13 ms·
Zoom RCE from Pwn2Own 2021
- swiley 5y agoNo one should be installing native apps for this now that we have WebRTC.
- deleted 5y ago[deleted]
- StreamBright 5y ago>> for this What is exactly “for this”?
- jchw 5y agoI’d assume teleconferencing. And tbh, I’m not sure I disagree. WebRTC has some issues and certainly isn’t the greatest, but it feels like every teleconferencing solution goes through basically the same problems over and over again. I know some swear up and down that Zoom is better than any WebRTC solution and I am going to have to hard disagree, it has a larger featureset than say, Google Meet, but I don’t know anyone in my current org that isn’t disappointed in Zoom’s reliability or security issues. In my case the security issues I’ve personally heard of are less serious (mostly random people somehow getting into meetings — never witnessed that with Meet or anything else for that matter) but to be honest, I have zero trust in Zoom. If I could run it with less privileges than a browser tab I would. I’d really prefer a world where people don’t have to deeply distrust software, but still adhere to principle of least privilege where it is reasonable to do so. I feel like if I have to install software natively, it better be software with a decent track record from a trustworthy team. However we’re really at a worst of both worlds situation with Zoom. I don’t trust it at all, and it gets a ton of privileges that are only checked in the sense that there might be some scrutiny from researchers. Not saying I never had issues with the WebRTC solutions, but honestly, at worst I just found myself refreshing the tab and going on my way. Meanwhile I’ve been warned against even trying Zoom for Linux as apparently it makes the old Skype for Linux look like a solid product.
- wilde 5y agoWebRTC has had plenty of implementation issues. https://googleprojectzero.blogspot.com/2020/08/exploiting-android-messengers-part-3.html https://googleprojectzero.blogspot.com/2020/08/exploiting-an...
- supervisual 5y agoThere's a difference between Android native bugs and forgoing protection provided by browser on desktop instead of relying on Native apps.
- wilde 5y agoThe browser is also a native app. https://googleprojectzero.blogspot.com/2018/12/adventures-in-video-conferencing-part-1.html https://googleprojectzero.blogspot.com/2018/12/adventures-in...
- hdjjhhvvhga 5y agoDefine "this". The web app has less features[0] and you might be forced by your employer to use a feature that doesn't exist in the web version. [0] https://support.zoom.us/hc/en-us/articles/360027397692-Desktop-client-mobile-app-web-client-and-PWA-comparison https://support.zoom.us/hc/en-us/articles/360027397692-Deskt...
- wichert 5y agoWebRTC still requires you to implement your own signalling layer, which is where most of these problems occur. Using XMPP for signalling in combination with WebRTC is very common.
- lima 5y agoUnfortunately, Zoom deliberately cripples their web app to the point of being unusable. If your employer uses Zoom, there's no way to avoid the native app.
- wereHamster 5y agolol we use Zoom for most of our meetings and I always used the web app, without any issues.
- meibo 5y agoSitting in a meeting and saying a few words is like 10% of what Zoom can do - there's webinars, breakout rooms, Q&A, polls, moderation, and a lot of other smaller features which are incomplete or unavailable on the web client.
- brundolf 5y agoThat’s why I keep it quarantined to my work computer. If friends/family want to use it, I use it on there.
- dijit 5y agoOne company has piss poor security; but there have been hundreds of native apps doing teleconferencing before, which were native. Nothing to do with native or not; and pushing everything to a web-browser makes a really complicated bit of software with weird quirks and potential hidden bugs. Yes it’s more tested, but when your code paths are literally infinite- “more eyes” isn’t going to help.
- skrebbel 5y agoTo be frank, if Zoom was a web only app (or maybe web plus web-in-a-electron like eg Slack and WhatsApp) there'd be a vocal HN crowd complaining that there was no proper native app.
- koolba 5y agoLast I checked you didn’t have to install anything. I’m not sure about more advanced usage like screen sharing or how many timing options their are, but for generic “see me, see you” it works fine in the browser.
