Author Topic: Zoom Client Leaks Windows Login  (Read 3235 times)

0 Members and 1 Guest are viewing this topic.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 64658
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Zoom Client Leaks Windows Login
« Reply #15 on: April 10, 2020, 07:27:09 AM »
Win 8.1 [x64] - Avast PremSec 20.4.2408.B#3 [UI.520] - CC 5.65 - EEK - FF ESR 68.8 [NS/AOS/uBO/PB] - TB 68.8.1 - ASB/ACP/ASL.BC
Deutschsprachiger Bereich -> Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 32430
  • malware fighter
Re: Zoom Client Leaks Windows Login
« Reply #16 on: April 10, 2020, 12:43:12 PM »
It is not only Google to ban Zoom, also governments like Taiwan, Germany and American senators:
https://www.ft.com/content/dac7d60b-54fa-402b-8469-70f85aaace76

Encryption keys of non-Chinese user have been sent to Chinese servers. Do we want that?
Using Chinese made devices you do that everyday, remember.

My only hope is that China stays part of our Globe and they will send us loads of good "chi".

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Online bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 43557
  • 60 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Zoom Client Leaks Windows Login
« Reply #17 on: April 10, 2020, 02:17:54 PM »
It is not only Google to ban Zoom, also governments like Taiwan, Germany and American senators:
https://www.ft.com/content/dac7d60b-54fa-402b-8469-70f85aaace76

Encryption keys of non-Chinese user have been sent to Chinese servers. Do we want that?
Using Chinese made devices you do that everyday, remember.

My only hope is that China stays part of our Globe and they will send us loads of good "chi".

polonus
To read the article, you need to sign up. Not about to happen any time soon. :)
Free avast! Security Seminar: http://bit.ly/2N1eaR2  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 10 Pro v1909 64bit, 24 Gig Ram, 1TB SSD, AvastOmni 20.3.xxx, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 64658
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Zoom Client Leaks Windows Login
« Reply #18 on: April 14, 2020, 01:26:50 PM »
Win 8.1 [x64] - Avast PremSec 20.4.2408.B#3 [UI.520] - CC 5.65 - EEK - FF ESR 68.8 [NS/AOS/uBO/PB] - TB 68.8.1 - ASB/ACP/ASL.BC
Deutschsprachiger Bereich -> Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Online bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 43557
  • 60 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Zoom Client Leaks Windows Login
« Reply #19 on: April 14, 2020, 03:48:05 PM »
Why do we have so many topics with the same information?
It makes replying extremely difficult and confusing.
Free avast! Security Seminar: http://bit.ly/2N1eaR2  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 10 Pro v1909 64bit, 24 Gig Ram, 1TB SSD, AvastOmni 20.3.xxx, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq

Offline SpeedyPC

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3279
  • Avast shall conquer the whole world
Re: Zoom Client Leaks Windows Login
« Reply #20 on: April 15, 2020, 12:56:26 PM »
Why do we have so many topics with the same information?
It makes replying extremely difficult and confusing.


P.E.B.K.A.C!!!!  8) :-X
« Last Edit: April 15, 2020, 01:01:34 PM by SpeedyPC »
ASUS G75VX-T4153H - Avast Premier v20.1.2397 - W8.1 64bit - Avast SecureLine VPN - Avast Secure Browser - Firefox 64bit - Thunderbird 64bit - MBAM Premium - Adguard Premium - CryptoPrevent Premium - Privacy Eraser - MCShield - WinPatrol PLUS - Macrium Reflect Home Edition

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 36619
Re: Zoom Client Leaks Windows Login
« Reply #21 on: April 15, 2020, 08:19:55 PM »

