Yet another (relative) win for the browser environment: "We also know that the method works on the Windows and Mac version of the Zoom software, but does not affect the browser version."
Zoom zero-day discovery
21–30 of 246 posts
Re: Zoom zero-day discovery
#22Earlier quoted context omitted.
You are always free to sell the hacks for their """actual""" market value on the black market. Of course you need to launder the money, you might get jailed, you might have to flee the country and so on but at least you get your fair rate.
Or sell it to the NSA (or insert your national intelligence service here) as a defense contractor, which some might call your “patriotic duty”.
Re: Zoom zero-day discovery
#23Yet another (relative) win for the browser environment: "We also know that the method works on the Windows and Mac version of the Zoom software, but does not affect the browser version."
Edit: Not an electron app.
Re: Zoom zero-day discovery
#24Is it just me, or does $200k seem far too low for this? I understand that the reward was paid by the event, not Zoom... but it seems to me that Zoom should “pony up” some additional funds for this research.
Re: Zoom zero-day discovery
#25“Makes calls safer”. It fixes this particular no user input RCE vulnerability, but how many others remain? If this type of vulnerability is present at all in Zoom, then it stands to reason more wait to be discovered by sufficiently motivated attackers. These things shouldn’t end with a bounty for the researcher and a patch by the vendor. It should end with a root cause analysis and a plan to fix that type of vulnerab…
Re: Zoom zero-day discovery
#26Earlier quoted context omitted.
> Is it just me, or does $200k seem far too low for this? For two researchers, that sounds like a lot. $100k each in less than a week for this bug sounds just rightly priced.
There is most likely much more than a week of work behind this.
Re: Zoom zero-day discovery
#27“Makes calls safer”. It fixes this particular no user input RCE vulnerability, but how many others remain? If this type of vulnerability is present at all in Zoom, then it stands to reason more wait to be discovered by sufficiently motivated attackers. These things shouldn’t end with a bounty for the researcher and a patch by the vendor. It should end with a root cause analysis and a plan to fix that type of vulnerab…
I'm still upset they try to force you to use their plugin. These would be less scary if it were jst a web app.
Re: Zoom zero-day discovery
#28Yet another (relative) win for the browser environment: "We also know that the method works on the Windows and Mac version of the Zoom software, but does not affect the browser version."
I don't think this is the right conclusion to jump to. Browsers have a mountain of issues in their own right.
Re: Zoom zero-day discovery
#29Yet another (relative) win for the browser environment: "We also know that the method works on the Windows and Mac version of the Zoom software, but does not affect the browser version."
We don't know much about the RCE. It may have been able to do something in the browser, with more effort, e̶s̶p̶e̶c̶i̶a̶l̶l̶y̶ ̶g̶i̶v̶e̶n̶ ̶t̶h̶a̶t̶ ̶t̶h̶e̶ ̶"̶n̶a̶t̶i̶v̶e̶ ̶a̶p̶p̶"̶ ̶h̶e̶r̶e̶ ̶i̶s̶ ̶a̶n̶ ̶E̶l̶e̶c̶t̶r̶o̶n̶ ̶a̶p̶p̶. Perhaps they stopped once they saw they had done enough for the $200k bounty. Edit: Not an electron app.
Zoom is a C++ / Qt app
Re: Zoom zero-day discovery
#30“Makes calls safer”. It fixes this particular no user input RCE vulnerability, but how many others remain? If this type of vulnerability is present at all in Zoom, then it stands to reason more wait to be discovered by sufficiently motivated attackers. These things shouldn’t end with a bounty for the researcher and a patch by the vendor. It should end with a root cause analysis and a plan to fix that type of vulnerab…
I'm still upset they try to force you to use their plugin. These would be less scary if it were jst a web app.
The web-app has fewer capabilities (no gallery view, last I used it), but works great.
Also, Meet is fully-featured and runs entirely in-browser.