Zoom,Triple Play episode 5 season 1 - Joe and Mandi the videoconferencing software that's skyrocketed in popularity as much of the globe sits at home due to the coronavirus outbreak, is quickly turning into a privacy and security nightmare.
BleepingComputer reports about a newly found vulnerability in Zoom that allows an attacker to steal Windows login credentials from other users. The problem lies with the way Zoom's chat handles links, as it converts Windows networking UNC (Universal Naming Convention) paths into clickable links. If a user clicks on such a link, Windows will leak the user's Windows login name and password.
The good thing is that the password is hashed; but the bad thing is that it is in many cases simple to reveal it using password recovery tools such as Hashcat.
The vulnerability was first found by security researcher @_g0dmode and verified by security researcher Matthew Hickey. Additionally, Hickey told the news outlet that this vulnerability can be used to launch programs on a victim's computer when they click on a link, though Windows will (by default) at least give a security warning before launching the program.
As far as security vulnerabilities go, this one is pretty bad, as it doesn't require a lot of knowledge to exploit. It does require the victim to actually click on a link, and it can be mitigated by tinkering with Windows' security settings, but it's definitely something Zoom should fix by changing the way the platform's chat handles UNC links.
In the meantime, for a quick fix, go to Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> Network security: Restrict NTLM: Outgoing NTLM traffic to remote servers and set to "Deny all".
Mashable has contacted Zoom for comment on this story, and we'll update it when we hear back.
SEE ALSO: Zoom's iOS app no longer sends data to FacebookThis is not the only privacy/security-related issue that has been unearthed at Zoom in the past couple of weeks. Just yesterday, The Intercept reported that Zoom doesn't actually use an end-to-end encrypted connection for its calls, despite claiming to do so. There's also the issue of leaking users' emails and photos to unrelated parties, and the fact that the company's iOS app, until recently, sent data to Facebook for no good reason.
Zoom software also has a couple of worrying privacy features, and although this isn't Zoom's fault, it's worth noting that hackers are using the app's newfound popularity to trick users into downloading malware.
Topics Cybersecurity
Inside the viral collab house featuring OnlyFans and TikTok creatorsLorin Stein in Conversation with Donald Antrim and Ben LernerJava Jive by Sadie SteinKids Tossing Guns, Phenomenal HardYour time management won't work until you realize how little time you haveNintendo announces 'Super Mario Bros. Wonder' Direct livestreamThe Morning News Roundup for October 3, 2014Super blue moon: When and how to see itDevastatingly, Dolly Parton is not on TikTokInside the viral collab house featuring OnlyFans and TikTok creatorsElon Musk says audio and video calls are coming to Twitter/XBest software deal: Adobe Photoshop and Premiere Elements 2023 on sale for 37% offAmazon comes hard for Apple Fitness+ with Halo FitnessHints for Hosts by Sadie SteinThe Morning News Roundup for October 2, 2014The Notion of Family21 best crime documentaries on Netflix in 2023Nevermore by Sadie SteinSecret Nerdery: Warhammer 40,000Devastatingly, Dolly Parton is not on TikTok Writers’ Fridges: Walter Mosley V. S. Naipaul, the Man Versus the Work Redux: If You Can Hoe Corn for Fifty Cents an Hour … by The Paris Review Ugliness Is Underrated: Ugly Design by Katy Kelleher Staff Picks: Butt Fumbles, Bounty Hunters, and Black Dashiell Hammett's Strange Career by Anne Diebel The Sad Boys of Sadcore by Kristi Coulter The Surprising Story of Eartha Kitt in Istanbul by Hilal Isler Poetry Rx: Nevertheless, Live by Claire Schwartz Mermaids and Transgressive Sex: An Interview with Alexia Arthurs Alain Mabanckou’s Masterfully Unstructured Novel of Addiction by Uzodinma Iweala An Incomplete Biography of Marcel Proust by Liana Finck Ugliness Is Underrated: In Defense of Ugly Paintings Joan Morgan, Hip The Silence of Sexual Assault in Literature by Idra Novey Always a Tough Guy at Heart by Tadao Tsuge The Answers Are Not Important: An Interview With Catherine Lacey Satirizing Identity Politics: An Interview with Lexi Freiman Redux: Brooklyn Crossing by The Paris Review Staff Picks: Film Forum, Fallout Shelters, and Fermentation
2.0649s , 10108.7421875 kb
Copyright © 2025 Powered by 【Triple Play episode 5 season 1 - Joe and Mandi】,Pursuit Information Network