Live data from Hacker News

Zoom zero-day discovery

blog.malwarebytes.com

21–30 of 246 posts

Re: Zoom zero-day discovery

#21

Yet another (relative) win for the browser environment: "We also know that the method works on the Windows and Mac version of the Zoom software, but does not affect the browser version."

I don't think this is the right conclusion to jump to. Browsers have a mountain of issues in their own right.

Re: Zoom zero-day discovery

#22
post #12

Earlier quoted context omitted.

You are always free to sell the hacks for their """actual""" market value on the black market. Of course you need to launder the money, you might get jailed, you might have to flee the country and so on but at least you get your fair rate.

Or sell it to the NSA (or insert your national intelligence service here) as a defense contractor, which some might call your “patriotic duty”.

You need to setup as a defense contractor (and jump through all the hoops) just so you can sell a Zoom zero-day and realize the NSA will give you 50k?

Re: Zoom zero-day discovery

#23

Yet another (relative) win for the browser environment: "We also know that the method works on the Windows and Mac version of the Zoom software, but does not affect the browser version."

We don't know much about the RCE. It may have been able to do something in the browser, with more effort, e̶s̶p̶e̶c̶i̶a̶l̶l̶y̶ ̶g̶i̶v̶e̶n̶ ̶t̶h̶a̶t̶ ̶t̶h̶e̶ ̶"̶n̶a̶t̶i̶v̶e̶ ̶a̶p̶p̶"̶ ̶h̶e̶r̶e̶ ̶i̶s̶ ̶a̶n̶ ̶E̶l̶e̶c̶t̶r̶o̶n̶ ̶a̶p̶p̶. Perhaps they stopped once they saw they had done enough for the $200k bounty.

Edit: Not an electron app.

Re: Zoom zero-day discovery

#24
post #3

Is it just me, or does $200k seem far too low for this? I understand that the reward was paid by the event, not Zoom... but it seems to me that Zoom should “pony up” some additional funds for this research.

I can't tell much from the gif, but perhaps. RCE for anyone that runs Zoom, or RCE for anyone in a meeting you're in or something else?

Re: Zoom zero-day discovery

#25
post #6

“Makes calls safer”. It fixes this particular no user input RCE vulnerability, but how many others remain? If this type of vulnerability is present at all in Zoom, then it stands to reason more wait to be discovered by sufficiently motivated attackers. These things shouldn’t end with a bounty for the researcher and a patch by the vendor. It should end with a root cause analysis and a plan to fix that type of vulnerab…

I'm still upset they try to force you to use their plugin. These would be less scary if it were jst a web app.

Re: Zoom zero-day discovery

#26
post #19
post #10

Earlier quoted context omitted.

> Is it just me, or does $200k seem far too low for this? For two researchers, that sounds like a lot. $100k each in less than a week for this bug sounds just rightly priced.

There is most likely much more than a week of work behind this.

This is one of those "$10 for the hammer hit, $49,990 for knowing where to hit it" situations.

Re: Zoom zero-day discovery

#27
post #25
post #6

“Makes calls safer”. It fixes this particular no user input RCE vulnerability, but how many others remain? If this type of vulnerability is present at all in Zoom, then it stands to reason more wait to be discovered by sufficiently motivated attackers. These things shouldn’t end with a bounty for the researcher and a patch by the vendor. It should end with a root cause analysis and a plan to fix that type of vulnerab…

I'm still upset they try to force you to use their plugin. These would be less scary if it were jst a web app.

They do? I don't have any plugin installed and use Zoom in Firefox without major issues

Re: Zoom zero-day discovery

#28
post #21

Yet another (relative) win for the browser environment: "We also know that the method works on the Windows and Mac version of the Zoom software, but does not affect the browser version."

I don't think this is the right conclusion to jump to. Browsers have a mountain of issues in their own right.

And an order of magnitude more security researchers trying to poke holes in them, too.

Re: Zoom zero-day discovery

#29
post #23

Yet another (relative) win for the browser environment: "We also know that the method works on the Windows and Mac version of the Zoom software, but does not affect the browser version."

We don't know much about the RCE. It may have been able to do something in the browser, with more effort, e̶s̶p̶e̶c̶i̶a̶l̶l̶y̶ ̶g̶i̶v̶e̶n̶ ̶t̶h̶a̶t̶ ̶t̶h̶e̶ ̶"̶n̶a̶t̶i̶v̶e̶ ̶a̶p̶p̶"̶ ̶h̶e̶r̶e̶ ̶i̶s̶ ̶a̶n̶ ̶E̶l̶e̶c̶t̶r̶o̶n̶ ̶a̶p̶p̶. Perhaps they stopped once they saw they had done enough for the $200k bounty. Edit: Not an electron app.

> It may have been able to do something in the browser, with more effort, especially given that the "native app" here is an Electron app.

Zoom is a C++ / Qt app

Re: Zoom zero-day discovery

#30
post #25
post #6

“Makes calls safer”. It fixes this particular no user input RCE vulnerability, but how many others remain? If this type of vulnerability is present at all in Zoom, then it stands to reason more wait to be discovered by sufficiently motivated attackers. These things shouldn’t end with a bounty for the researcher and a patch by the vendor. It should end with a root cause analysis and a plan to fix that type of vulnerab…

I'm still upset they try to force you to use their plugin. These would be less scary if it were jst a web app.

You can force it to use a web app by declining permission to run locally.

The web-app has fewer capabilities (no gallery view, last I used it), but works great.

Also, Meet is fully-featured and runs entirely in-browser.

Post reply on HN