u/BTheEPIC

▲ 53 r/netsec

Spirit Airlines' post-liquidation web infrastructure consists of a poorly applied domain redirect, an exposed booking flow that still processes transactions, and a live Azure API still issuing valid flight records and PNRs. Plus, $35 of defensive domain registrations that immediately redirected human traffic.

Share the story via bte.ink/spirit

u/BTheEPIC — 11 days ago