메뉴
BL
Wired AI 28일 전

클로드, 미국 유료 페스티벌 무료 VIP 티켓 발행 해킹 방법 찾아내

IMP
8/10
핵심 요약

보안 연구원이 AI 도구 Claude를 이용해 미국 주요 음악 페스티벌의 티켓을 담당하는 Front Gate Tickets 시스템의 취약점을 찾아내고, 최고 관리자 권한을 획득해 무제한 VIP 티켓을 발행할 수 있음을 증명했습니다. 해당 연구원은 악용 대신 즉시 취약점을 신고했고, 회사 측은 24시간 내에 이를 조치했다고 밝혔습니다. 이 사건은 AI가 인터넷 전반의 해킹 가능한 버그를 얼마나 쉽고 폭넓게 찾아낼 수 있는지 보여주는 중요한 사례입니다.

번역된 본문

자율적인 해킹이 가능한 AI 도구에 대한 두려움은 보통 핵무기 발사 코드 도용이나 은행 예금 잔고를 0으로 만드는 것과 같은 악몽 같은 시나리오를 떠올리게 합니다. 하지만 현실적으로 훨씬 더 그럴듯한 시나리오는, AI에게 티켓팅 웹사이트의 최고 관리자 권한을 획득하라고 요청한 뒤 본인과 모든 친구들을 위해 보나루(Bonnaroo) 페스티벌의 무료 VIP 후스타운(backstage) 패스를 발행받는 것입니다.

이것이 보안 연구원 이안 캐럴(Ian Carroll)의 발견이었습니다. 그는 4월에 AI 도구인 Claude Opus 4.7을 사용하여 프론트 게이트 티켓(Front Gate Tickets) 시스템에 대한 전면적인 접근 권한을 얻을 수 있는 기법을 발견했습니다. 이 회사는 롤라팔루자(Lollapalooza)와 사우스 바이 사우스웨스트(SXSW), 오스틴 시티 리미츠(ACL)에 이르기까지 거의 모든 미국 주요 음악 페스티벌의 티켓팅을 처리합니다. 캐럴은 티켓마스터와 마찬가지로 이벤트 기업 라이브 네이션 엔터테인먼트(Live Nation Entertainment)의 자회사인 프론트 게이트의 웹사이트에 버그가 있었으며, Claude의 도움을 받아 이를 악용해 수백만 건의 고객 또는 직원 기록에 액세스하고, 원하는 어떤 가치의 이벤트 티겟이든 자신이나 지정한 사람에게 자유롭게 발행할 수 있었다는 사실을 알아냈습니다.

스타트업 Seats.aero를 운영하면서 독립적인 보안 연구도 수행하는 캐럴은 "4,000달러짜리 티켓을 보고 버튼만 누르면 원하는 만큼 발행할 수 있다는 것을 알게 된 것은 꽤 멋진 일이었다"며 "아무런 제한이나 제약 없이 모든 이벤트에 참석할 수 있었다. 매진되었더라도 백스테이지 패스나 슈퍼 VIP를 대상으로 판매되는 모든 것을 얻을 수 있었다"고 말했습니다.

캐럴은 실제로 이러한 티켓 발행 능력을 악용하지 않았으며, 대신 프론트 게이트 측에 자신의 발견을 보고했고 회사 측은 현재 해당 취약점을 패치했다고 밝혔습니다. 와이어드(WIRED)의 연락을 받은 회사 측은 성명을 통해 캐럴에게 해킹 가능한 결함을 보고해 준 것에 감사를 표하고, 이 사건을 보안 개선으로 이어진 성공적인 협업으로 규정했습니다.

성명서에서는 "이 문제는 24시간 이내에 해결되었으며, 악용, 티켓 영향, 고객 정보 유출의 증거는 없음을 확인할 수 있었다"며 "이 문제는 책임감 있는 보안 연구원에 의해 발견되었는데, 그는 AI 지원 도구를 사용하여 표준 방화벽 보안 제어를 우회하고 페스티벌 행사장의 입장 스캐너가 사용하는 내부 API에 액세스한 것이며, 이는 소비자를 향한 시스템이나 공용 로그인 포털이 아니다"라고 설명했습니다.

