Two vulnerabilities in Zoom could lead to code execution
blog.talosintelligence.com
blog.talosintelligence.com
Everybody is using zoom these days and in my opinion it's because it has an excellent user experience.
I'm wondering if something like Cisco WebEx is just as "broken" but everyone doesn't have their eyes on it.
One thing for sure. We need a way to run desktop applications in isolated containers in the same way mobile apps are run.
I joined a WebEx meeting the other day, downloading it's client. And after the meeting a little window popped up with my next meetings.
Without permission it'd hooked into my outlook calendar.
At the the very least, we could have some sort of virtual file system that by default applications only see.
I'm sure the capability exists in windows, because there's a mod management tool for Skyrim I've used where it creates a virtual folder for all your activated mods and the game itself sees that virtual folder when running.
As an aside, remember when Skype was the most popular audio/video chat app in the world?
Or even MSN messenger?
I also remember Hangouts getting popular but then stagnating in using 100% CPU and setting fire to your laps.
And I hate that Covid means that I am pretty much forced to use have half a dozen each day.
On my work computer it went from using kind 60% of a core to almost nothing.
I've only ever seen this when explaining to people why Linux appears to be using all their RAM - it caches your disk to make subsequent reads faster, and when an application needs more memory the cache will be evicted immediately and at almost no performance cost.
It's completely insane to suggest the user's RAM is yours to consume. Some people have 64 gb of memory in their desktops, and others have 4gb on their $300 laptop because that's all they could afford, and some have 2gb on their cheap phone.
That's where it's taught I think, and certainly it's the truth in that context. But more than a few times I've encountered it as a defense for stuff like bloated chat programs slurping up gigabytes of RAM.
With respect to hardware diversity, I think part of the problem is most programmers do their development on powerful hardware and become accustomed to it. Certainly nobody wants to sit around for an hour waiting for their build to finish on low-end hardware when a powerful computer, which they or their employer can easily afford, could finish the build in minutes. But because of that, they lose touch with end users who will be running that software on very modest hardware.
Find Ripcord, it is fast and works for Slack and Discord.
Then, when you can choose which service to use, pick one that is web-first.
I can live with a fat app, but anything that insists on being there and having serious negative trade-offs even when not using it, in my opinion falls under malware.
I hope they all uninstall cleanly after covid.
Short of that Sandboxie, which has been around for a long time, has more of a restrictions/container type approach.
https://community.sophos.com/products/sandboxie/f/forum/1196...
Also, is it possible to sandbox any app? Say, for example, Zoom.
No vulnerabilities are in production because of buggy code and lack of pre-production quality control. But yes more popularity means more free quality control by third parties. It is a sad reality of "scale first" and "cheapest offer" economies.
Qubes
So you're going to love this.
The CEO of Zoom is a former senior engineer on WebEx, funded by ex-WebEx employees and founders.
Zoom was originally him plus 40 software engineers in China.
If I was Cisco, I'd be wondering how much code was copied into Zoom.
And if I were you, I'd be wondering why people are using an essentially Chinese communications tool.
Zoom is not a normal US company that outsources to China - the entire development team started in China with a San Jose "HQ" (because Cisco is based in San Jose.)
He’s an American. His wife is an American. His kids are American.
1. https://www.cnbc.com/2019/08/21/zoom-founder-left-job-becaus...
You know NSA is an American Agency, and America is not China - there is a free enterprise. The only way they can "arm-twist" you is by rules and regulations that every company has to follow. In other words - NSA cannot force you to break the law.
[1] https://www.washingtonpost.com/world/national-security/nsa-i...
Where is this so-called "arm-twisting" ??
Even if it wasn't a metaphor the US has been known to physically harass people for Software more than any other regardless of what the people did.
Some examples please?
Unless what you saying is that some programmer neck was crushed for 8 minutes because they didn't want to implement backdoor??
You sidestepped my main point, that US/CCP is a laughably false equivalency.
... oh wait your premise disqualifies that.
Well Arabia and Russia are starting to force data being processed and stored in their territory by blocking foreign comm-tech. But i don't think that is a solution, that is just digital nationalism driven by fear of espionage and demand for the power of mass surveillance.
What "the world" should do is lobby against nation-states and mega-corps having their noses in everything, because it is a central building block of totalitarianism. Even if the state doesn't go all out authoritarian, it opens back doors that leave people vulnerable to abuse by bad actors.
A proven case? Look at Crypto AG. Sure one might argue the whole company was planted, so it doesn't count ...
For regular citizens, in USA, isn't having NSA know your stuff worse than having CCP know it?
