Zoom Windows client could allow credentials to be leaked via UNC path injection
bleepingcomputer.com
bleepingcomputer.com
Sorry, but this one isn't on Zoom. This is all on Windows. You should be able to click a static link and expect it not to send your user password (or an easily crackable hash) to some remote server.
This is nothing new and can also be seen in one of tools I often use to check if my VPN is easily detectable [0].
This is Windows being vulnerable to carelessly authenticating to a remote server using an insecure protocol. Attack vectors also include email, messenger applications, QR codes, and anything else that might form an URI you can click on.
You can prevent this in your firewall by setting the right group policy [1] or blocking outbound SMB/NTLM/etc. in your network firewall.
[0] hʇʇp://witch.valdikss.org.ru/ WARNING: will try to trigger the exact same credential leak on Windows. Use with care. [1] https://www.securitynewspaper.com/2016/08/06/understanding-w...
Microsoff should really disable this insecure method of authentication to public addresses for everyone but business users who rely on it (and whose IT department can manually enable the feature through group policy). There are sort-of-valid reasons to use SMB over the internet (easy network printing for one, as well as mounting disks in networks that still hand out publicly routable IPv4 addresses such as universities) and closing the port would break that functionality immediately.
Why should every residential ISP in the world need to cover up for Microsoft's design flaw? This bug is presented as news but it has been a known security issue for at least 6 years now.
Sometimes you gotta imagine it like it's a bad flag for a program or library that's just left on default. If you're using that program or library then you are also responsible for how you use it.
Every chat application turns HTTP strings into links and I don't believe it's the application developer's fault to assume that a simple link will cause code execution or leak credentials. That's a bad API design by Microsoft to the point where it's a vulnerability.
If someone told you that on iOS a link starting with HTTP would cause the device to send your Apple password to a random server, would you think that's normal and therefore developers should know better? Why would it be any different with any other kind of link? Wouldn't you expect the OS not to fail catastrophically when a user clicks a link like that?
Having fallen out of paying attention to Windows Server over the past few years, I'd be a little surprised if the weak NTLM hash is still on by default in current versions of Windows (although that's not to say most of the Windows install base isn't in obsolescence).
Even if it didn't, which I'm not sure about, they still need to send one if you're trying to open a samba share. This attack works by presenting a UNC link to a samba share, which (when the user accepts the credential prompt) will send a nice compatible NTLM password hash.
https://techcrunch.com/2020/03/31/zoom-at-your-own-risk/
I now see senators in my country holding meetings over Zoom and it's horrifying.
I've been avoiding most things Google, but these days I don't have a problem with colleagues using Google's Meet, because honestly I trust Google more than Zoom. Skype is another popular option.
This is a wasted opportunity for a solution like Signal.org to provide support for e2e group video calls. I'm guessing it's not easy to implement.
reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0" /v "RestrictReceivingNTLMTraffic" /t REG_DWORD /d 2 /f
reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0" /v "RestrictSendingNTLMTraffic" /t REG_DWORD /d 2 /f
It's an option of my personal "de-tracking" Windows 10 script https://github.com/lazerl0rd/ScriptWINg.https://www.bbc.co.uk/news/business-52115434
One interesting point was that the most senior figures in the UK government have been using Zoom to conduct official meetings while several of them are in isolation at home due to the virus. That is concerning given the reported lack of basic security features like full encryption.
Good thing about this is the fatigue. We're just a few years away until jo*rnalists lose most of their power.