Live data from Hacker News

‘War Dialing’ tool exposes Zoom’s password problems

krebsonsecurity.com

51–60 of 247 posts

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#51

It's 1985 all over again: I'm in my bedroom running a ProDOS wardialer on my 300/1200 baud AppleModem; I have found zero computers, but it is fun watching the numbers flick past, hoping that I, too, can discover a WOPR and start global thermonuclear war.

Yeah but this time, it’s an easy as guessing a world leaders zoom meeting, and tricking them into believing something preposterous

I remember a Montreal morning show doing this via phone and tricking a few world leaders. Hopefully some funny things come out of this.

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#52
post #10

Earlier quoted context omitted.

Yeah but then it sucks for people calling in to have to punch in a 21+ character long meeting ID

> Yeah but then it sucks for people calling in to have to punch in a 21+ character long meeting ID I may be out of touch with the average biz-guy, but how many people are realistically calling in manually, over traditional phone-lines these days? Is it really a significant percentage?

When I did consulting, almost every meeting had at least one dial-in. If you didn't include a dial-in, you'd be guaranteed to either get a request to add one, or you'd get people who didn't show.

There was always:

1. someone who was on the road - a traveling consultant or someone in sales

2. a client or potential who called in because of the same, or because they don't sit at a computer all day and/or don't have a headset for their computer.

3. People in a conference room

4. a client who sucks at computers and dials in because they can't figure out how to install the latest version of CiscoGoToZoomMeetingWebEx.exe in IE8 on their macbook.

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#54

Earlier quoted context omitted.

That's not helpful when you have to punch it into a conference room speakerphone. I did once put together a hack that would scrape the meeting ID from the Zoom UI and emit the touchtones from my laptop to dial in.

There is always a trade off between security and usability. I like your hack though, any chance you'd put it on Github?

I haven't used it in a while, so I wouldn't be surprised if the Zoom bit is broken, but here it is:

https://gist.github.com/micahbf/91a295016f4472b47acfe317d714...

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#56

How hard is this for them to fix?

They may decide there is nothing to fix. If you want to use a password you can.. but don't force it on the average user who would trade having no password with the potential of someone random joining.

If you want to keep it private use a password.

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#57
post #51

Earlier quoted context omitted.

Yeah but this time, it’s an easy as guessing a world leaders zoom meeting, and tricking them into believing something preposterous

I remember a Montreal morning show doing this via phone and tricking a few world leaders. Hopefully some funny things come out of this.

Hopefully we don't have any unfunny things come out of this.

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#58
post #10

Earlier quoted context omitted.

Yeah but then it sucks for people calling in to have to punch in a 21+ character long meeting ID

> Yeah but then it sucks for people calling in to have to punch in a 21+ character long meeting ID I may be out of touch with the average biz-guy, but how many people are realistically calling in manually, over traditional phone-lines these days? Is it really a significant percentage?

I call in for every meeting I can. My hearing is poor; the sound quality on the computer just isn't good enough for me. Then add in that my computer is heavily loaded, so it's ability to encode/decode sound is degraded.

I have a high quality desk phone on a land line (admittedly, VOIP from FIOS, but not via my computer) and I will fight tooth and nail to keep it.

All that being said, I'm comfortable typing in an arbitrary length password on my phone. All I ask is that it be formatted to make that easy (groups of 3-4 numbers with spaces).

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#59
post #10

Earlier quoted context omitted.

Yeah but then it sucks for people calling in to have to punch in a 21+ character long meeting ID

The telephone dial-in option should've been separate - if the user chooses to enable it then they can fall back to shorter IDs, while meetings that don't need it (or where it doesn't make sense anyway - screen shares, presentations, etc) would use longer, more secure IDs.

which means all you gotta do is war dial the phone network...

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#60

It's 1985 all over again: I'm in my bedroom running a ProDOS wardialer on my 300/1200 baud AppleModem; I have found zero computers, but it is fun watching the numbers flick past, hoping that I, too, can discover a WOPR and start global thermonuclear war.

Yeah but this time, it’s an easy as guessing a world leaders zoom meeting, and tricking them into believing something preposterous

Modern Version: "Shall we play a game?" "Love to" "‼To play Global Thermonuclear War, you must first update your flash player. Click here‼️"
Post reply on HN