Zoom Structural Vulnerability Discovered

houssem kaabi houssem.kaabi at GMAIL.COM
Thu Jul 11 04:01:49 EEST 2019


Hello everyone,

Indeed  the zoom vulnerability launch a debate about how our privacy is
invaded through solutions that were meant to protect us. The case of Zoom
is not the first proof of that,and this once more, enhance the importance
of the human factor beside technology to build a strong protection system.

I believe that ICANN technical team will find out, along with zoom team , a
patch for the solution, but I also want to highlight the awarness role that
ICANN  should take in order to limit damages.

Security is about human in first place and then iabout organizational
process and means.

Here is a very usefull tips to protect MAC from Zoom Hackers:
https://securingtomorrow.mcafee.com/consumer/consumer-threat-notices/zoom-webcam-vulnerability/



Bests,

--

[image: --]

Houssem Kaabi
[image: http://]about.me/houssem_kaabi/
<http://about.me/houssem_kaabi/>

*My profiles: [image: Facebook] <https://www.facebook.com/hkaabi> [image:
LinkedIn]
<http://www.linkedin.com/profile/view?id=217756984&trk=hb_tab_pro_top>
**[image:
Twitter] <https://twitter.com/houssemkaabi1>*
*Tel: +216 **55 546 264**/ 53 406 429*




*P Respectons ensemble l'environnement. N'imprimez ce message que si
nécessaire. Let's respect the environment together. Only print this message
if necessary.*


Le mar. 9 juil. 2019 à 21:01, Michael Karanicolas <mkaranicolas at gmail.com>
a écrit :

> Hey - remember when ICANN switched everyone from Adobe over to Zoom as a
> way of enhancing information security and data privacy?
>
> "A vulnerability in the Mac Zoom Client allows any malicious website to
> enable your camera without your permission... This vulnerability allows any
> website to forcibly join a user to a Zoom call, with their video camera
> activated, without the user's permission. On top of this, this
> vulnerability would have allowed any webpage to DOS (Denial of Service) a
> Mac by repeatedly joining a user to an invalid call. Additionally, if
> you’ve ever installed the Zoom client and then uninstalled it, you still
> have a localhost web server on your machine that will happily re-install
> the Zoom client for you, without requiring any user interaction on your
> behalf besides visiting a webpage. This re-install ‘feature’ continues to
> work to this day."
>
> Read more here:
> https://medium.com/@jonathan.leitschuh/zoom-zero-day-4-million-webcams-maybe-an-rce-just-get-them-to-visit-your-website-ac75c83f4ef5
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20190711/9abba76a/attachment.htm>


More information about the Ncsg-discuss mailing list