back

by gregsadetsky·6y ago·view on hn ↗
Ooh, this reminds me that I saw a file being included straight from github.com on flyporter.com (Canadian regional airline)

Actually, extremely weirdly, they didn't include the "actual" file (the raw version of it) but ... they included the github page in the <script> tag...??

Go through a checkout on flyporter.com (use dates > Aug 31st as they're resuming service then) and you'll see

`<script src="https://github.com/furf/jquery-ui-touch-punch/blob/master/jq...

in the source code which makes no sense (try that URL in your browser!)

I contacted everyone I could find on LinkedIn who's working as CTO/CIO/etc. there, AND emailed them but never heard back. (this was 9 months ago... the issue is still there)

Isn't this how the British Airways checkout ended up being hacked?