None
EN
Leaked Secrets and Unlimited Miles: Hacking the Largest Airline and Hotel Rewards Platform
['Improper Authorization On Points Recipient Endpoint Allows Attacker To Authenticate As Any User Using Only Surname', 'Rewards Number', 'Authorization Bypass On', 'Widgets.Unitedmileageplus.Com', 'Allows Attacker To Authenticate As Any User Via Last Name', 'Potential Access To United Mileageplus Administration Panel']
Blog | Sam Curry
Leaked Tenant Credentials for Virgin Rewards Program allows Attacker to Sign API Requests on Behalf of Virgin (Add/Remove Rewards Points, Access Customer Accounts, Modify Rewards Program Settings, etc.) The credentials could be used to fully authenticate as the airline to the "lcp.points.com" API by signing HTTP requests using the disclosed secret, allowing an attacker to call any of the API calls intended for the airline like modifying customer accounts, adding/removing points, or modifying settings related to the Virgin rewards program.