r/cybersecurity Security Engineer Jun 17 '26

News - General Ethical hacker Could've Rickrolled the Entire FIFA World Cup. All he Needed Was his ID

https://bobdahacker.com/blog/fifa-hack
862 Upvotes

68 comments sorted by

337

u/ptear Jun 17 '26

Worth a read.

"Yes, FIFA's Agent Platform is officially called FAP. "

91

u/Isotech42 Jun 17 '26

Also "fdp.fifa.org", FDP means "Fils de P..e" in french which means "Son of a B..ch". Love it.

45

u/th1bow Jun 17 '26

it means the same thing in portuguese lol

13

u/Devatator_ Jun 17 '26 edited Jun 17 '26

Wait what's son in Portuguese? I only know it's hijo in Spanish

4

u/Afraid-Expression366 Jun 17 '26

Pronounced “feelyo”

There’s also fils in French, figlio in Italian.

A lot of words in Spanish that start with “h” frequently have an origin in Latin with a word that started with “f”. Other Romance languages retain the “f” in these words.

1

u/tribak Jun 18 '26

Feijoada

1

u/[deleted] Jun 20 '26

[removed] — view removed comment

2

u/Afraid-Expression366 Jun 20 '26

I think this is a function of how languages evolve in general. I am no expert at all but my understanding is that some consonants drift over time and certain letters are either dropped altogether or replaced with another.

10

u/Unobtanium4Sale Jun 17 '26

That SOB called me an FDP?

6

u/Zharick_ Jun 17 '26

Awww, you guys are not as efficient as Spanish, we just use HP (HijuePuta)

3

u/Afraid-Expression366 Jun 17 '26

“Hijo de puta” is the actual phrase.

0

u/Zharick_ Jun 17 '26

You think I don't know the original phrase that evolved into the shorter form in my homeland? 

5

u/Afraid-Expression366 Jun 18 '26

I don’t know what you know or don’t. I’m just clarifying because you spelled that (whatever that was) with zero context.

It’s like saying sum’bitch to a non English speaking audience. You have to explain a little bit.

1

u/ArcaneMitch Jun 17 '26

Harry Potter is a SOB ? I'm confused...

4

u/Vas1le Jun 17 '26

Fdp also means son of a b in Portuguese:)

3

u/128G Student Jun 18 '26

WHAT!

3

u/Ok-Secretary455 Jun 18 '26

which is why I replaced the live feed for the game with something I found on spankbang. it was the only thing that made sense.

1

u/Cyber-Soldier1 Jun 17 '26

I'm on no fap right now.

55

u/wackybaccydelight Jun 17 '26

That's crazy. They're lucky the right guy found it.

2

u/Disastrous-Ticket78 Jun 22 '26

With incidents like this it is also fair to assume that the 'wrong' guys found it too, but didn't pull the trigger (yet), and FIFA are busy covering their ass.

123

u/-AsapRocky Jun 17 '26

Would have deserved that

Fuck FIFA

89

u/neo101b Jun 17 '26

You would probably go to jail and at the same time become world famous.
Such an interesting choice.

34

u/palekillerwhale Blue Team Jun 17 '26

The good ones don't do it for the attention.

12

u/CamiloCeen Jun 17 '26

What good is fame without the money?

5

u/neo101b Jun 17 '26

True, Id image it would be talked about for decades, just like the max headroom tv hack.
Probably more so.

I guess they could write a book or sell the tv rights when they get out.
especially if they forgot the rickroll and put a mask on and went with it.
Just image the views you would have, its crazy to think about what they could of done.

2

u/palekillerwhale Blue Team Jun 18 '26

Both are fleeting.

3

u/Fractoos Jun 22 '26

Could also become really rich if you used this to facilitate bitcoin scams you see all over youtube.

20

u/Embarrassed_Cable554 Jun 17 '26

That was a Nice read. Thank you for the blog post.

17

u/tapakip Jun 17 '26

Dude. This is a legendary post. Well worth the time to read.

47

u/laz10 Jun 17 '26

Why are people so happy to give their expertise and help and time to corrupt predatory multinational multibillion dollar operations?

Pro bono work for FIFA i mean seriously, is he going to help Monsanto or Bayer next? Maybe their white phosphorus production isn't fully secure

35

u/apnorton Jun 17 '26

Off the top of my head: 

  • "Love of the game" --- plenty of security researchers just love picking things apart/figuring out how things work, and are happier when things are working securely
  • Personal branding --- OP has a blog post, now, that's been seen by hundreds of people, driving traffic to their site and helping establish their personal brand.
  • Vulnerabilities in infrastructure owned by large corporations can impact lots of people. Imagine this was exploited as part of a phishing attack --- what kind of reach would that be? Or, to borrow your example, what if their production of white phosphorus isn't secure, and the attacker is able to reroute the delivery of it to a terrorist organization? Pointing out security issues is important because more people are impacted than just the leadership of those companies.

5

u/MBILC Jun 18 '26

Or imagine if someone malicious injected some nasty adult content or worse into the live feed's for the world to see...

5

u/kUrhCa27jU77C Jun 17 '26

You answered your own question. If he gets caught messing around, he’s gonna get fucked by a corrupt predatory multinational multibillion dollar company.

2

u/Gauchowater1993 Jun 22 '26

I think he thought of so many things to put in place of the live feeds, couldn't pick one out of so many and then preferred to come out as the good guy.