하지만 결함이 수정된 지금이라도, 이 사건은 AI가 인터넷의 모든 측면에서 해킹 가능한 버그를 얼마나 광범위하게 파헤칠 수 있는지를 보여줍니다. 승인된 보안 연구자들이 특정 해킹 기능에 AI 도구를 사용할 수 있도록 허용하는 앤스로픽(Anthropic)의 사이버 검증 프로그램(Cyber Verification Program)에 참여하고 있는 캐럴은, Claude가 프론트 게이트 사이트에 침투하기 위한 자신의 기술 핵심 요소를 얼마나 쉽게 생각해 냈는지에 놀랐다고 말합니다.

캐럴은 "내가 아무것도 하지 않았어도 AI가 종단 간(End-to-End)으로 이 취약점을 찾아냈을 가능성이 매우 높다고 생각한다"고 말했습니다. 와이어드의 연락을 받은 앤스로픽은 성명을 통해 "우리는 방어자가 세계의 코드를 더 안전하게 만드는 데 도움이 되는 바로 이런 종류의 연구를 수행할 수 있도록 고급 보안 기능을 제공하기 위해 사이버 검증 프로그램을 만들었다"고 밝혔습니다. 또한 캐럴이 이 프로그램의 일원이 아니었다면, 프론트 게이트 시스템을 해킹하기 위해 Claude를 사용하는 행위가 탐지되어 차단되었을 것이라고 덧붙였습니다.

와이어드에 대한 답변에서 프론트 게이트 대변인은 회사의 보안 장치가 개인 정보 노출을 제한했으며, 티켓을 사적으로 발행했더라도 감사 추적(audit trail)이 남았을 것이고, 해커가 발행한 티켓은 사용되기 전에 탐지되어 취소되었을 것이라고 주장했습니다. 이에 대해 캐럴은 회사의 주장이 기껏해야 불확실할 뿐이라고 반박합니다. 그는 회사 측으로부터 어떤 눈에 띄는 대응도 받지 않고 회사 플랫폼에서 최고 관리자 권한을 성공적으로 얻었으며, 실제로 공개 로그인 포털을 통해 사이트에 액세스했다고 말합니다. 또한 캐럴은 프론트 게이트가 해당 취약점이 이전에 악용되지 않았다는 증거를 가지고 있다고 주장하지는 않는다고 지적했습니다. 게다가 프론트 게이트는 확인했습니다.

