x404.co.uk
http://www.x404.co.uk/forum/

Ryanair - Others Can Edit Your Flight Booking
http://www.x404.co.uk/forum/viewtopic.php?f=3&t=12370
Page 1 of 1

Author:  pcernie [ Thu Feb 03, 2011 11:34 pm ]
Post subject:  Ryanair - Others Can Edit Your Flight Booking

Economy airline Ryanair's online booking system allows for flight amendments and the addition of extra services for their associated fees. According to a report by Berlin newspaper Der Tagesspiegel (German language link), it's easy for an outsider to gain access to the system using just a reservation number or email address along with the flight date as well as the departure and destination airports. This data can be found out quite easily, for example by asking people about their holiday plans via Facebook. It's therefore relatively easy for anyone to maliciously manipulate Ryanair bookings.

Update: While other airlines require either a password or a unique booking number to access their booking systems, Ryanair's spokesman Daniel de Carvalho apparently considers this as dispensible. In a statement to Der Tagesspiegel he waved off concerns issued by experts consulted by Der Tagesspiegel. In direct communication with The H in response to the original wording of this last paragraph of our report, Ryanair's PR forwarded the full statement in English: "Your ‘experts’ are talking complete rubbish. If someone’s lunatic ex-partner wants to access a flight booking and pay for priority boarding or extra baggage for the person they just split up from then they all have a lot more to worry about than a simple amended flight booking. It is everyone’s individual responsibility to keep their personal information personal."

http://www.h-online.com/security/news/i ... 81896.html

FYI...

Author:  l3v1ck [ Fri Feb 04, 2011 1:04 am ]
Post subject:  Re: Ryanair - Others Can Edit Your Flight Booking

El Reg CLICKY
Quote:
Daniel de Carvalho, a spokesman for Ryanair, dismissed concerns that extra (or as he put it "superfluous"1) security to its booking system might be needed in defence against possible attacks. He told Der Tagesspiegel that it's up to passengers to keep their information secure, implying it's a passenger's hard luck if something goes awry.

But as web developer Thomas Cannon points out, email addresses are freely handed out on business cards and seldom kept secret. Once an email address is known then it becomes a simple exercise in scripting to try every possible combination of flight for a particular day.

"If we knew someone’s email address and were to write a script that programatically submitted requests to the Ryanair website at a relatively slow rate of four per second, it would take just over 10 minutes to check every flight permutation for a flight on a single date," Cannon argues. "To brute force every permutation against an email address for the whole of next month it would take just over five hours."

Author:  bobbdobbs [ Fri Feb 04, 2011 8:44 am ]
Post subject:  Re: Ryanair - Others Can Edit Your Flight Booking

Ryanair will only do something when forced to by the courts.
They seem to have the attitude [LIFTED] the customer.
Every flight I have taken, if I could of taken a Ryanair flight I would of been charged more and usually to go to a more out of the way inconvienant airport..
Im sure if they thought they could get away with it they call Newcastle airport as London: north!

Page 1 of 1 All times are UTC
Powered by phpBB® Forum Software © phpBB Group
https://www.phpbb.com/