Eblogtip.com
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions

Archives

  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • December 2022

Categories

  • News
  • Technology
  • Uncategorized
eBlogTip
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions
  • News

Hackers could be eavesdropping on your Zoom calls thanks to this flaw

  • August 14, 2023
Total
0
Shares
0
0
0


Researchers have discovered a flaw in Zoom and AudioCodes products which could allow threat actors to listen in on video conferencing calls, hijack vulnerable endpoints, and even deliver more devastating malware such as infostealers or ransomware.

Security expert Moritz Abrell from SySS was the one who found flaws in AudioCodes desk phones and Zoom’s Zero Touch Provisioning (ZTP) features, which allows admins to configure VoIP devices in a centralized manner. 

The provisioning process was flawed, though – so when the tool tries to grab configuration files from the ZTP service, it does so without any client-side authentication mechanism, which the attackers could abuse to drop malware from a rogue server.

Taking over devices

Furthermore, there was another improper authentication issue, this time in the cryptographic routines in AudioCodes’ VoIP desk phones, which crooks could use to decrypt sensitive information. Combine these two flaws, and you get an exploit chain that grants attackers full access to the vulnerable devices. 

“When combined, these vulnerabilities can be used to remotely take over arbitrary devices. As this attack is highly scalable, it poses a significant security risk,” Abrell said.

Three years ago, at the early days of the Covid-19 pandemic, Zoom was one of the most-used applications out there, resulting in an enormous spike in popularity. As a result, hackers dug deep into the program’s code, finding flaw after flaw. At one point it had gotten so bad that the company halted all production and focused solely on boosting the security of its services.

Since then, Zoom plugged numerous holes, other communication and collaboration tools (such as Teams, for example) took some of the load off Zoom, and many firms had their employees return to the office.

Via: The Hacker News


Source link

Total
0
Shares
Share 0
Tweet 0
Pin it 0
Previous Article
  • News

Mounting reports of iPhone 14 battery issues threaten to spoil Apple’s iPhone 15 launch party

  • August 14, 2023
View Post
Next Article
  • Technology

Researcher says they were behind iPhone popups at Def Con

  • August 14, 2023
View Post
You May Also Like
View Post
  • News

Bad news – turns out even long passwords can be cracked easily

  • September 30, 2023
View Post
  • News

AMD has a new trick to make games run smoother – but only for RX 7000 GPUs

  • September 30, 2023
View Post
  • News

Ukraine’s War of Drones Runs Into an Obstacle: China

  • September 30, 2023
View Post
  • News

ICYMI: the 7 biggest tech stories of the week, from Meta Quest 3 to Raspberry Pi 5

  • September 30, 2023
View Post
  • News

A Windows 11 PC that’s smaller and lighter than the iPhone 15 Pro has been tested — just wait till someone hacks it into a Windows smartphone

  • September 30, 2023
View Post
  • News

Researchers find a way to make photos and muted videos ‘speak’ – here’s what it could mean for your privacy

  • September 30, 2023
View Post
  • News

Quordle today – hints and answers for Saturday, September 30 (game #614)

  • September 29, 2023
View Post
  • News

iCloud gets a makeover with a revamped look and quality-of-life upgrades

  • September 29, 2023

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

eBlogTip.com
  • Categories

Input your search keywords and press Enter.