FlyerTalk Forums - View Single Post - UAs Official Response to HKG Ticketing/IT Error: Redeem @ Correct Amount or Redeposit
Old Jul 19, 2012, 8:53 pm
  #1956  
alex_b
 
Join Date: Jul 2010
Location: London, UK
Programs: BA Gold, UA Nobody, Hilton Gold
Posts: 2,372
Originally Posted by West Coast Ace
Yes. The website is just a sexy front end. In SQL (db lingo) it goes something like this:

SELECT user from sales_table where saleDate='2012-07-12' and depCity='LAX' and arrCity='HKG' and payType='award'
I was actually wondering if it was SQL or knowing how 'legacy' so many of these systems are whether it was something more esoteric. Do you know what specific technology it is running on?

The 'IT mistake' has been bandied about (in the 25 pages I've read). Anyone think this could be a 'parting gift' from a disgruntled last day at the office type? Another reason UA may be in lockdown. Trying to find said person and get a confession out of them. Could be checking logs to see who was logged in and what commands they were running.
I doubt it, the reason being is that the error seems far too random for an insider attack. If you really wanted to screw over United (and had the unfettered admin access that would be needed for people who are claiming this is a hack) you'd just divide all of the award tables by 1000 or screw up a bunch of fare codes. If you were trying to do some insider stuff for personal gain you'd likely change a small number of values then reset them immediately after ticketing. Setting up a website bug that shows an incorrect value in one field whilst ticketing, followed by pulling lots, some or no miles from an account but only when transiting a few cities seems much too random for an attack.

I think Occam's razor applies, this was a screw up pure and simple. Now I'd love to see the incident analysis they write up, but I doubt they'd share it even if we asked nicely.
alex_b is offline