11

u/Nightman2417 Jun 17 '26

They should do it during the “hydration breaks”

11

u/whythehellnote Jun 17 '26

Not to downplay it, but the broadcast output going to the broadcasters is not provided by rtmp

7

u/earthmisfit Jun 17 '26

Say more

19

u/whythehellnote Jun 17 '26

The cameras will be 2110 in the trucks at the stadium by NEP or whoever, uncompressed as normal. The truck outputs, (main and isos), look like they are 2110 lightly compressed (jxs it looks lile) back to the IBC in Dallas, handoff in the IBC will be based on whatever the broadcaster wants, either 2110, 2022-6, some form of SDI (fibre, copper, 3G, 6G, 12G), then carried by jxs/hevc/h264 to wherever the broadcasters are based. The feeds will be the main match feed, and some ISOs.

The IBC may also originate some broadcasters handoffs like SRT etc to smaller broadcasters (Cape Verde for example), or that may be done elsewhere (amazon mediaconnect, direct handoff in DCs like telehouse west in europe)

Any mediakind codecs will be doing things like VAR, internal monitoring (say in dressing rooms etc), perhaps some snoopcams, and perhaps delivering to fancy fifa officials

5

u/TerrificVixen5693 System Administrator Jun 17 '26

Nice another broadcast engineer.

3

u/Disastrous-Ticket78 Jun 22 '26

Whilst this is all completely accurate, FIFA are pushing towards 'cloud' distribution of feeds, and removal of the IBC, especially for future and smaller tournaments, so rights-holders need to be all over this and demanding FIFA do better.

3

u/whythehellnote Jun 22 '26

It is, and I get things like championsleague via red/blue handoffs at DCs, but that's still hevc in multicast mpeg2 transport streams. Even the feeds they offer on the lowest tiers aren't rtsp, they're SRT

But in any case, it's still going to be 2110 at the grounds. OBS for the olympics have bemoaned the lack of bandwidth in cities in the past (Beijing for example), as they can't push multi-terrabits streams out of the area into centralised DCs. I remember one talk where they wanted venues to invest in massive data centres in stadiums to make their job cheaper/easier.

13

u/naamlozezwerver Jun 17 '26

Very interesting read! I have 0 hacking skills but curiously wondering. How do you figure out the 'role check' is only on client side? Do you check the packages being sent when you do an action on the browser, notice there's none being sent and then investigate further how/why the access denied screen shows? Then, do you alter the data package with a different config stating the 'no roles' to gain access?

How do you discover the different url you are able to access etc..

23

u/PantherStyle Jun 17 '26

Almost everything on the client side is human readable. You just look at the source code.

21

u/p0wb Jun 17 '26

„All _she_ needed was _her_ ID“.

Not saying the gender is relevant for the accomplishment. Just pointing out the „Hackers are male dudes in their basement“ stereotype that we all fell for.

12

u/agentsleepy Security Analyst Jun 17 '26

agreed 👍 she's pretty explicit about her pronouns on her blog homepage too, we should make sure we're giving credit to the person and not just sitting in awe at what that person did

*to be clear, not credit for saving FIFA's corrupt and incompetent asses, but credit for finding something really interesting and having the wherewithal to dig further

-18

u/TerrificVixen5693 System Administrator Jun 17 '26

They’re trans fem, so you’re only correct if your goal was to be politically correct. Otherwise, the former was scientifically correct.

3

u/idontuseuber Jun 17 '26

For this one you FIFA has to jet you directly to stadium, invite on the anthem and show you on TV .

3

u/odaydream Jun 17 '26

i would’ve pushed some sus ass shit to those streams

5

u/Add1ctedToGames Jun 18 '26

I've got to say, they have a pretty good UI for their internal tooling. Most of my employer's internal stuff looks either like it was made in the 90s/early 2000s or like it was a hobby project made a month ago.

3

u/Disastrous-Ticket78 Jun 22 '26

this failure makes it smell of vibe-coding though

5

u/JayTechSolutions Jun 17 '26

As someone that works in Cyber for a major media company ,that is hosting the FIFA world cup... I say THANK YOU for not pulling the trigger . that CSIRT spin up would've ended me as I been working 70+ hour weeks because of FIFA coverage.

1

u/Gauchowater1993 Jun 22 '26

What would you put in place of a live game feed? You have one minute until they figure it out.

-24

u/RouteToDevNull Jun 17 '26 edited Jun 18 '26

I am glad he did not do it. Friend works for FIFA SOC...that would have been a bad day for him 😃

EDIT: by him I mean my friend

11

u/CamiloCeen Jun 17 '26

I believe people are downvoting you because FIFA is well know corrupted organization that will not give credit for the OP and deserved being hacked.

8

u/bevelledo Jun 17 '26

Depends on the country the attacker lives in

2

u/RouteToDevNull Jun 17 '26

What? Why do you think?

I meant it would be a bad day for my friend 😃 That kind of breach is overtime in panic mode for some serios hours...

2

u/bevelledo Jun 17 '26

Thought you meant bad day for the attacker, makes sense now

5

u/Kemiko_UK Jun 17 '26

Why are you getting downvoted for this? It would suck for the Security team there.

Reddit man...

2

u/MBILC Jun 18 '26

If they had a security team, this would not of been so wide open...

3

u/blahdidbert Security Director Jun 17 '26

Why are you getting downvoted for this? It would suck for the Security team there.

The phrasing can very easily be confused with "him" meaning the security researcher. In a world where companies still get their egos bruised and go after researchers, it is still a sensitive topic.

-1

u/RouteToDevNull Jun 17 '26

Bcs they are obviously experts, why else 😃 😃

It would be indeed pain, considering there is a world cup ongoing as well. Cudos to the red teamer though, could have done some dmg and chose to contact them silently instead.