Chinese as in "under the jurisdiction the Chinese government"? Well... quite a bit. The comment was pretty specific about it being the location.
Wait, what??
While this is true, both he and his wife were born in China, and it's not clear if they renounced their Chinese citizenship. I buy their explanation that development is done in China to save money, but it's an interesting choice for someone so concerned with looking like an American company.
[1] https://www.cnbc.com/2019/03/26/zoom-key-profit-driver-ahead...
Sorry for the amp link I'm in a hurry I have a zoom call in a few minutes
https://www.google.com/amp/s/technode.com/2020/04/13/is-zoom...
It would have taken you less time to fetch the original link than to type that.
I'm on mobile, it was part true. I really had no idea I needed to click on that tiny i and didn't have time to do a search by title.
Typing in mobile is really fast type days. I have a full keyword/small phone. I started training myself to type faster on mobile by coding on a mobile editor a few years ago. It is so much more difficult at first but you become more focused with time. Add in a free editor app with ad popups every few minutes for additional challenge.
People use it because it's currently the best product.
For us at our university, ease of use and the fact that it allows the speaker of a talk to see the audience while sharing screen made it the preferable tool.
Why not? As I'm in the UK I assume that either I use a USA based product and have my data open to USA government sponsored TLAs, or use proprietary products from other countries and have their secret agencies have some sort of access.
With Five-Eyes, or Maximator, mainstream development in one of the countries involved suggests there's going to be intelligence agency access.
For private citizens access by CCP is probably (unless you have links to China) far lower risk than using software connected to Western nations.
I don't have need of secret communications really; Jitsi (meet.jit.si serves my needs when I get to choose the video chat software; family and friends seem happy with it).
(I briefly had Zoom installed a few months ago, then un-installed it, but I don't know how to verify).
In a sense, yes. I think Zoom has achieved far more popularity than Zoom was prepared for. Everything about Zoom feels like it was thrown together hastily and for a much smaller audience.
It may seem unrelated, but I think a microcosm of all this was: Attention tracking. They removed this feature because of its unpopularity after privacy people flagged it, which may have not happened if Zoom hadn't gotten popular. But it also shows that they have no internal brakes on this sort of thing; no strong product lead or anyone else able to push back on the PowerPoint prodders with "nope, not happening, that's fucking weird and creepy".
Can you expect good code to come out of that environment?
Notably, these vulnerabilities were in features I, a daily user of Zoom in these weird times, did not even know existed (code snippets and GIFs). Strikes me as more "shit rushed out of the door with no oversight and minimal code review to get boxes checked".
Secure? Different story. But if code quality correlates with security, then most likely yes. They can push secure code.
May I introduce you to https://meet.jit.si, which works flawlessly, is open-source, and supports e2e encryption.
I really don't understand why "use Jitsi" isn't the stock answer when people start complaining about Zoom, let alone on HN.
Jitsi wouldn't work for the Zoom meetings I admin. It's too technical for a very untechnical audience.
Zoom was hard enough, and 90% of the meetings in our ecosystem use Zoom, meaning they only need one app. Asking them to use Jitsi would require two (as every other meeting uses Zoom), which means a non technical audience has to learn 2 technical things instead of 1.
In the case of E2E encryption, every attendee has to type in the meeting key when they join for it to work. The users I work with will forget/won't understand why etc. They just want to speak to people. So that will render e2e useless if 1 out of 20 attendees doesn't do it.
Not to mention we have attendees who don't own a smartphone so have to dial in. Making the E2E Jitsi stuff pointless.
Jitsi is great for technical people. Zoom is great for non technical people.
Which would imply that some users had issues getting onto Zoom, the easiest of these systems to join. So why make it harder?
wat? That's a totally-incorrect assumption. Zoom requires installation of software. Jitsi doesn't.
> I've actually just gone off to try out jitsi again (i do actually check to see if it's worth switching platforms) and it turns out it asks me to install an android app too. So Jit.si itself actually needs me to download software on my smartphone. So......
But technical "whizzkid stuff" (as they call it) is not something they are comfortable with.
I'd quite like to not have to unexpectedly sacrifice 4 hours of my time finding a bug in the config. Nor do I really want to spend (at least) a weekend to double check all the install/config works correctly to start with.
I'm busy enough with the day job without starting a second one. I admin this voluntarily and I'd rather work smart, not hard.
EDIT: You can see my reply to the parent for user side technical effort. A helpful hint might be to think about this problem in people terms, rather than systems terms.
> My point was that Zoom fits some use cases better, and that seems to be the case more often than not for users with less technical ability than the HN userbase.
Some of our users may be, in the kindest possible way, completely batshit insane with their life falling apart when they first turn up to our meetings.
