Zoom, the videoconferencing software that's skyrocketed in popularity as much of the globe sits at home due to the coronavirus outbreak, is quickly turning into a privacy and security nightmare.
BleepingComputer reports about a newly found vulnerability in Zoom that allows an attacker to steal Windows login credentials from other users. The problem lies with the way Zoom's chat handles links, as it converts Windows networking UNC (Universal Naming Convention) paths into clickable links. If a user clicks on such a link, Windows will leak the user's Windows login name and password.
The good thing is that the password is hashed; but the bad thing is that it is in many cases simple to reveal it using password recovery tools such as Hashcat.
The vulnerability was first found by security researcher @_g0dmode and verified by security researcher Matthew Hickey. Additionally, Hickey told the news outlet that this vulnerability can be used to launch programs on a victim's computer when they click on a link, though Windows will (by default) at least give a security warning before launching the program.
As far as security vulnerabilities go, this one is pretty bad, as it doesn't require a lot of knowledge to exploit. It does require the victim to actually click on a link, and it can be mitigated by tinkering with Windows' security settings, but it's definitely something Zoom should fix by changing the way the platform's chat handles UNC links.
In the meantime, for a quick fix, go to Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> Network security: Restrict NTLM: Outgoing NTLM traffic to remote servers and set to "Deny all".
Mashable has contacted Zoom for comment on this story, and we'll update it when we hear back.
SEE ALSO: Zoom's iOS app no longer sends data to FacebookThis is not the only privacy/security-related issue that has been unearthed at Zoom in the past couple of weeks. Just yesterday, The Intercept reported that Zoom doesn't actually use an end-to-end encrypted connection for its calls, despite claiming to do so. There's also the issue of leaking users' emails and photos to unrelated parties, and the fact that the company's iOS app, until recently, sent data to Facebook for no good reason.
Zoom software also has a couple of worrying privacy features, and although this isn't Zoom's fault, it's worth noting that hackers are using the app's newfound popularity to trick users into downloading malware.
文章
62
浏览
22795
获赞
32526
Remember FOMO? Yeah, neither do we.
I can hardly remember what it feels like to devote even an ounce of concern to social engagements.IThe White House wants your help to 'make the government tiny again'
Tired of U.S. health officials studying deadly and infectious diseases? Sick of the Department of Ag5 Affordable Last
Most phone shoppers would be rocking the latest and greatest model, were it not for budget constrainAlexa, have you been hacked? New research found major security flaws in Amazon’s virtual assistant.
“Alexa, is a hacker listening to everything I say to you?”According to a new report, theFacebook gets off the hook yet again in FTC antitrust case
The great Facebook breakup, it seems, is not to be. At least not yet. It was only in late December tHow to Boot to BIOS in Windows 11
The Windows 11 POST (Power On Self-Test) process happens quickly for improved startup times, leavingBest Amazon deal: Save 20% on grocery essentials
SAVE UP TO 20%:The Amazon Spring Grocery Sale has pantry essentials marked down by as much as 20% inApple removed 'Fortnite' from the App Store for violating its policies
When it comes to the App Store, Apple is through playing nice. The tech giant confirmed Thursday thaHow to turn off comments on a Facebook post
Sometimes feedback in the form of comments is welcome on Facebook posts. Other times, not so much. FIt's time to re
It’s a tradition like no other: Come early April, sports fans flock to the App Store to re-dowSkullcandy Push Ultra earbuds review: Decent to use and hard to lose
Whether you're on a campus or stuck at home doing remote learning this fall, you need a pair of earbApple launches new iMac with better display and 1080p webcam
It's the return of the ... iMac? Get it? Like the Mark Morrison song? Whatever, Apple made a new iMaLG wants to put transparent OLEDs in restaurants and subways
LG's got a transparent OLED display, and if you're wondering how such a device could be useful, theTheirTube shows how YouTube's algorithm creates conspiracy theorists
Ever wonder how your dear Aunt Karen got radicalized into believing the bizarre conspiracy theoriesPope Francis just threw some serious papal shade at Donald Trump
It's well known that Pope Francis and President Donald Trump don't exactly see eye-to-eye on global