Bug in FIFA World Cup internal system gave anyone ability to modify TV stream


A security researcher said she was able to access several internal FIFA platforms due to a simple security flaw, which allowed her to watch and have full control of the TV stream of every World Cup game. 

The researcher, who goes by BobDaHacker, said she simply registered as a player agent on FIFA’s official agent registration platform. Then, thanks to having that account and a flaw in FIFA’s back-end API, which didn’t check if a user actually had the proper authorization, she was able to access several internal FIFA platforms. 

This included the system that allows broadcasters to control what gets displayed on people’s TVs across the world, and what gets displayed on commentators’ screens as they narrate the match, per the researcher.

“A single attacker could hijack every camera simultaneously. An attacker could have rickrolled the entire FIFA World Cup,” BobDaHacker wrote in a blog post published on Tuesday. 

BobDaHacker reported the flaw on Tuesday night Japan time, and FIFA fixed the issue a few hours later, without ever acknowledging the researcher’s report. 

FIFA did not immediately respond to TechCrunch’s request for comment.



Source link

  • Related Posts

    Smart Glasses Are Capturing Footage in Public. Here’s How to Spot Them

    New smart glasses are debuting this week at Augmented World Expo. There’s a lot of powerful technology packed into upcoming devices like Snap Specs and XReal Aura, which aren’t much thicker than a…

    Apple 2027 rumors: AirPods with cameras for AI and the second folding iPhone

    Now that we’re clear of WWDC and all of the new AI-powered features coming to Apple’s platforms, Bloomberg reporter Mark Gurman has more details about rumored new hardware, like the…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    Smart Glasses Are Capturing Footage in Public. Here’s How to Spot Them

    Smart Glasses Are Capturing Footage in Public. Here’s How to Spot Them

    Can a Trump-Modi Meeting Reset U.S.-India Relations?

    Can a Trump-Modi Meeting Reset U.S.-India Relations?

    EU lawmakers to approve tougher migration rules, including deportation centres

    Less than a month after launch, the entire Luna Abyss team has been laid off

    Less than a month after launch, the entire Luna Abyss team has been laid off

    From Hailey Bieber to Charli XCX, It Girls Everywhere Are Ditching Pastels for Summerween Manis

    From Hailey Bieber to Charli XCX, It Girls Everywhere Are Ditching Pastels for Summerween Manis

    Mbappé y Haaland se llevan los reflectores tras sendos dobletes

    Mbappé y Haaland se llevan los reflectores tras sendos dobletes