Slashdot Mirror


The FCC Website Lets You Upload Malware Using Its Own Public API Key (hackernoon.com)

The FCC lets you upload any file to their website and make that file publicly accessible using the FCC.gov domain. Or rather they don't, but they have somehow not realized that they are letting people do it and telling them how in their own documentation. From a report: Take a look at this document about FCC Chairman Ajit Pai which has clearly not been put there by anyone who works at the FCC, neither has this one. Those currently uploading files are able to do this using the FCC's own public API, a key that they seem to send to anyone with any email address. Obviously I am not going to tell you how, but if you have enough of the right kind of technical experience the public FCC API documentation will. People seem to be experimenting uploading different filetypes, so far they have managed pdf/gif/ELF/exe/mp4 files up to 25MB in size, which means that you could easily host malware on the FCC.gov website right now and use it in phishing campaigns that link to malware on a .gov website.

41 comments

  1. How long before it is hosting kiddy porn by Bob+the+Super+Hamste · · Score: 3, Interesting

    How long before it is hosting kiddy porn and will the FBI raid them?

    --
    Time to offend someone
    1. Re:How long before it is hosting kiddy porn by the_skywise · · Score: 1

      That's just what they want people to do. Track the malware files back to their uploaders.

      It's a reverse honey-pot.

    2. Re:How long before it is hosting kiddy porn by Anonymous Coward · · Score: 1

      "That's just what they want people to do. Track the malware files back to their uploaders."

      Starbucks?

    3. Re:How long before it is hosting kiddy porn by Anonymous Coward · · Score: 0

      Remember Spicey's feud with Dip-n-Dots? Well, Chairman Pai hates Starbuck's. Something about "not being a real unicorn".

    4. Re:How long before it is hosting kiddy porn by Anonymous Coward · · Score: 1

      All I gotta say is: yet another evidence of Trump - Russia collusion.
      Hitler impeachment any day now. Hillary 2020!

    5. Re:How long before it is hosting kiddy porn by Anonymous Coward · · Score: 0

      You crack me up...

    6. Re:How long before it is hosting kiddy porn by Anonymous Coward · · Score: 0

      Perhaps never...
      There may be some kind of filter after upload that look for malware and other undesirable content. It is trivial to have a malware scanner embedded in the upload process. Looking for porn might be a bit harder, but perhaps modern AI can even handle that.
      The only way to know for sure is to try it. I lack source material, so I will leave that as an exercise to the reader.

    7. Re:How long before it is hosting kiddy porn by chuckugly · · Score: 1

      Two birds, with a publicly funded stone.

    8. Re:How long before it is hosting kiddy porn by R3d+M3rcury · · Score: 1

      I'm thinking it's Obama's fault.

    9. Re:How long before it is hosting kiddy porn by Anonymous Coward · · Score: 0

      What's wrong with Russia colluding with USA to become more democratic? Why does everyone see this as a bad thing?

      Hitler is dead and Hilary will never be president. I'd vote for anyone else, and did. She's corrupt to the core. At least he's corrupt towards himself rather than grabbing power for his party. Scope matters.

  2. So...Slashdot expects me... by Anonymous Coward · · Score: 3, Interesting

    to download random files of unknown origin, from a website they say can't be trusted? That is, if I am to believe the article summary.

    1. Re:So...Slashdot expects me... by Anonymous Coward · · Score: 1

      They're just PDF files, what's the worst that could happen?

    2. Re:So...Slashdot expects me... by Anonymous Coward · · Score: 0

      VirusTotal currently sees them both as clean.

      7521271363.pdf - https://www.virustotal.com/#/file/0ebe6eba267865b1aaef9d85fa62310bd9183af020ded50295c56a4b74e98a53/detection

      DOC-578d579d1f000000-A.pdf - https://www.virustotal.com/#/file/76b70ae6f0db01c721e39f4bebc00b0aa207c26a8ae5bb5543b3dae266907c4b/detection

    3. Re:So...Slashdot expects me... by Anonymous Coward · · Score: 0

      DOC-578d579d1f000000-A.pdf:

      To: The American People
      From: The Federal Communications Commission
      1-888-225-5322
      445 12th Street SW, Washington, DC 20554
      Dear American citizenry,
      We’re sorry Ajit Pai is such a filthy spineless cuck.
      Sincerely,
      The FCC

      7521271363.pdf:

      Fuck Net Neutrality. God bless America!

    4. Re: So...Slashdot expects me... by Ralgha · · Score: 2

      The first one is probably legit. It's an accurate description of Ajit Paid, and they want to apologise for how much of a tool he is.

    5. Re:So...Slashdot expects me... by Gavagai80 · · Score: 1

      If you use Adobe Reader to open the PDF, complete destruction of all life in the universe.

      --
      This space intentionally left blank
    6. Re:So...Slashdot expects me... by Anonymous Coward · · Score: 0

      Hahahahahaha awesome.

    7. Re: So...Slashdot expects me... by Anonymous Coward · · Score: 0

      The second is legit too. Get rid of inequity and receive a blessing.

