By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: American Archive of Public Broadcasting fixes bug exposing restricted media
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > American Archive of Public Broadcasting fixes bug exposing restricted media
Tech News

American Archive of Public Broadcasting fixes bug exposing restricted media

By admin 4 Min Read
Share
SHARE

​A vulnerability in the American Archive of Public Broadcasting’s website allowed downloading of protected and private media for years, with the flaw quietly patched this month.

BleepingComputer was tipped about the flaw by a cybersecurity researcher who asked to remain anonymous, stating that the flaw has been exploited since at least 2021, even after the researcher previously reported it to the organization.

After contacting AAPB about the flaw, a spokesperson confirmed the issue, and the researcher validated that the fix was implemented within 48 hours.

“We’re committed to protecting and preserving the archival material in the AAPB and have strengthened security for the archive,” stated AAPB’s Communications Manager, Emily Balk, to BleepingComputer.

“We look forward to continuing to make public media history free and accessible to the public.”

The American Archive, operated by WGBH Educational Foundation (GBH) and the Library of Congress, is a public nonprofit archive whose mission is to collect, digitize, and preserve historically significant content produced by public radio and television in the United States.

BleepingComputer was told that the AAPB vulnerability first circulated as a rumor in online discussions about the leak of the Sesame Street “Wicked Witch of the West” episode on the Lost Media Wiki Discord channel.

Lost Media Wiki took down the episode, saying that it was “likely obtained in an illegal data breach,” urging members to refrain from re-sharing it on its Discord channel.

Initially secret, the exploit method began circulating in Discord preservation groups by mid-2024, leading to further leaks of protected content on Discord servers focused on content preservation.

Known as data hoarders, these communities dedicate themselves to archiving software, websites, operating systems, and various forms of media, including TV shows, music, and movies. However, they often operate in a gray area, where copyrighted content is preserved and shared, blurring the line with digital piracy.

Even with AAPB’s takedown efforts, the exploit continued to circulate on various Discord servers and messaging apps, with a proof-of-concept shared with BleepingComputer showing just how easy it was to abuse.

The exploit shared with BleepingComputer is a simple Tampermonkey script that exploits an insecure direct object reference (IDOR) flaw, allowing users to request media files by ID and bypass AAPB’s access controls.

The bug enabled users to change the media ID parameter in media access requests, allowing them to access resources by the ID, even if they were protected or private.

Although the main /media/{ID} pages had some access controls, attackers could bypass them by tampering with fetch or XMLHttpRequest calls made in the background.

Instead of AAPB’s server rejecting those requests with a ‘403 Forbidden’ error, as long as the request had a valid media ID, the content was served.

While the vulnerability has now been fixed, it is not known how much content was accessed and shared within the data hoarder community.

The leak of content at American Archive followed another incident earlier this year, where PBS employee contact information was leaked and spread through Discord servers for fans of ‘PBS Kids.’

Both incidents illustrate how archival and fan communities can gain access to sensitive or private data, even when it’s not used for malicious purposes.

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

You Might Also Like

In 2026, what medtech skills will empower you to face the future head on?

Google Fitbit Air Deal Includes Free Active Band

Tesla Reveals New Details About Robotaxi Crashes—and the Humans Involved

cPanel, WHM emergency update fixes critical auth bypass bug

How horology developed through the ages

TAGGED: American Archive, Discord, Piracy, video, Vulnerability, Web Application, Website
Share This Article
Facebook Twitter Copy Link
Previous Article Levante vs Real Madrid Bet Builder Tips – 9/1 La Liga Special, Analysis & Predictions
Next Article Save $36 on a Cool, Compact Hall Effect Keyboard
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Kylie Jenner Before & After Plastic Surgery: Photos With Lip Fillers & More
Celebrity
Ghost of Yōtei: Legends’ Raid is the “Last Major Planned Update,” Says Sucker Punch
Gaming News
How to Find Flight Deals Using Google Flights and Wikipedia
Travel
Japan earthquake triggers tsunami warnings as coastal evacuations begin
World News
In 2026, what medtech skills will empower you to face the future head on?
Tech News
Shipping industry fears fuel shortages that could drive up prices worldwide
Business
America’s productivity boom started before AI, and a Stanford economist who decoded the Great Resignation says working from home is the reason why
Business

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Investing £5 a day could help me build a second income of £329 a month!

Brussels unveils plans for a European Degree but struggles to explain why

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
Trump evokes more anger and fear from Democrats than Biden does from Republicans, AP-NORC poll shows
March 28, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?