

Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- > Client says "access denied"
> Server says "here's everything"
hahahaha
> Hire me (just kidding... unless?)
FIFA is a legendarily awful organization. In my weaker moments reading your piece I thought to myself how nice it would have been if someone more ruthless than you had been made an example of them.
by rectang - To be fair FIFA is one of the best international federations in terms of good governance. Dutch sport think-tank Play The Game has an assestment methodology and the project called "Sports Governance Observer" and did asses FIFA in 2018 [1]
FIFA gets disproportionate amount of attention and, ofc, high-level corruption scandals, but I would say it's more like a by-product of the sheer scale of the football, and not a problem with FIFA itself. I believe most sports federations in the world are very far from FIFA in terms of governance, but also from facing problems that FIFA has.
[1] https://www.playthegame.org/publications/sports-governance-o...
by divan - Right before contacting FBI I would start Subway Surfers stream. Fuc** Driven Development it still the only way for big orgs, this is the only way as we can see...by misiek08
- You hit the jackpot on security research, but you cannot take like an hour or two to at least get rid of the AI smell? Please do use AI, nothing against that, all I'm saying is please, please don't deliver this weirdness:
> I did not touch any of these controls. But they were there. Functional.
I really needed to push myself to read because it was very interesting and thank you, for doing the work and sharing.
by patates - How could that possibly, ever have made it through. Every single API for every single service didn't check the JWT?by mjfisher
- Vibe coding? Just have LLM make it and then press merge?by Ekaros
- It started as internal service where you need to be connected with a VPN so why bother with security.by maciekkmrk
- This happens more often than you would think.
During COVID, lots of live shows (concerts, etc.) in Japan moved to streaming (and most of them stuck, so thanks to that, lots of large concerts today have real-time streaming, which is great for foreign fans).
Out of 10+ platforms, more than half have vulnerabilities that allow you to access the content freely (sometimes including the rehearsals, because they are also streamed internally), and on a handful, you can access the admin panel and, as the author said, stream whatever you want.
Most of them have been patched over the years (some are just the byproduct of them changing the backend/SaaS provider, though), but there remain some major providers where you can get content for free.
by thrdbndndn - Do you know these feeds actually go to broadcasters? They could be internal feeds for refs, match review, head office monitoring, etc.
The broadcast contribution feeds I’ve seen in the past are MPEG-TS, not via RTMP.
Still a great find.
by anthonyeden - you're right, it's not the international signals, but internal distribution onlyby srfwx
- Awesome read! Congratulations on discovering this and reporting. Hope you get something back from FIFA. This could've lead to some huge disaster if it failed under the wrong hands.
Love your writing skills as well!
> I closed it immediately. But the damage was done (to my brain).
Laughed so hard when I read this one :D
by arecsu - It was a cool story, no doubt.
> Love your writing skills as well!
I‘d say it was heavily AI assisted
by Tepix - I don't understand why people obsess over LLM(AI)format. The content is interesting, but they dismiss it just because the format is an issue. All of this content is worth reading and is good. And it's about security.by jdw64
- The content is rendered unreadable by the LLMs sentence construction. Secondly, it's insulting. If you didn't care enough to write it, why should I care enough to read it?by willdr
- It's really annoying. Honestly I'm impressed how quickly one becomes able to smell it after seeing enough of it, I feel like a year or two ago everyone thought LLM bots would be forever indistinguishable from real users (and in fairness, the well-managed ones probably are).
No hate on the author, but LLMs just have such an annoying and overdramatic way of phrasing things. The content is worth reading, I enjoyed it! It would just be even better if it hadn't been turned into such a slog to read through.
by ipdashc - Clearly a big f-up by FIFA on what looks like quite a tidy platform otherwise.
One question though, how do you know your feed would kick off the 'real' feed if you pushed to RTMP, does it just take the most recent connection as live? Does the protocol have a mechanism for dealing with multiple people pushing to the same endpoint? There maybe more checking on that endpoint and if course I'm sure most live broadcasters would have a live director to cut any feeds at their end if a dodgy feed popped up too.
A huge vulnerability nonetheless and a great write up!
by srmarm - Good question! So RTMP doesn't really have a clean way to handle two publishers on the same stream key. What would actually happen is the two streams fighting for the ingest endpoint, so the output would glitch between the two sources. Like if I pushed Subway Surfers gameplay it'd be flickering between the actual match and Subway Surfers with the audio cutting back and forth. You're right that a live director would catch it pretty fast but even a few seconds of that on air during a World Cup match is not great.by BobDaHacker
- I'll write a full article in a year or two, but here's the short version: some weeks ago, as I was looking for job offers, I found one that was interesting. As I didn't knew the company, I wanted to do my due diligence and check them out. I open the website and find a ClickFix (the "prove you're not a bot" type) attack on their main page.
I spent over 2 hours and a small (but bigger than 0) amount of my own money to report the issue by emailing and even trying to call them (they didn't have any dedicated responsible disclosure page or contact). After some time, they finally answered my emails, took down the website and "fixed" the issue.
When I finally applied for the role, got ghosted for a week and only after I wrote them again, asking for an update, I got rejected as they allegedly were looking for someone more junior - though the job title was explicitly "Senior XXX Lead".
Some years ago, I went to interview (in person) at a big European financial institution. As I got there around lunchtime, I happened to get to the front door at the same time as some employees were returning from lunch who, very kindly, held the door open for me.
I was in their office around their computers, unsupervised and unaccompanied, for 10-15 minutes, enough time to plant some O.MG USB-C cables.
During the interview, I had a chance to talk to the CTO and told them what happened and how I was allowed access in the office, and immediately saw his face change and quickly change topic, and end the interview.
Unsurprisingly, I didn't get the job - I should have probably kept my mouth shut.
by tagyro - Really amusing to read this one. I did something similar for Qatar 2022 and got access to roster submission (https://zachholman.com/posts/hacking-fifa). To their credit they patched it pretty quickly, but their promised "token of appreciation" never came. (Although on the other hand, they didn't sue me, so I guess that's a win.)by holman
- Please stop using AI to write for you, it ruins what is otherwise a fascinating story, and on reflection I struggle to trust it.
If you used AI to generate the blog post, did you use AI to generate the screenshots and story?
- I got 100% Human on Pangram, so either they did the work to have their AI service pass this test, or...they actually wrote it.by nunez
- Yeah I used Claude as a writing assistant for the initial draft. I'm autistic and long-form writing isn't my strong suit, getting a 4000 word blog post to flow well is genuinely hard for me. But I do edit it pretty heavily after, the voice and the jokes and the structure are mine, the AI just helps me get a baseline down so I'm not staring at a blank page. The research, the screenshots, the disclosure, that's all me. I've been doing this stuff for years.by BobDaHacker
- I don't mind it here at all, in fact I didn't even notice it's AI before reading this comment. It's clearly not a one-shot AI slop but a well thought out and edited by a human post.
Not everyone who has something interesting to say is a good writer, and I think it's great if AI can help them tell their stories.
by srdjanr - I remember a frontpage post from like 2 days ago:
"If you want human attention show human effort" or something in that direction. I think this fits here just right.
by sevenzero - I am curious, what exactly triggers your AI senses in this post?by V__
- Unfortunate to see AI police as top comment on a good amusing post!by robeym
- Agreed. The post looks great. The story is great but the AI style in this case does distract.
I'm not against using AI for writing at all but you want to be careful that the output doesn't contain too much of this noise over signal type of wording that repeats and wants to just sell you something.
by alexhans