Cisco: Magic WebEx URL Allows Arbitrary Remote Command Execution
bugs.chromium.org
bugs.chromium.org
We're yelling at browser vendors for locking down their browsers more and more and for removing more and more features that allow developers more native access, but then stuff like this happens.
Who thought that exposing the full native OS API via a (cumbersome) scripting language was a good idea? Why does this need to be a browser extension and not something I need to explicitly install on my machine?
Java Applets at least had a sandbox (albeit with flaky security). They have gone away because of security concerns, but as people still need some native access, people build stuff like this that is infinitely worse than what Java has ever been. Instead of a single sandbox, we're now relying on an unlimited amount of only mildly competent developers coming up with elaborate schemes that do nothing but provide a slight bit of obscurity.
That uuid and the base64 encoding of the library name and function calls point to the fact that the developers felt uncomfortable, which is good I guess. That they then chose to use such an impotent method of protection is less so. At this point, why did they even bother?
I'm starting to think that we are actually worse off now than we were in the age of Java Applets and NSAPI plugins
Even their Android client can't manage the mic volume properly and people can't hear you.
Ridiculous experience, worst web conferencing service I have ever used (I consider it even worse than Oracle Beehive Conferencing - not many people know this). In contrast, WebEx is way better (phone dial-in quality is pretty good).
Beehive Conferencing used to be the default option for remote web conferencing (it actually has a better Linux version than WebEx). Beehive's predecessor, cannot even remember the name, use to be Windows ONLY and crashes attendees' Windows (BSOD) randomly (15-20%...) LoL
I didn't even know they had any kind of Linux support. Internally, Cisco only supports macOS and Windows on the desktop so it's no wonder the Linux support is bad. If you absolutely need to use Webex then clearly using desktop Linux is a bad idea.
Currently it's a maze of dialogs only technical people are able to navigate successfully. Expecting people already in need of support to manage to bypass this deliberate inconvenience is simply unrealistic.
The company I work for used to maintain a solution based on this approach. It worked well until browser-vendors started tightening up security.
After that we had to come up with a different solution all together, because almost no users managed to configure our integration successfully.
(And that rewrite was a lot of work, so I can see why Cisco/WebEx has been postponing it as much as possible)
They could even, god forbid, accept that it's not possible instead of coming up with "clever" ways to make it possible.
It also doesn't inspire confidence that this is the screenshot of the Chrome Extension they give users to encourage them to use the extension: http://imgur.com/a/Rsy3H
(For those who don't want to click, the screenshot showing the install has the rating from the Chrome Webstore, which is currently at 2 stars)
I mean, I applaud the honesty of showing us what users have rated it, but it just seems kind of sloppy to me.
Currently my company uses Hangouts, BlueJeans, Zoom, and WebEx - don't know why there is no decision made.
In this context it is the worse - I tried to run it on Linux, like you said now that chrome support is gone, I can only launch the Java (swing - not Java applet for sure) UI via Firefox, end up with crappy slow GUI, no ability for screen sharing & viewing, no audio, utterly useless.
On Linux, web conferencing services that provide a lite (feature rich) version like BlueJeans and GoToMeeting (chrome extension and/or web version) are pleasant to use.
I personally prefer to use Hangouts if no such pure web version is available although Hangouts seems to have lost its gravity…
I remember the joy of using WebEx for the first time back in 2006, instead of Netmeeting or the other applications we had available to us.
Using Chromium on Debian, everything worked absolutely smoothly. No further install requested. Audio quality was great. My video picture looked a bit grainy to me, but the other participant appeared very clear on my end.
They're using WebRTC[2], which excludes Explorer and Safari, but covers recent versions of just about everything else.
After poor experiences using Skype, Webex and Hangouts, I was very pleasantly surprised by appear.in
[2] http://support.appear.in/article/94-who-can-use-appear-in
WebEx just seems castrated, feature-wise.
For meetings that fall into my evening, I join conferences via a tablet and the Android App, and connect to audio through it so I can relax or move about the house.
It seems bonkers that someone would think it is a good idea to not at the very least have any domain level validation. It is also another mark against the more eyes mean more security mindset. That flaw would be available in clear text to anyone who bothers to examine the manifest of the Chrome extension. It just seems like no white hat bothered to look before.
Cisco's proposed fix for the exploit seems a bit hacky though.
I suspect there are many others who are just as capable of doing the same work, but either A) don't have the opportunity (e.g. they have day jobs, few people work on P0) or B) aren't as public about their findings (e.g. exploit brokers, nation states, etc)
Anyway, that's what I remind myself whenever I start thinking "I wish I could be as cool as Tavis". Someday I'd love to have have the opportunity to do the same work.
Good luck using it if you have a single non technical client on call.
Here's a whitepaper on one of their newer products that is fully end-to-end encrypted (meaning anti-NSA): http://www.cisco.com/c/dam/en/us/solutions/collateral/collab...
Not suspecting Cisco of anything nefarious here, but such brochure-speak doesn't necessarily mean much.
Now this does only apply for companies that choose to go with the on-premise KMS, if not, Cisco manages the KMS in their own cloud as well, which does mean it's not a true e2e solution (although like I said, I can speak with a pretty high level of confidence that security is one of the top priorities)
So my comment (weak as it is) stands.
That took too long. Of course, just like RSA Security LLC now they will try to better their image. I think they had their chance.
Part of the marketing is talking about security. It's unclear if the reputation matches reality though.
I say this as someone who has become super disillusioned with Cisco, as the thread originator has. But this is mostly because of their switch products, pricing, configuration management, and end user software. I don't have much experience with their security. Though I have no reason to suspect that it's the least better than any other companies' security based on the amount of patching and their default configurations.
Putting my security researcher hat on, maybe this tiny little group's purpose is to figure out and get intel on what directions customers are actually looking in, so they know where to hide stuff.
Not comfortable talk, I know. I'm inspired by http://video.fosdem.org/2014/Janson/Sunday/NSA_operation_ORC... (46:05, well worth watching; 357MB)
I sadly do not know the answer to the rest of your questions.
Multi-user screen sharing (I didn't realise this), video conferencing, chat and audio. From your browser.
It's since been discontinued but the ideas (and means to do this) live on in other projects; some listed here: https://support.mozilla.org/en-US/kb/hello-status
"impossible"? Hardly. It's even been done.
[1]https://observatory.mozilla.org/analyze.html?host=www.webex....
It looks like this is a really strong set of security requirements. According to their stats, 87% of sites tested have an F score, and only 1.47% have an A- or higher.
EDIT: The better technical term would be "arguably patched." See reply below.
Just so that nobody reading the comments gets the wrong idea: read the whole discussion. Fixed here seems very subjective; they only seem to have limited the extension to the webex.com domain. In particular,
> although this does mean any XSS on webex.com would allow remote code execution
and
> doesn't use HTTP Strict Transport Security, either as a header or by being preloaded
My understanding is that this means that not only would any XSS on webex.com lead to possible exploitation, but also that anyone who can MitM your machine, such as in a coffee shop, and use that to gain remote execution by intercepting and faking a request to an unsecured webex.com. (Since no HSTS is in place, the browser would allow it.)
The latter is less likely, but nonetheless, this extension seems to allow anyone who can talk to it an RCE, which seems far from fixed.