Author Topic: Zoom Client Leaks Windows Login  (Read 20157 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: Zoom Client Leaks Windows Login
« Reply #45 on: July 21, 2020, 11:45:08 PM »
Hi bob3160,

That latest Zoom fix was for users still on Win7.
When you are still out on Win7 you have a somewhat larger problem just with that issue i.m.h.o.  :(

Most users that endanger the Interwebz' infrastructures nowadays as always are folks that do not patch,
upgrade and update. We cannot stress that message often enough.

Let this sink in, keep your code cycles updated and fully patched, my good friends.
It's not only you that suffer but it is also you endangering others through causing such a boogaloo.

polonus

Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48552
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Zoom Client Leaks Windows Login
« Reply #46 on: July 21, 2020, 11:46:15 PM »
Hi Bob, how are you ?

I was just mentioning a ( smart ) alternative.

Greetz, Red.
It is an alternative as are many others. If you use this type of program very frequently, you learn very quickly that
the overall best platform for remote presentations is still ZOOM.
ZOOM has also been very quick to address any security concerns that were raised.
It is because they quickly address any security concerns, I questioned the date of this report.
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48552
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Zoom Client Leaks Windows Login
« Reply #47 on: July 21, 2020, 11:49:44 PM »
Hi bob3160,

That latest Zoom fix was for users still on Win7.
When you are still out on Win7 you have a somewhat larger problem just with that issue i.m.h.o.  :(

Most users that endanger the Interwebz' infrastructures nowadays as always are folks that do not patch,
upgrade and update. We cannot stress that message often enough.

Let this sink in, keep your code cycles updated and fully patched, my good friends.
It's not only you that suffer but it is also you endangering others through causing such a boogaloo.

polonus
Any time you use outdated software which includes your operating system, you put your security at a potential risk.
It was also the users sloppy way of handling invitations that originally cause ZOOM to tighten up and prevent user stupidity.
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: Zoom Client Leaks Windows Login
« Reply #48 on: July 23, 2020, 04:11:04 PM »
But why there wasn't still a reply to this open letter sent by media watchdogs?
Re: https://ico.org.uk/media/about-the-ico/documents/2618022/vtc-open-letter-20200721.pdf

There were contacts before with development teams, so why the hesitation?

polonus




Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89033
  • No support PMs thanks
Re: Zoom Client Leaks Windows Login
« Reply #49 on: July 23, 2020, 05:36:59 PM »
Personally I thought the letter pretentious, self serving and why send as an Open Letter.  To my mind you reply to an Open letter in the Open.  But when talking of security/privacy no one would/should do this.

Why hasn't there been a response, why would they and how would you know they haven't as there is no reference about replies.  Also when you consider the last paragraph, responses by 30 September 2020 and we are only in July 2020.  I also don't see anything giving a location to respond.

Quote from: extract of letter
We welcome responses to this open letter from VTC companies, by 30 September 2020, to demonstrate how they are taking these principles into account in the design and delivery of their services. Responses will be shared amongst the joint signatories to this letter.

Highlighting is mine.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Zoom Client Leaks Windows Login
« Reply #50 on: July 30, 2020, 09:31:56 AM »
Zoom Security Exploit – Cracking private meeting passwords
https://www.tomanthony.co.uk/blog/zoom-security-exploit-crack-private-meeting-passwords/
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89033
  • No support PMs thanks
Re: Zoom Client Leaks Windows Login
« Reply #51 on: July 30, 2020, 11:22:54 AM »
Zoom Security Exploit – Cracking private meeting passwords
https://www.tomanthony.co.uk/blog/zoom-security-exploit-crack-private-meeting-passwords/

Quote from: Extract - Very Short Version.
I reported the issue to Zoom, who quickly took the web client offline to fix the problem. They seem to have mitigated it by both requiring a user logs in to join meetings in the web client, and updating default meeting passwords to be non-numeric and longer. Therefore this attack no longer works.

So the long and 'Short' of it (excuse the terrible pun) is this is no longer an issue, until the next one comes along.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48552
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Zoom Client Leaks Windows Login
« Reply #52 on: July 30, 2020, 02:32:44 PM »
Zoom Security Exploit – Cracking private meeting passwords
https://www.tomanthony.co.uk/blog/zoom-security-exploit-crack-private-meeting-passwords/
This is also old news. This security issue was addressed month ago.
Security news is important but, it should also be relevant.
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Zoom Client Leaks Windows Login
« Reply #53 on: July 30, 2020, 03:10:12 PM »
Zoom Security Exploit – Cracking private meeting passwords
https://www.tomanthony.co.uk/blog/zoom-security-exploit-crack-private-meeting-passwords/
This is also old news. This security issue was addressed month ago.
Security news is important but, it should also be relevant.
Check the article, it clearly says "29th July – Disclosure", so not possible to post it earlier.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48552
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Zoom Client Leaks Windows Login
« Reply #54 on: July 30, 2020, 03:17:06 PM »
Zoom Security Exploit – Cracking private meeting passwords
https://www.tomanthony.co.uk/blog/zoom-security-exploit-crack-private-meeting-passwords/
This is also old news. This security issue was addressed month ago.
Security news is important but, it should also be relevant.
Check the article, it clearly says "29th July – Disclosure", so not possible to post it earlier.
It is still old information. This was fixed  months ago.
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Zoom Client Leaks Windows Login
« Reply #55 on: July 30, 2020, 03:19:32 PM »
Zoom Security Exploit – Cracking private meeting passwords
https://www.tomanthony.co.uk/blog/zoom-security-exploit-crack-private-meeting-passwords/
This is also old news. This security issue was addressed month ago.
Security news is important but, it should also be relevant.
Check the article, it clearly says "29th July – Disclosure", so not possible to post it earlier.
It is still old information. This was fixed  months ago.
If you're not interested, just skip it.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48552
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Zoom Client Leaks Windows Login
« Reply #56 on: July 30, 2020, 03:51:27 PM »
Zoom Security Exploit – Cracking private meeting passwords
https://www.tomanthony.co.uk/blog/zoom-security-exploit-crack-private-meeting-passwords/
This is also old news. This security issue was addressed month ago.
Security news is important but, it should also be relevant.
Check the article, it clearly says "29th July – Disclosure", so not possible to post it earlier.
It is still old information. This was fixed  months ago.
If you're not interested, just skip it.
That isn't the point. If it's old and fixed, there isn't any reason to post it is there?
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Zoom Client Leaks Windows Login
« Reply #57 on: July 30, 2020, 04:05:51 PM »
Zoom Security Exploit – Cracking private meeting passwords
https://www.tomanthony.co.uk/blog/zoom-security-exploit-crack-private-meeting-passwords/
This is also old news. This security issue was addressed month ago.
Security news is important but, it should also be relevant.
Check the article, it clearly says "29th July – Disclosure", so not possible to post it earlier.
It is still old information. This was fixed  months ago.
If you're not interested, just skip it.
That isn't the point. If it's old and fixed, there isn't any reason to post it is there?
IMO, yes.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48552
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Zoom Client Leaks Windows Login
« Reply #58 on: July 30, 2020, 04:15:27 PM »
Just to increase the post count? It certainly doesn't pass along anything important.
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Zoom Client Leaks Windows Login
« Reply #59 on: July 30, 2020, 04:22:49 PM »
Just to increase the post count? It certainly doesn't pass along anything important.
Nothing to gain in increasing my post count. Users have the right and should know about issues/bugs even after they're fixed. That's basically the same Microsoft does on patch day. Further, it's interesting to see how a company deals with such reports.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0