Meeting hosts [0] can explain Zoom to them in three/four steps and look after them from there with in meeting controls. With Jitsi, they've got to keep asking them to stop unmuting themself because they keep pressing buttons... Which means they have to stop the meeting for 5 minutes, again and again and again.
EDIT for further information / clarity:
Zoom also enables users to chat without any additional steps [1]. With Jitsi you have to create a name to even see the chat. So new users may connect, not hear anything [2] and then just leave and not come back. Zoom, they can see the message we send them and then we can guide them from there.
Then there's the fact that meeting hosts cannot screen share from smartphone with Jitsi -- 90% of our users/hosts are smartphone only [3]. This would require them buying a laptop. Many hosts cannot do this / adds to technical effort.
Then there's the fact that we'd have to type in the name of the Jitsi meeting EXACTLY whenever we want to start the meeting. Hosts would have to get the name of the meeting ID exactly correct every week. To make meeting IDs secure, that'd mean they have to type a complex character sequence out perfectly every day. (Yes they can copypasta, but some aren't even that technically adept).
Then of course there's always the chance someone else uses that meeting ID at the same time by accident! There's no method I saw where you can reserve a Jitsi meeting ID only for our use [4]. Oh, and while I'm here, what about the fact that you cannot schedule a jitsi meeting ID ahead of time? So there's no scheduling a call / meeting available.
I might as well talk about security too -- anyone in a Jitsi meeting can start a live recording [5]. And any participant can just remove and change the meeting password at any time. And no waiting rooms. And once a user is removed, they can just join again -- repeat Zoombombings, woo!
And then this doesn't even begin to cover the fact that hosts need to go through all the steps to set up a meeting [6] every time they start a meeting. Zoom handles all that with the default settings I enable for them as admin.
Some of this can be covered by custom Jitsi server installs. But that introduces way more technical effort on my side and doesn't cover dial in phone options (at least in a simple and forward maintainable way).
I'd rather pay Zoom £20 a month.
====
Addendum: I just tried setting up a password for a meeting and then inviting myself. The password wasn't required to join... Pretty poor!
[0]: not me, I'm admin
[1]: e.g. in the case of buggy audio
[2]: maybe they didn't accept the permissions properly
[3]: tested on latest android app
[4]: I could be wrong, but this is a simple option for Zoom
[5]: An absolute no-no for us.
[6]: set up the password, mute participants to start with, chat with host only (not an option on jitsi), amongst others
None of our extended family c.20 people from teens to elders (c.80yo) needed help - we've been using it daily amongst us since the pandemic broke out.
People who have used Zoom several times still need help; it's more complex (that's good and bad).
EDIT -- I've actually just gone off to try out jitsi again (i do actually check to see if it's worth switching platforms) and it turns out it asks me to install an android app too. So Jit.si itself actually needs me to download software on my smartphone. So......
There are a myriad of things that mean Zoom fits our use case better. I'm not going to enumerate all of them as I'd be here for an hour.
My point was that Zoom fits some use cases better, and that seems to be the case more often than not for users with less technical ability than the HN userbase.
Posted in reply to a child comment earlier ^.
When I originally scoped out which platforms fitted our use case best, it was Jitsi vs. Zoom in the end. This was 3 months ago.
We ended up with Zoom for several reasons specific to our use case.
No software is a magic bullet that solves 100% of use cases. This is why competition exists.
Zoom is a shady company that does crap like secretly install a web server on Macs that allows it to reinstall itself once installed. I refuse to install Zoom on any computer. I installed it on my iPad out of necessity where I know it’s in a strict sandbox.
Edit link:
https://www.zdnet.com/article/zoom-defends-use-of-local-web-...
But if I'd have to pick one I'd guess Google has the best security analysis track record, anti-China fetish which tops the lack of clue what they are doing with their chat or conferencing products.
Versus, say, Google Hangouts Meet, Facebook, Skype, Telegram, WhatsApp etc.?
I presume the same with telegram.
Skype for business has been deprecated by Microsoft in favour of teams. I use it daily and it's just not that great. It requires a Microsoft subscription.
Google hangouts meet only just became available for everyone to use. Before it required a Google business subscription. It makes my CPU usage max out and cooks my laptop.
Zoom works well with 10s of people in a call, it's easy to use. Breakout rooms is a useful feature.
With COVID so many people are using it not because of a marketing campaign but because it's easy to use.
I think it's like asking "why is a an iPhone better than a Blackberry? They both make calls and send email."
But I think Zoom has built their product to not be "enterprise" which in my opinion is a good thing. As that usually means you need to accept jank.
Of course there are security issues with the software as well.
I haven't used jitsi or uberconference. If you have, tell me why they aren't popular?
Do they do anything that Zoom doesn't?
Partly, but they also actively go out of their way to disable security mitigations for reasons that are unclear so I’m not all that surprised. On Linux I think they were one simple buffer overflow away from arbitrary code execution, which is all but asking for an attack if you parse data from the network in an unsafe language.
1. Today zoom links load a webpage that hits a local web server which launches the app (after some delay). There has to be a better way. Why do I need an app at all? Yes I know there is a trick to avoid using/installing the app but it’s not full featured.
2. Fans run on high during a simple video conference and my cpu melts during a screen share. Why is GPU acceleration not a thing here?
None of that happens with google meet for example. Most modern CPUs have hardware support for h264/5 encoding decoding. I shouldn’t need to blow my CPU budget to show a video and play some sounds.
Does it matter? Shoddy code is shoddy code, no matter how many people run it.
A bad program may only run on one person's machine, but if that machine belongs to the Secretary of Defense, it still matters.
I immediately shutoff Kazaa and rethought my approach to secure computing at home
These two only failed because Microsoft deliberately killed them. One of these things I will never understand.
See also: atlassian, oracle, salesforce, zendesk, etc
[0] https://www.nytimes.com/2020/04/20/technology/zoom-security-...
That's what Windows 10x is doing. Performance will most likely take a hit.
Edit:Like 6 months or 2 years :shrug:
1) Zoom client application chat Giphy arbitrary file write
This is not an 'arbitrary file write'. There is virtually no 'arbitrary file write' that doesn't lead to code execution on Windows. The reason is detailed in the report itself:
> The severity of this vulnerability is partially mitigated by the fact that Zoom client will append a string _BigPic.gif to the specified filename. This prevents the attacker from creating a fully controlled file with arbitrary extension.
Nobody is getting hacked by downloading a corrupt .gif file.
2) Zoom Client Application Chat Code Snippet Remote Code Execution Vulnerability
This is not an 'arbitrary file write', as even in the most user input intensive scenario it is restricted. It's not a 'remote code execution', either as they clearly detail in the last paragraph:
> In summary, this vulnerability can be abused in two above outlined scenarios. First, without user interaction, it can be abused to plant arbitrary binaries on target system albeit at a constrained path potentially used in exploiting another vulnerability. Secondly with user interaction, plant binaries at almost arbitrary paths and can potentially overwrite important files and lead to arbitrary code execution.
The report itself does not detail the actual way this reaches remote code execution, saying only:
> This in itself could potentially be abused in leveraging another vulnerability.
However, they could presumably extract the exe to %APPDATA%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup, which would cause remote code execution when the user logs in again. I would be surprised if the reality isn't they tried this and they couldn't do it. I don't understand why they cut this so short.
It's pretty normal for me to be able to drop an .exe in various places. That's what happens when a website triggers a download. The important thing here is the 'execution' of remote code execution, which they have failed to demonstrate.
This is an endless frustration as a vulnerability researcher. Security consultancies, trying to fish for contracts are endlessly willing to misrepresent bugs and security issues they find as much as possible, and there's very little accountability for this.
https://support.zoom.us/hc/en-us/articles/214629443-Zoom-web...
If the Zoom native app's security is a concern for you, the arguably increased security of your browser's environment should help.
If you are a Zoom meeting host, you can save your participants the trouble of the procedure described above by always showing the Join From Browser link:
https://support.zoom.us/hc/en-us/articles/115005666383-Show-...
Another advantage is being able to switch directly to an app instead of remembering which browser instance has which tab.
With Discord specifically I have a weird issue on Linux where my mic works fine in the browser but doesn't work at all in the desktop version.
Second, some browsers allow you to create a window for a website that acts as an app on its own. I don’t remember which ones, I think Chrome was one.
I've written a browser extension to transparently redirect all meeting invites to use their web client:
My intention is only to inform people of an option that is more secure, but one that for whatever reason is obscured by Zoom.
A lot of people don't have a choice but to use Zoom because it is what their meeting host uses.
> Why do I have to complete a CAPTCHA?
> Completing the CAPTCHA proves you are a human and gives you temporary access to the web property.
Okay, but... why do I have to complete a CAPTCHA?
> What can I do to prevent this in the future?
> If you are on a personal connection, like at home, you can run an anti-virus scan on your device to make sure it is not infected with malware.
> If you are at an office or shared network, you can ask the network administrator to run a scan across the network looking for misconfigured or infected devices.
