look through servers connected to the internet.“Like so many other of my hacks this story starts with me being bored and browsing shodan (or well, technically zoomeye, Chinese shodan), looking for exposed jenkins servers that may contain some interesting goods,” crimew said in a blog about the leak.“At this point I've probably clicked through about 20 boring exposed servers with very little of any interest, when I suddenly start seeing some familiar words.An exposed jenkins server belonging to CommuteAir.”On the server was a large amount of company data about CommuteAir, including the private information about its employees.“It was just a matter of time until I found something like this.”CommuteAir said the leak happened because of a misconfigured development server."

Like summarized versions? Support us on Patreon!