    8. Re:So...Slashdot expects me... by Anonymous Coward · · Score: 0

      If you use Adobe Reader to open the PDF, complete destruction of all life in the universe.

      Some say this has already happened.

    9. Re:So...Slashdot expects me... by Anonymous Coward · · Score: 0

      I'm not clicking that.

  3. Anyone have an API key? by technoid_ · · Score: 0

    Anyone mind sharing a valid API key?

    --
    Two wrongs don't make a right, but 3 lefts do - Lew of GO magazine
    1. Re:Anyone have an API key? by Anonymous Coward · · Score: 0

      Damn you're lazy...

      Read the summary and get your own.

    2. Re:Anyone have an API key? by Anonymous Coward · · Score: 0

      https://10minutemail.com/, now you can have your own.

  4. Decision Makers by bezenek · · Score: 4, Funny

    And these are the people who are making decisions about the future of the Internet?

    --
    Omne ignotum pro magnifico.
    1. Re:Decision Makers by lactose99 · · Score: 4, Insightful

      Making decisions? Its already made, to bend over backwards for Big Business at the expense of the public

      --
      Fully licensed blockchain psychiatrist
    2. Re:Decision Makers by Anonymous Coward · · Score: 0

      No. I highly doubt that Mr. Ajit Paid or Mignon Clyburn or any of the other commissioners or their staff write web apps or web pages. That said, they should have the USDS (US Digital Service) take a look at and fix their site.

    3. Re:Decision Makers by bobbied · · Score: 1

      I hope you are not surprised by this.. The FCC has been this way for decades now.

      --
      "File to fit, pound to insert, paint to match" - Aircraft Maintenance 101
    4. Re:Decision Makers by Anonymous Coward · · Score: 0

      Don't you worry about that! Web developers and the ubiquity of outrageously poorly implemented javascript has crippled and will ultimately destroy the WWW beyond all recognition long before Big Business has any chance to successfully create and roll-out any profit model that does anything but lose money. The public is safe. Web browsers? Not so much.

    5. Re:Decision Makers by Anonymous Coward · · Score: 0

      Making decisions? Its already made, to bend over backwards for Big Business at the expense of the public

      Making decisions? Its already made, to bend over backwards for Civil Rights Extremists at the expense of the public.

      There, FTFY.

  5. the fles by mrwireless · · Score: 5, Interesting

    In case the files get removed or you use a text-only browser: The first PDF document looks like an official FCC letter and reads: Dear American citizenry, Weâ(TM)re sorry Ajit Pai is such a filthy spineless cuck. Sincerely, The FCC The second PDF is just an empty document with one line of profanity.

    1. Re:the fles by mugurel · · Score: 1

      I like how you regard the rejection of net neutrality as profanity.

    2. Re:the fles by Anonymous Coward · · Score: 0

      Your bias is showing, faggot.

      DOC-578d579d1f000000-A.pdf:

      To: The American People
      From: The Federal Communications Commission
      1-888-225-5322
      445 12th Street SW, Washington, DC 20554
      Dear American citizenry,
      We’re sorry Ajit Pai is such a filthy spineless cuck.
      Sincerely,
      The FCC

      7521271363.pdf:

      Fuck Net Neutrality. God bless America!

      If you live in America and don't like it, get the fuck out.

  6. RCE? by CODiNE · · Score: 2

    so far they have managed pdf/gif/ELF/exe/mp4

    Eh... interesting but boring. How about PHP/asp/py/pl/vbs and other server side languages?

    --
    Cwm, fjord-bank glyphs vext quiz
    1. Re:RCE? by schleimkeim · · Score: 1

      I really hope no one uses vbs as a server side language.

    2. Re:RCE? by Anonymous Coward · · Score: 0

      ASP.net can

    3. Re:RCE? by Anonymous Coward · · Score: 0

      Yup (*spits*) there's yer problem.

  7. They'll fix it with Secret Sauce by Anonymous Coward · · Score: 1

    Just as with their DDoS mitigation tactics, you can bet that they will fix this with some "commercial cloud partner" Secret Sauce. Because God knows, we can't expect the Federal Communications Commission to have in-house the technical skills to competently run a reasonably safe server that allows them to accept public comment and supporting evidence documents over The Internet.

    1. Re:They'll fix it with Secret Sauce by Anonymous Coward · · Score: 0

      This is what you get after enabling a Statist State.

      Government will continue the rape of Liberty until it becomes so small that it can be drowned in a bathtub.

  8. Corporate Agenda Comi$$ion by Anonymous Coward · · Score: 1

    I hope you are not surprised by this.. The FCC has been this way for decades now.

    Indeed, younguns should take a moment and watch Pump Up The Volume (again). Everybody knows the war is over.

  9. <Comment Subject> by easyTree · · Score: 1

    Perhaps we might see an unexpected release on their site about how they've decided to 'do the right thing (tm)' re. net neutrality ?

  10. unintended consequences by nobuddy · · Score: 1

    When they opened up the site for the auto-submit bots from Comcast and Verizon to flood their public feedback channel with ant-neutrality comments, this was a side effect.