원문 보기
원문 보기 (영어)
Comment Loader Save Story Save this story Comment Loader Save Story Save this story Fears about AI tools capable of autonomous hacking usually involve nightmare scenarios like the theft of nuclear launch codes or zeroed-out bank reserves. Far more plausible, it turns out, is asking AI to gain super-administrator access on a ticketing website and then issuing yourself and all of your friends free VIP backstage passes to Bonnaroo. That was the discovery of security researcher Ian Carroll, who used the AI tool Claude Opus 4.7 in April to discover a technique that allowed him full access to the systems of Front Gate Tickets, which handles ticketing for practically every major US music festival, from Lollapalooza and South by Southwest to Austin City Limits. Carroll found that Front Gate, which like Ticketmaster is a subsidiary of the event company Live Nation Entertainment, had a bug in its website that he—with Claude’s help—could exploit to gain access to millions of customer or staff records and freely issue tickets for any event, of any value, to himself or whoever he chose. “It was pretty cool to see a ticket that’s $4,000, and I could just hit a button and issue as many as I wanted,” says Carroll, who runs the startup Seats.aero but also does independent security research. “I could go to every single event with no limitations or restrictions: I could get the backstage pass or whatever they sell to the super VIPs—even if it’s sold out.” Carroll did not, in fact, take advantage of his ticket-issuing superpower, and instead reported his findings to Front Gate, which says it has now patched the vulnerability. When WIRED contacted the company, it responded with a statement that thanked Carroll for reporting the hackable flaw and described the incident as a successful collaboration that had resulted in improvements to its security. "This was resolved within 24 hours, and we can confirm there is no evidence of exploitation, ticket impact, or compromise of customer information,” the statement reads. “The issue was identified by a responsible security researcher who used AI-assisted tools to bypass standard firewall security controls and access an internal API used by entry scanners at festival venues—not a consumer-facing system or public login portal.” Even now that the flaw is fixed, though, the incident demonstrates just how broadly AI may be able to dig up hackable bugs in every facet of the internet. Carroll—who is part of Anthropic’s Cyber Verification Program, which allows approved security researchers to use its tools for certain hacking functions—says he was taken aback by how easily Claude came up with key elements of his technique for breaking into the Front Gate site. “I think there's a very good chance it could have found this exploit end-to-end without me doing anything at all,” Carroll says. When WIRED reached out to Anthropic, the company responded in a statement that it “created our Cyber Verification Program to make advanced security capabilities available to defenders so they can conduct exactly this sort of research that helps make the world’s code safer.” It added that if Carroll had not been part of the program, his use of Claude to hack Front Gate’s systems would have been detected and blocked. In its response to WIRED, Front Gate’s spokesperson argued that the company’s security safeguards limited the exposure of personal information, that the fraudulent issuing of tickets would have left an audit trail, and that tickets issued by a hacker would have been detected and canceled before they could be used. Carroll counters that those claims are uncertain at best. He says he successfully gained super-administrator privileges on the company’s platform without any discernible response from the company, and did in fact access the site via a public-facing login portal. Carroll also notes that Front Gate doesn’t claim to have evidence the vulnerability wasn’t previously exploited. What’s more, Front Gate confirmed Carroll’s findings after he shared a draft of a blog post about his discovery with the company, prior to WIRED reaching out to Front Gate. In its response to Carroll at the time, the company didn’t dispute that he was able to generate tickets at will. Carroll says he first became aware of Front Gate a couple of months ago, when he was considering attending Electric Daisy Carnival, a giant electronic dance music festival in his hometown of Las Vegas. He saw that the festival’s ticketing was run by Front Gate and was intrigued to see when he checked other festivals’ websites that the same company ran ticketing for practically every major US music festival other than Coachella. “This is like Ticketmaster but for music festivals,” he remembers thinking. “They have the monopoly, essentially.” As a security researcher who specializes in finding web vulnerabilities, he decided to poke around Front Gate’s web domain for bugs. He quickly found what looked like a SQL injection vulnerability—a common flaw that allows a hacker to input commands into a text field on a website, causing them to run on the site’s backend and sometimes send back data stored there in a database. But a web application firewall on the site appeared to be blocking him from exploiting it. So he asked Claude Opus 4.7, the most advanced AI model Anthropic made available to the general public at the time, to find a way to exploit the flaw. It immediately coded a hacking technique that bypassed the firewall. “It was the first time, really, that I had a vulnerability that I didn't fully understand,” says Carroll. “I had to go back and read what Claude had written to understand the bypass, because I didn't write it. Claude did it completely by itself.” Claude had, in fact, found that a “nested SQL query”—a SQL query inside of another SQL query—could evade the firewall’s detection. Soon the AI tool had written a script that displayed samples from a table of 500 databases of exposed customer information. In total, Carroll believes that the vulnerability he and Claude found would have provided access to the information of millions of customers, including names, emails, and mailing addresses—but not credit card details—as well as that of Front Gate’s staff. With access to staff data, Carroll quickly found that he could also take over staff accounts. He searched for a super administrator’s account, clicked the option to reset its password, and was able to find the reset code that the site had sent to the administrator’s email stored in the site’s backend. He then used it to confirm the reset, setting a new password and taking over the administrator’s account. Soon he was looking at the most expensive tickets he could find for Bonnaroo and adding them as comp tickets to a kind of shopping cart. “It seems like you could do that for every single event that you wanted to,” Carroll says. (He didn’t actually complete an order and issue any tickets for fear of crossing a line and being charged with fraud.) Carroll was surprised to see just how easy his takeover method was: No two-factor authentication prevented a leaked, stolen, or guessed password from giving someone full access. “There's just this one centralized company issuing all tickets for every single festival,” Carroll says. “And even without this vulnerability, if you knew someone's password, you could just log in without any verification and issue free tickets.” Perhaps most remarkable, Carroll says, is that Front Gate didn’t appear to have properly audited its own site for simple vulnerabilities, either with human hunters or the AI ones that seem to now make the bug-finding process scarily easy. “It just feels concerning when you think these very professional music festivals with professional websites are well-run,” says Carroll. “Then you get access, and you realize it's all held together by duct tape and prayers.”