Doom, the classic computer shooter that became a worldwide sensation in 1993, has a reputation for having versions for all kinds of devices, running on everything from an Apple Watch to a calculator. But for CCESS, a group of Brazilian hackers, the best possible place to run the game would be the website of the United States National Aeronautics and Space Administration, NASA.

In August 2018, one of the group's hackers, known as Subsolo, discovered two vulnerabilities on the space agency's website and immediately notified NASA. In a message, a CCESS member explained that the hacker had been conducting penetration tests on the site in search of bugs and technical flaws when he found two XXS vulnerabilities. This type of system flaw allows anyone who knows how to hack to enter the system and execute code inside it, making it possible to run various kinds of programs on the website.

NASA promptly fixed the first of the two vulnerabilities after CCESS contacted the agency. The second, however, was not fixed. After six months without any response from the agency, the hackers decided to play a prank on the site as a warning to the space organization.

Doom running on a NASA page

Doom running on NASA's website.

On Sunday (February 10, 2019), CCESS member Leandro Trindade took advantage of the flaw the organization had ignored and ran Doom inside the NASA OIG website. The Office of Inspector General is responsible for audits and for improving the economic efficiency of research projects dedicated to space exploration and observation. CCESS member Augusto Resende then took the joke one step further by running the arcade classic Space Invaders.

Both games remained accessible on the page until 3:09 p.m. on Tuesday (February 12), when the problem was fixed and the games could no longer be accessed. Although the hackers did it in good spirits to have a little fun, the episode makes clear how important greater investment and attention are for the security of these major websites, given the possibility that someone with malicious intentions could gain access and wreak havoc.

CCESS has a tradition of testing the digital security of major companies. The group has found flaws in websites such as that of Banco do Brasil, where one vulnerability made it possible to create fake pages on the official website. Like NASA, the bank only took action when the group exposed the flaw.