7 ms·
Hi I'm the author, AMA Or come hang out in the party chat! Use the exploit to join: https://jlleitschuh.org/zoom_vulnerability_poc/zoompwn_iframe.html https:/
by Jlleitschuh 7y ago
Hi I'm the author, AMA
Or come hang out in the party chat!
Use the exploit to join:
https://jlleitschuh.org/zoom_vulnerability_poc/zoompwn_iframe.html https://jlleitschuh.org/zoom_vulnerability_poc/zoompwn_ifram...
- nradov 7y agoHave your checked for similar vulnerabilities in competing products such as GoToMeeting and WebEx? They have the same basic features.
- liveoneggs 7y agobluejeans video installs a nasty daemon that runs at boot too. I'll never attend a bluejeans meeting again
- longnguyen 7y agoWow didn't know that. I rarely use bluejeans but I guess i will uninstall it anyway.
- Randgalt 7y agoAnyone know what port the Bluejeans server is running on and/or how to kill it in a manner similar to the Zoom workaround?
- packetslave 7y agoBlueJeans 423 [...] TCP localhost:18171 (LISTEN) $ nc 127.0.0.1 18171 GET / HTTP/1.0 HTTP/1.1 200 OK Content-Length: 23 Server: Swifter 1.3.3 BlueJeansHelper Service
- redbeard0x0a 7y agoRemoving the BlueJeans from your machine is a little more involved because they actually used launchd. launchctl list Then you need to find where the plist files are (i.e. com.bluejeans.app.detector.plist). You can disable an entry from launchctl list: launchctl disable uid/<your user uid>/com.bluejeans.app.detector You can also unload if you find the actual file launchctl unload ~/Library/LaunchAgents/com.bluejeans.app.detector.plist There were a couple differently named bluejeans agents.
- megablast 7y agoNot if you just use it through the browser, which is more stable than their app.
- migueltarga 7y agoRingCentral Meetings uses zoom.us engine but the local server runs on port 19424 instead. I'm able to replicate the issue on it. PoC: http://localhost:19424/launch?action=join&confno=3535353535 http://localhost:19424/launch?action=join&confno=3535353535
- nuvs 7y agoI can confirm that this vulnerability exists in RingCentral for macOS, version 7.0.136380.0312. I was taken into Miguel's meeting, but since the host wasn't presented, it simply let me know it was waiting for him (It also had a friendly notice "Your video will turn ON automatically when the meeting starts". I've changed my settings in Video > Meetings, just like in Zoom, to turn off my vid when joining. Also confirmed that the server is running on port 19424 (via terminal command 'lsof -i :19424').
- thijsvandien 7y agoIn my case it's 19421 as written in the article.
- migueltarga 7y agoFor RingCentral or Zoom? Could be because I have both on my machine.
- thijsvandien 7y agoZoom
- migueltarga 7y agoYes, my comment was about RingCentral Meetings
- thijsvandien 7y agoSorry, never heard of that, and since the rest of the story was so similar, it didn't really register in my brain as something entirely different.
- tzakrajs 7y agoGreat chat, I think you were right when you said all vulnerabilities should have a video conference for Q&A after release. It was really helpful to get a better understanding of the platform and the threats facing it.
- Jlleitschuh 7y agoIf you want to see some part of this fixed, please UPVOTE this issue: https://github.com/mozilla/standards-positions/issues/143 https://github.com/mozilla/standards-positions/issues/143
- saganus 7y agoStayed on that call for over 3 hours and I just have to say that it was one of the best experiences I've had on the internet in years. People behaved pretty good considering it was a random public Zoom call (except for a few trolls, but nothing really bad). It just felt like the internet of yore where random people would meet and chat and just be nice to each other. Lots of interesting topics, people from all over the world, lots of surprised faces, random camera sights out the window, someone with a unicorn mask... It was a blast. Thank you Jonathan for a great time!
- Jlleitschuh 7y agoThanks for being cool!
- PunksATawnyFill 7y agoI didn't really participate, but yeah, it was a pretty entertaining happenstance gathering!
- vtrips 7y agoI listened for a long time, learned a lot as well. This made me think - is there any website that facilitates you to do such public conferences on zoom like clients. Basically a bunch of people who are interested in a certain topic could join and chime in - go from topic to topic. It could be a very healthy discussion. People could post and schedule meetings and essentially anyone who wants to learn could join. I do listen to podcasts often, but such meetings would be pretty different than podcasts. Does this already exist?
- saganus 7y agoI am not aware of anything like what you describe, but I did see some people in that Zoom call suggesting the creation of a Discord and/or Slack channels. However what I fear is that they will become like any other modern forum in that you will need heavy moderation, people will try to troll, etc. The beautiful thing about Jonathan's call was it's spontaneity I think, and that everyone was so excited to talk about the vulnerability that the group had a single focus. I might be too cynical so maybe it's a good idea, and if someone suggest a place/site/forum to have these kind of discussions I would definitely try it out.
- vivan 7y agoHuh, I'm on Windows and it auto-joined the meeting too, with video enabled. I wonder if this is because at some point in the past I opened a Zoom meeting and allowed Chrome to open the Zoom URI in the Zoom app?
- megous 7y agoWe need "allow only for this session" (or tab) in the permissions popup bar.
- FabHK 7y ago> You can confirm this server is present by running lsof -i :19421 in your terminal. Might be good to specify what the output would be if the vulnerability is present or not, like this: "If the server is running on your machine, you'll get a line specifying which process is listening to that port. If the command returns empty, your machine is not vulnerable."
- cconover 7y agoInterestingly, I implemented every mitigation listed in the article: kill the web server process, remove and add an empty directory at `~/.zoomus` to prevent it being re-added, remove Firefox's content type action for Zoom, and disable video turning on when Zoom launches. When I visit a Zoom join link or the POC link above, Firefox prompts me to open the Zoom client to join the meeting, and when I click "Open Link" the client opens just as it should and joins the meeting. This seems to confirm that there is no functionality to create a seamless experience for the user that actually requires the presence of the web server. If you don't have the client installed the page can prompt you to download it the same as it would the very first time you download and install it. You can ask your browser to remember the link association and not be prompted for which app the link should open going forward. These are minor steps, even for a regular user, and ones with which most users are likely already familiar. To me this further illustrates that the web server is truly just a ploy on Zoom's part to keep their hooks in users' systems, and have a way in that the user isn't privy to. Any other excuse they are giving about "enhanced experience" is dubious at best and deceitful at worst.
- kevlened 7y agoIt seems the web server "is a workaround to a change introduced in Safari 12": https://news.ycombinator.com/item?id=20389668 https://news.ycombinator.com/item?id=20389668 > You can ask your browser to remember the link association If that's true in Safari, then a web server is using dynamite to kill a fly.