AUTO-UPDATED

Rickrolling the World Cup

Security researcher bobdahacker discovered a critical vulnerability in FIFA’s digital infrastructure that could have allowed unauthorized individuals to hijack live match broadcasts and manipulate sensitive tournament data.

Key Points

  • The researcher gained access to the FIFA Football Data Platform by exploiting a misconfigured Microsoft Entra account system.
  • The flaw allowed potential control over RTMP ingest URLs, which serve as the primary broadcast feed for live World Cup matches.
  • Exposed systems included administrative dashboards, player bios, match scores, and the FIFA AI Pro analysis tool.
  • The researcher bypassed client-side access restrictions that failed to verify user roles on the server side.
  • Instead of exploiting the access, the researcher reported the security gaps to FIFA, their streaming contractors, and law enforcement.

Why it Matters

This incident highlights the severe risks associated with centralized authentication systems when internal access controls are not properly enforced on the server side. The vulnerability demonstrates how a single configuration error in a global organization can jeopardize the integrity of high-profile international broadcasts and sensitive sporting data.
Hackaday Published by Navarre Bartz
Read original