Friday, October 26, 2012

Airline Bar Codes Give Away Security Status and can be modified with smart phones

@ Home Printed Airline Boarding Passes Can Be Modified to Avoid Safety Screenings

Barcode data can be altered to allow passengers to go through the U.S. TSA's PreCheck lines with lighter security


  • Blogger explains how he was able to decode his own boarding pass



Read more: http://www.dailymail.co.uk/sciencetech/article-2223652/Fears-airline-boarding-pass-barcodes-read-mobile-phone-altered-avoid-security-checks.html#ixzz2AQh600KS
Follow us: @MailOnline on Twitter | DailyMail on Facebook



Barcodes on airline boarding passes can be read using smartphones and altered to allow passengers through lighter security checks, an aviation security researcher has claimed.

The U.S. Transport Security Administration (TSA) runs a program called PreCheck which allows frequent fliers to be randomly chosen for 'expedited screening' before boarding domestic flights.

Boarding passes for travel on U.S. airlines feature barcodes which include data telling security staff whether the passenger has been chosen to go through these less stringent checks.

Vulnerability: An airline security blogger has shown how boarding pass barcodes can be read using a phone then edited to allow passengers to avoid stringent pre-flight security checks
Vulnerability: An airline security blogger has shown how boarding pass barcodes can be read using a phone then edited to allow passengers to avoid stringent pre-flight security checks

Those selected go through dedicated screening lines which allow them to leave on their shoes, belts and jackets, keep hold of their toiletries and laptops, and avoid the controversial full-body scanners.
With passengers able to print their boarding passes before they leave home, they can use barcode readers - which are available as smartphone apps - to see whether they have been selected.
 
    The vulnerability in the system was highlighted last week by John Butler in his aviation blog Puckinflight - where he revealed the barcode information was unencrypted.

    Explaining how he has been able to decode the barcode on a boarding pass for an upcoming trip, he writes that he has published the information because he is 'seriously concerned with boarding pass security'.
    He shows how the final digit in the decoded data is either a one or a three - depending on whether or not the passenger has been selected for PreCheck.

    A man undergoes a pat-down during TSA security screening: Travellers selected for the agency's PreCheck programme can avoid having to remove their shoes, belts and jackets
    A man undergoes a pat-down during TSA security screening: Travellers selected for the agency's PreCheck programme can avoid having to remove their shoes, belts and jackets

    'What  terrorists  or really anyone can do is use a website to decode the barcode and get the flight information, put it into a text file, change the 1 to a 3, then use another website to re-encode it into a barcode,' he writes.
    'Finally, using a commercial photo-editing program or any program that can edit graphics [they can] replace the barcode in their boarding pass with the new one they created.'

    Other information stored on the barcode could be changed in exactly the same way, Mr Butler explains, including the passenger name and even the flight details.

    'The really scary part is this will get past both the TSA document checker, because the scanners the TSA use are just barcode decoders, they don’t check against the real time information,' he adds.

    So as long as the passenger remembers to put three on the end of the data they will always get through. Mr Butler said he has contacted the TSA to report the vulnerability.


    Read more: http://www.dailymail.co.uk/sciencetech/article-2223652/Fears-airline-boarding-pass-barcodes-read-mobile-phone-altered-avoid-security-checks.html#ixzz2AQfmcj2P
    Follow us: @MailOnline on Twitter | DailyMail on Facebook

    Thursday, October 25, 2012

    Barns & Noble Credit/Debit Readers Hacked


     Barns & Noble CC Readers Hacked and Bug implanted to steal Credit/Debit Card  Numbers and PINS...

