FCC Closes Virus Upload Loophole On Its Website

Hands typing on a keyboardImage copyright Getty Images
Image caption The FCC is taking steps to improve the security of its website after internet users spotted a serious vulnerability

The Federal Communications Commission (FCC) has taken steps to secure its website after users discovered they could upload malware to it.

On Thursday, security researchers discovered a function connected to the US government agency website's comment system that let them upload files.

The site allowed anyone to sign up to obtain a software key that let them upload the files they wanted.

The FCC said there was no evidence malware had actually been uploaded.

"The FCC comment system is designed to maximise inclusiveness and part of that system allows anyone to upload a document as a public comment, which is what happened in this case," the FCC told the BBC.

"The Commission has had procedures in place to prevent malware from being uploaded to the comment system. And the FCC is running additional scans and taking additional steps with its cloud partners to make sure no known malware has been uploaded to the comment system."

At the time of writing it is no longer possible to upload files in this manner, the communications watchdog said.

In plain sight

The bug emerged in what is known as application programming interface (API) available via the FCC site.

APIs are a well established technology and let developers interact via the web with the data that organisations hold and the services they offer.

While the comment system was easy for members of the public to use and upload files to when making complaints to the watchdog, the API was not meant to be publicly accessible.

However, anyone who knew where to find the API on the FCC's website could request access to it. Documentation explaining how to upload documents was also publicly available on the site.

Security researchers experimented with the API, filling in forms to request access to keys that let them use it via email.

When they received the key, the users were surprised to find that they were able to upload any file type they liked to the website, whether the files were documents, music files or executable code.

The programmers claimed they were able to upload files as big as 25MB in size, Guise Bule, the editor of Contratastic magazine wrote on website Medium.

RECENT NEWS

Google Leverages AI To Automatically Lock Phones During Theft

Amid increasing incidents of mobile phone thefts, Google has launched an AI-based feature that automatically locks the s... Read more

Microsofts Emissions Surge Nearly 30% Amid AI Demand Growth

Microsoft has reported a nearly 30% increase in its emissions from 2020 to 2023, underscoring the challenges the tech gi... Read more

Impact Of AWS Leadership Change On The Global AI Race

The recent leadership transition at Amazon Web Services (AWS), with Adam Selipsky stepping down and Matt Garman taking t... Read more

The Global Impact Of App Stores On Technology And Economy

Since Apple launched its App Store in 2008, app stores have become a central feature of the digital landscape, reshaping... Read more

Alibaba's Cloud Investment Strategy: Fuelling AI Innovation And Growth

Alibaba Group's cloud business, Alibaba Cloud, has emerged as a powerhouse in the tech industry, spearheading innovation... Read more

Elon Musk Takes On Government 'Censorship': A Clash Of Titans In The Digital Arena

Elon Musk's recent endeavors to challenge government-led content takedowns mark a significant development in the ongoing... Read more