> Another way to prevent getting this page in the future is to use Privacy Pass. You may need to download version 2.0 now from the Firefox Add-ons Store.
How would a virus scan help here? I certainly hope my browser doesn't go around advertising when I last did one of them. And how does Privacy Pass prove I'm human, are robots unable to pretend to be Firefox plus Privacy Pass?
Usually that means that the IP you are connecting from got somehow flagged as an originator of malicious attacks. Like if the virus on your computer does automated requests (click fraud, scraping, DoS,...) to other IPs that are monitored by them.
Of course this is probably mostly useless especially if you are on a dynamic IP but that's where it's coming from.
Giving cloudflare the benefit of the doubt, what could trip this is:
1) the site is getting higher than average visits (tripping the anti-DDoS flag for the CDN)
2) I went without javascript on, so they think I am just a bot.
EDIT: after giving it the benefit of the doubt, the captha didn't work for me at least 4 times. That is unacceptable.
[This is usually done by counting requests/second at the origin then using the CF API to enable the firewall rule or change the security level)
When I checked it on my phone (Android, mobile Firefox with the same add-ons), I was able to go fine.
On my sites I set it to "essentially off", only ips with really bad reputation see the captcha.
> And how does Privacy Pass prove I'm human, are robots unable to pretend to be Firefox plus Privacy Pass?
Privacy pass just like some blockchain tech require to spend some computational resources in order to get tokens. After all CloudFlare goal isn't to block bots as is, but to make DDoS attacks and mass vulneribility scan more expensive.It's intentionally very slow to get and use those token though
If we then say that the captcha you solve can be dynamically adjusted based on how suspicious the request is, then that is a sort of difficulty tuning.
Sure this isn't exactly blockchains or whatever, but it's basically the same idea.
Why would CloudFlare endorse this system if it was just "business as normal but you solve 1/30th of the captchas"?
They don't just endorse it, they developed it. Their argument was that it allowed them to solve the "Tor CAPTCHA problem" (as a Tor user, you see CAPTCHA on almost every page visit to a CloudFlare-fronted site) without breaking the anonymity of Tor users (because CloudFlare is in a position to maliciously track a scary amount of Tor exit traffic).
The idea is that this 1/30 multiplier is meant to reduce the amount of pain Tor users have, without making attackers' jobs easier (a factor of 30 isn't really that much of a change for most attackers and CloudFlare has DDoS protection beyond just CAPTCHA, but it does make a huge difference for normal users).
All of that being said, the Tor project does not endorse the usage of PrivacyPass because they are ethically opposed to the entire concept of having to get a hall pass from CloudFlare to browse large swathes of the internet. And being one of a handful of PrivacyPass users on Tor will reduce your anonymity significantly. The Tor Projecy might also disagree with the privacy claims made by PrivacyPass, but given they are against the very idea of the project I believe they haven't done any actual research into their claims.
This idea is older than blockchains; it's basically hashcash (https://en.wikipedia.org/wiki/Hashcash), which AFAIK was one of the inspirations for Bitcoin.
iOS sandbox is much more powerful thn macOS and the risk is significantly reduced
Basically, the option to join from a browser is only shown once you first signal intent to install the app. This procedure is described in the Zoom docs:
https://support.zoom.us/hc/en-us/articles/214629443-Zoom-web...
The meeting host can also change a setting that allows the Join From Browser link to be displayed without having to go through the procedure above:
https://support.zoom.us/hc/en-us/articles/115005666383-Show-...
However, the ZOOM web client lacks quite a few features, including viewing the video of more than one participant at a time. I believe it's also not possible to share audio. So if you need to do any of these things, you really still have to install the ZOOM client on your computer!
The news of such vulnerabilities probably doesn't even reach them.
I was forced to update to 5.x at one point, so it seems like this is old news.
So progress?
https://www.zdnet.com/article/zoom-defends-use-of-local-web-...
Your link is from 2019. GP is referring to how Zoom has (so far) moved on from those kinds of egregious behaviors, so now in June 2020 we're looking at just regular (non-malicious) code vulnerabilities.
They made business decisions that seemed rational at the time, to grow fast at the expense of good security.
Now they're making business decisions that are rational for the current situation -- they've grown hugely, and now have been fixing their reputation for privacy and security.
Culture has nothing to do with it. It's pure business. I trust their profit motive far more than any "culture". And their profit motive now is: do everything to be a trustworthy product. And their actions over the past couple of months have been demonstrating that.
Do you think it's impossible for companies to change? Because a company makes mistakes, they can't ever be trusted again? That doesn't seem very realistic.
It seems rational to create malware?
At least, if it looks like a vulnerability, they can probably get away with it.