    Barnes & Noble is warning its customers to check their credit and debit card statements for unauthorized transactions after discovering someone tampered with its card readers in 63 stores across the country.  
    See store list at bottom of this article
    Only one device was tampered with in each store, affecting fewer than 1 percent of card readers in Barnes & Noble stores, the company said in a news release on Wednesday.  The company disconnected all of the devices at its 700 stores after discovering the tampering on Sept. 14.  
    The FBI asked Barnes & Noble not to disclose the breach last month, for fear of compromising the investigation.
    The criminals apparently planted bugs in the devices to get customers’ credit card and PIN numbers, Barnes & Noble said, calling the tampering a “sophisticated criminal effort.”
    The nation’s largest bookseller is working with federal law enforcement authorities as well as banks, payment card brands and issuers to identify accounts that may have been compromised.
    But as a precaution, Barnes & Noble said debit card users who shopped at affected stores should change their pin numbers.
    B&N insists its customer database is secure.
    The company also stressed that the breach involved only purchases made in a store using one of the tampered devices and that transactions on Barnes & Noble.com, Nook devices and apps were not affected.
    If this could be done at B&N, then why not Wal-Mart, Kroger, Costco, Target, etc, I would suspect that Barnes and Noble are not the only retail chain hacked.
    Here is the list of affected stores:  If you feel you might have been a victim, call your local FBI office as they are investigating this as "organized" crime.
    Store Address
    City
    State
    Zip
    4735 Commons Way
    Calabasas
    CA
    91302
    2470 Tuscany Street Suite 101
    Corona
    CA
    92881
    2015 Birch Road Suite 700
    Chula Vista
    CA
    91915
    313 Corte Madera Town Center
    Corte Madera
    CA
    94925
    5604 Bay Street
    Emeryville
    CA
    94608
    810 West Valley Parkway
    Escondido
    CA
    92025
    1315 E. Gladstone Street
    Glendora
    CA
    91740
    5183 Montclair Plaza Lane
    Montclair
    CA
    91763
    894 Marsh St Bldg G
    San Luis Obispo
    CA
    93401
    2615 Vista Way
    Oceanside
    CA
    92054
    72-840 Highway 111 Suite 425
    Palm Desert
    CA
    92260
    27460 Lugonia Ave
    Redlands
    CA
    92374
    1150 El Camino Real Space 277
    San Bruno
    CA
    94066
    10775 Westview Parkway
    San Diego
    CA
    92126
    3600 Stevens Creek Blvd
    San Jose
    CA
    95117
    11 West Hillsdale Blvd.
    San Mateo
    CA
    94403
    9938 Mission Gorge Road
    Santee
    CA
    92071
    40570 Winchester Rd
    Temecula
    CA
    92591
    4820 Telephone Road
    Ventura
    CA
    93003
    1149 S. Main St.
    Walnut Creek
    CA
    94596
    470 Universal Drive North
    North Haven
    CT
    06473
    100 Greyrock Place Suite H009
    Stamford
    CT
    06901
    60 Isham Road
    W. Hartford
    CT
    06107
    18711 NE Biscayne Blvd
    Aventura
    FL
    33180
    333 N. Congress Avenue
    Boynton Beach
    FL
    33436
    152 Miracle Mile
    Coral Gables
    FL
    33134
    1900 W International Spdway
    Daytona Beach
    FL
    32114
    2051 N. Federal Highway
    Fort Lauderdale
    FL
    33305
    12405 N Kendall Drive
    Miami
    FL
    33186
    11380 Legacy Ave
    Palm Beach Gardens
    FL
    33410
    14572 SW 5th St Suite 10140
    Pembroke Pines
    FL
    33027
    11820 Pines Blvd
    Pembroke Pines
    FL
    33026
    5701 Sunset Drive Suite 196
    S. Miami
    FL
    33143
    700 Rosemary Ave Unit #104
    West Palm Beach
    FL
    33401
    1441 West Webster Avenue
    Chicago
    IL
    60614
    1130 North State Street
    Chicago
    IL
    60610
    5380 Route 14
    Crystal Lake
    IL
    60014
    20600 North Rand Road
    Deer Park
    IL
    60010
    728 North Waukegan Road
    Deerfield
    IL
    60015
    1630 Sherman Avenue
    Evanston
    IL
    60201
    1468 Springhill Mall Blvd
    W. Dundee
    IL
    60118
    170 Boylston Street
    Chestnut Hill
    MA
    02467
    96 Derby Street Suite 300
    Hingham
    MA
    02043
    82 Providence Highway
    East Walpole
    MA
    2032
    395 Route 3 East
    Clifton
    NJ
    07014
    55 Parsonage Road
    Edison
    NJ
    08837
    2134 State Highway 35
    Holmdel
    NJ
    07733
    4831 US Hwy 9
    Howell
    NJ
    07731
    23-80 Bell Blvd.
    Bayside
    NY
    11360
    176-60 Union Turnpike
    Fresh Meadows
    NY
    11366
    1542 Northern Blvd
    Manhasset
    NY
    11030
    160 E 54th Street (Citicorp)
    New York
    NY
    10022
    2289 Broadway
    New York
    NY
    10024
    33 East 17th Street (Union Square)
    New York
    NY
    10003
    555 Fifth Ave
    New York
    NY
    10017
    2245 Richmond Avenue
    Staten Island
    NY
    10314
    230 Main St
    White Plains
    NY
    10601
    97 Warren Street
    New York
    NY
    10007
    100 West Bridge Street
    Homestead
    PA
    15120
    800 Settlers Ridge Center Drive
    Pittsburgh
    PA
    15205
    1311 West Main Road
    Middleton
    RI
    02842
    371 Putnam Pike  Suite 330
    Smithfield
    RI
    02917
    1350-B Bald Hill Rd
    Warwick
    RI
    02886