Text: | Print|

Airlines deny responsibility for information leak   

多家航空公司信息泄露漏洞被公布 回应:均不卖帐

记者昨天在乌云网上看到,仅1月29日一天就有5条涉及航空公司的漏洞得到公司确认,内容涉及:航空公司B2C系统沦陷,千万机票信息可以查看;民航出入境API系统逻辑缺陷,导致出入境实时数据泄露;航空公司内部员工邮箱账号和密码泄露,可登录公司内部邮件系统。不过,漏洞的细节并未进入到公开流程,还处于保密阶段。 [查看全文]
2015-02-02 15:00 Ecns.cn Web Editor: Mo Hong'e
1

(ECNS) -- Several Chinese airlines have denied being responsible for a leak of passenger information, China National Radio reported on Monday.

The leaked data include user names, ID numbers, mobile numbers, and airline information, posing a critical threat to consumer safety, according to a report by WooYun.org, a renowned third-party Internet security platform.

The airline companies have confirmed the news, but denied responsibility, saying that the data were leaked through other channels and not their websites. 

China Eastern Airlines said information must have been hacked into via third parties seeing as its own payment system does not have any security flaws.

Xiamen Airlines said it has stopped using the targeted ticketing system for two years, explaining that the WooYun report "overstated the data leak."

TravelSky Technology, a leading provider of information technology solutions for China's air travel and tourism industries, was also accused of security problems. Bo Manhui, company general manager, noted that their database is thoroughly encrypted and that they regularly check for any hidden flaws on their website.

Wu Di, a co-director at WooYun, insisted that their report gave an accurate picture of the situation.

Management vulnerability, including information sold by insiders, could result in leaks, while flaws in online systems could also cause trouble, Wu said.

Zhao Wu, an expert with 360 Safe Global, stressed that online vulnerability would still exist despite developments in network security, allowing hacking to occur.

Comments (0)
Most popular in 24h
  Archived Content
Media partners:

Copyright ©1999-2018 Chinanews.com. All rights reserved.
Reproduction in whole or in part without permission is prohibited.