Online bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 43557
  • 60 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Zoom Client Leaks Windows Login
« Reply #22 on: April 15, 2020, 08:25:46 PM »
Zoomed In: A Look into a Coinminer Bundled with Zoom Installer
https://blog.trendmicro.com/trendlabs-security-intelligence/zoomed-in-a-look-into-a-coinminer-bundled-with-zoom-installer/
Old news and easily avoidable by downloading the product from the source instead of third party sites.
Free avast! Security Seminar: http://bit.ly/2N1eaR2  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 10 Pro v1909 64bit, 24 Gig Ram, 1TB SSD, AvastOmni 20.3.xxx, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 64658
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Zoom Client Leaks Windows Login
« Reply #23 on: April 17, 2020, 11:11:03 AM »
Win 8.1 [x64] - Avast PremSec 20.4.2408.B#3 [UI.520] - CC 5.65 - EEK - FF ESR 68.8 [NS/AOS/uBO/PB] - TB 68.8.1 - ASB/ACP/ASL.BC
Deutschsprachiger Bereich -> Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Online bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 43557
  • 60 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Zoom Client Leaks Windows Login
« Reply #24 on: April 17, 2020, 03:01:35 PM »
Hackers Are Selling a Critical Zoom Zero-Day Exploit for $500,000
https://www.vice.com/en_us/article/qjdqgv/hackers-selling-critical-zoom-zero-day-exploit-for-500000
Sorry Asyn but I hate these one liners. Headlines are always designed to peak your interest and never give a true picture.
“Zoom takes user security extremely seriously. Since learning of these rumors, we have been working around the clock with a reputable,
industry-leading security firm to investigate them,” the company said in a statement. “To date, we have not found any evidence substantiating these claims.”
Free avast! Security Seminar: http://bit.ly/2N1eaR2  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 10 Pro v1909 64bit, 24 Gig Ram, 1TB SSD, AvastOmni 20.3.xxx, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 64658
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Zoom Client Leaks Windows Login
« Reply #25 on: April 17, 2020, 03:55:41 PM »
Zoom Endpoint-Security Considerations
https://dev.io/posts/zoomzoo/
Win 8.1 [x64] - Avast PremSec 20.4.2408.B#3 [UI.520] - CC 5.65 - EEK - FF ESR 68.8 [NS/AOS/uBO/PB] - TB 68.8.1 - ASB/ACP/ASL.BC
Deutschsprachiger Bereich -> Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Q-Dawg

  • Newbie
  • *
  • Posts: 1
Re: Zoom Client Leaks Windows Login
« Reply #26 on: May 04, 2020, 06:22:03 PM »
SO I had read this previously, but someone had linked this when I asked a related questions elsewhere.

I am working for an organisation that uses Zoom extensively for meetings with people exterior to our organisation. We had just been given the notification to update to their latest 5.0 version with their new security features installed and when I went to do that, I got a notification that this was a PHISHING threat, but none of my coworkers got it. Now, my coworkers are likely using Malwarebytes and I am using Avast on my home PC, but I wondered if anyone could talk me through what to do here like I am a five year old?

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 83011
  • No support PMs thanks
Re: Zoom Client Leaks Windows Login
« Reply #27 on: May 04, 2020, 07:04:15 PM »
SO I had read this previously, but someone had linked this when I asked a related questions elsewhere.

I am working for an organisation that uses Zoom extensively for meetings with people exterior to our organisation. We had just been given the notification to update to their latest 5.0 version with their new security features installed and when I went to do that, I got a notification that this was a PHISHING threat, but none of my coworkers got it. Now, my coworkers are likely using Malwarebytes and I am using Avast on my home PC, but I wondered if anyone could talk me through what to do here like I am a five year old?

An attached avast alert screenshot and or the location (or how you got there) you downloaded it from might have helped.  The (URL) PHISHING is normally site based rather than file based.

I just downloaded the Zoom Client (though I don't use it) ZoomInstaller.exe Version 5.0.1 (23502.0430) from the zoom.us/download location (that however does redirect to another location, see attached image, click to expand) and no alerts. 

So as you can see what you download and from where is important.
WinXP ProSP3/ Core2Duo E8300/ 4GB Ram/ avast! free 18.5.2342/ Firefox ESR, uBlock Origin, uMatrix/ MailWasher Pro7.11.0/ DropMyRights/ WinPatrol+/ Drive Image 7.1/ SnagIt 10.0/ avast! mobile security
Windows 10 Home 1909 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 20.2.2401 (build 20.2.5130.570) UI-1.0.505/ WinPatrol+/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 32430
  • malware fighter
Re: Zoom Client Leaks Windows Login
« Reply #28 on: May 08, 2020, 02:29:43 PM »
Again USA warns against the use of Zoom, because of APT-attacks:
https://publicintelligence.net/dhs-zoom-threats/

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Online bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 43557
  • 60 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Zoom Client Leaks Windows Login
« Reply #29 on: May 08, 2020, 03:03:26 PM »
Again USA warns against the use of Zoom, because of APT-attacks:
https://publicintelligence.net/dhs-zoom-threats/

pol
This looks like it describes old vulnerabilities that were address
by ZOOM in the update released on May 3.
Free avast! Security Seminar: http://bit.ly/2N1eaR2  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 10 Pro v1909 64bit, 24 Gig Ram, 1TB SSD, AvastOmni 20.3.xxx, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq