OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Chris Fairbourne (chris.fairbournecamsystems.com)
Date: Mon Sep 17 2001 - 12:39:06 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    Looks like aa.com (American Airlines) is NOT encrypting customer data for
    purchasing e-tickets.
    Hopefully this isn't still the case by the time this posts.
    This hold true for both Advantage login and non-members as well.
    At no time did I get a redirect to an SSL server for my session.

    Taking a peek at the "Passenger Details" page source, no where do you find
    "https" or ":443", hmm.
    Next I make a phony submission and low and behold this is what I grabbed:
    " f o r m % C I _ C r e d i t C a r d T o U s e _ C a
     r d N u m b e r " v a l u e = " 4 3 2 3 5 0 1 9 8 3 5 1 9 9 9 9 "

    I've made serveral phone calls to aa.com and generated a few e-mail.
    I can't convince them I'm wrong, so I bring it to this forum.

     

    Chris Fairbourne
    pgpkey: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0x371E73BB
    fingerprint: 7AE3DCC82215697A0C3F61C4968FCFDB371E73BB