- brundolf 5y agoIt does have a web app, but they make it incredibly hard to find. I’m not surprised that some don’t even know about it
- koolba 5y agoIndeed, IIRC, you need to click “download”, reject the download, and then an “Open in your browser” dialog appears.
- OJFord 5y agoIME, my video always shows as either blank white, or psychedelic light show. Android app works.
- edoceo 5y agoThere was a setting they had, so the Bowser option is shown right away (well, after the xdg-open prompt)
- Geezus_42 5y agoI can confirm that the in browser version does not allow for remote desktop. I use zoom in a support role because webex is a laggy dumpster fire.
- 5y ago
- cle 5y agoSo browser sandboxing? Is that fundamentally different from native sandboxes like snap, flatpak, et al?
- watermelon0 5y agoBrowser sandboxing is more battle tested, and probably a lot more researched, and with more fuzzing performed on it. I know that at least X11 is not sandboxed with snap/flatpak/etc., and there is no sandbox for macOS/Windows Zoom client, so using web client is infinitely more isolated.
- staticassertion 5y agoBrowser vendors push sandboxing technology and everything else kinda follows behind by years. It's unlikely you'll find a more powerful sandboxing approach than what's in Chrome.
- Wowfunhappy 5y agoAll of the apps that use WebRTC seem to have worse quality and latency than Zoom. Including the semi-hidden web version of Zoom. This could just be a coincidence, but I suspect it's not. For all of its faults, Zoom calls are just much better than all of the other mainstream solutions I've tried, particularly with large groups.
- fancy_pantser 5y agoThere's a YC company that tries to make starting and scaling WebRTC super easy, which is far from trivial for a variety of clients/browsers or with 5+ participants simultaneously: https://www.daily.co https://www.daily.co
- shp0ngle 5y agoZoom is much faster, especially on older PCs, than Teams or (especially) Google Meet, because it’s native pick your poison
- sriram_sun 5y agoFTA: "Using a combination of proxies, modified DNS records, sslsplit and a new CA certificate installed in Windows, we were able to inspect all traffic, including HTTP and XMPP, in our test environment." I have setup wireshark for troubleshooting. That's about it. What's the role of proxies, modified DNS records etc. in this setup? How can I duplicate this? Thanks.
- xnyhps 5y agoThe HTTP and XMPP traffic is encrypted using TLS. The proxies were used to decrypt, log and re-encrypt this traffic in real-time.
- jraph 5y agoAnd the new certificate and DNS records are to make the proxy look legit to the Zoom client, which would otherwise not accept TLS connections. Especially if there are DNS records which specify which CA is used for the certificate.
- tialaramex 5y ago> Especially if there are DNS records which specify which CA is used for the certificate. If you're thinking of CAA, those records are not for anybody except the CAs. They're an indication to the CA "You may/ may not issue for these names" and explicitly never an instruction to clients about what's trustworthy. It's unusual but completely sound to have CAA set to forbid all CAs, switch it to allow just one CA, get a certificate issued, then put it back to blocking them all again for a week or months. I'm not recommending that procedure, but it's sound and if any software can't handle that the software is broken. The idea here is that all the public CAs are trustworthy but their procedures may not be a good match to your particular way of doing things. For example if a CA does ACME http-01 proof-of-control (like Let's Encrypt) and you let customers run arbitrary stuff on port 80 on your machines that's a bad combination, probably you should get your certificates from a CA which doesn't use ACME http-01 and restrict CAA.
- 5y ago
- makeworld 5y agoThis is why I only run Zoom in Firejail.
- underscore_ku 5y agoi run the snap Zoom on Ubuntu
- dmurray 5y agoIs that more secure? Snaps seem to be shit for performance, so I avoid them by default, but maybe I should be favouring them when I have security concerns.
- danielheath 5y agoBy default (without -—classic) on install) they run in a chroot. Makes saving files sent to you a hassle as it can’t write to your downloads directory.
