---
title: "I could’ve rickrolled the entire FIFA World Cup. All I needed was my ID."
id: "42261"
slug: "i-couldve-rickrolled-the-entire-fifa-world-cup-all-i-needed-was-my-id"
permalink: "https://eay.cc/2026/i-couldve-rickrolled-the-entire-fifa-world-cup-all-i-needed-was-my-id/"
published_at: "2026-06-22T08:55:44+00:00"
author: "Stefan Grund"
type: "post"
format: "link"
tags:
  - "fifa"
  - "fifa worldcup"
  - "hack"
  - "netzkultur"
  - "sicherheit"
  - "wm 2026"
external_url: "https://bobdahacker.com/blog/fifa-hack"
short_url: "https://eay.li/439"
content_copy:
  - "https://bsky.app/profile/eay.social/post/3moujftdmoq2p"
  - "https://eay.social/@eay/116792921080758542"
geo_latitude: "50.973926"
geo_longitude: "6.68292"
---

# I could’ve rickrolled the entire FIFA World Cup. All I needed was my ID.

[Link →](https://bobdahacker.com/blog/fifa-hack)

BobDaHacker hat sich mit seinem Personalausweis als Agent bei der FIFA angemeldet, um dann festzustellen, dass jegliche Authentifizierung für diverse FIFA-Systeme nur Client-seitig geprüft wurde, nicht auf dem jeweiligen Server. Wodurch er sich problemlos Zugang zur Livestream-Verwaltung verschaffen konnte. Er hätte dadurch jeden Stream manipulieren können und z.B. Millionen Zuschauer weltweit rickrollen oder beim Finale mit [Subway Surfers](https://en.wikipedia.org/wiki/Subway_Surfers)-Gameplay trollen können, wie er selbst schreibt.

Die Sicherheitslücke zu melden, war dann wohl gar nicht so einfach. Erst als er sich an US-Behörden wandte, ging es weiter. Die FIFA selbst hat sich bis heute nicht gemeldet – oder bedankt.