- TheDong 5y agoNot really. https://github.com/ogra1/zoom-snap/blob/065831f1e83c1230810a6baa439b69bd9a753ee3/snap/snapcraft.yaml#L37 https://github.com/ogra1/zoom-snap/blob/065831f1e83c1230810a... It has the "home" permissions which means it can write "sudo pwn" into your ~/.bashrc, which will of course pwn you.
- travoc 5y agoI just decline Zoom meetings while politely saying “our cyber security division does not allow us to use Zoom.” Then send an alternative invitation. So far it seems to work just fine.
- puszczyk 5y agoWhat do you recommend to use instead?
- 5y ago
- johnchristopher 5y agoAre there any cases or instances of secrets leaking from a zoom meeting through hacking ? Specifically from audio and video, not chat ?
- skybrian 5y agoThis presumably doesn't apply to the web app, which is the only way I've used Zoom.
- mvanaltvorst 5y agoIt blows my mind that there are people who manage to find exploit chains like these, amazing job!
- junon 5y agoThis is generally through the use of (often custom) analyzers. I would wager, though I have little empirical evidence, that most non-trivial zero days of large software like this are not strictly manually discovered.
- skrebbel 5y agoIsn't this a bit like saying most software these days isn't manually built, because they use compilers?
- junon 5y agoNot at all.
- smolder 5y agoNot sure the point of this comparison. Using compilers to build software has been all but required for a long time, and exploit discovery can be done just by using the software in unexpected ways, or by using complex reverse engineering and analysis tools.
- Tutanota1 5y agoits more like you run a fuzzer and hope it breaks something.
- PeterisP 5y agoThe article goes into detail on how much trial and error effort it goes into making such an exploit chain - approximately two months work each for two people. Even for other people who have the required skills, making such a time investment - with no certainty of succes or reward - is a big barrier. Perhaps the math works out differently for blackhats as the payoff is larger and perhaps more certain if they do get to a working exploit.
- titzer 5y ago> This meant that by sending a ResponseKey message with an AES-encrypted <encoded> element of more than 1024 bytes, it was possible to overflow a heap buffer. This is what I was looking for. Fundamental bug was an overflow of statically-allocated buffer leading to heap corruption. We gotta get off memory-unsafe languages.
- UncleMeat 5y agoYup. I wouldn't hate it if it were illegal to write new applications that processed untrusted input in memory-unsafe languages, at least in the not too distant future. The fact that the industry doesn't see this as an urgent need is just embarrassing.
- junon 5y agoImagine thinking we should, literally, police language.
- UncleMeat 5y agoImagine thinking we should, literally, police engineering techniques. If you build a bridge then you are expected to use techniques and systems that provide at least some degree of planned safety for the users of that bridge. It is virtually impossible to write a C++ program of any meaningful complexity that processes untrusted data in an unsandboxed environment that does not expose the owner of the device running that program to harm. To say otherwise is to ignore decades of observation. Every single person who starts writing a new application in a memory-unsafe language that will deal with untrusted inputs is declaring up front that they are willing to tolerate the inevitable vulnerabilities and exploits caused by that decision. I think it is very important that our industry develops a path to getting all such programs off of unsafe languages, since it is very clear that techniques like testing, fuzzing, and audits are not sufficient to actually produce safe programs.
- virtue3 5y agoI initially disagreed with your viewpoint and after reading your response you've actually changed my mind. My only real gripe is I would prefer it came from the IEEE or something and not really from some government agency; or worse -> oracle or someone trying to get everyone to use java/their stuff.
- MoreenDichele 5y agoThe absolute dumbfucks who figured this out and could have created a world-changing worm with it and instead gave it away to the CCP for scraps deserve a bullet to the brain, in minecraft of course.
- beermonster 5y agoAlthough they don’t make it easy to find the link, you can use Zoom in a browser which is the best way of limiting the damage it can cause if you have to use it in the first place.
- avnigo 5y agoAnyone know what logging/printing library exploit.py is using in that first embedded video?