Thursday, January 21, 2021
  • About
  • Advertise
  • Careers
  • Contact
247newscentre
  • Home
  • News
    • World news
    • UK News
    • US News
    • AFRICA
    • WEATHER
  • Politics
  • Business
  • ENTERTAINMENT
  • Lifestyle
    • Diet & Fitness
    • Fashion & Beauty
    • Money
    • Health News
  • Sports
    • Transfer News
    • BOXING
    • F1
    • RUGBY
    • Golf
  • SHOWBIZ &TV
    • Celebrity News
    • Music
    • TV News
No Result
View All Result
247newscentre
Home Cyber Crime and hacking

Shocking Zoom flaw let hackers break into ANY private meeting – even if you had a password

admin by admin
30 July 2020
in Cyber Crime and hacking, Phones & Gadgets, SHOWBIZ &TV, Tech
0
Shocking Zoom flaw let hackers break into ANY private meeting – even if you had a password
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter


A BASIC Zoom flaw could have let hackers break into any private meeting.

Until recently, Zoom only had one million possible passcodes for meetings.

Hackers could have targeted your private meeting

2

Hackers could have targeted your private meetingCredit: Alamy

This may seem like a large number but it could have let cybercriminals guess a correct passcode within minutes.

The flaw was spotted by Tom Anthony from SEO firm SearchPilot.

Zoom had no limit to the amount of times you could try and log in to a meeting, meaning multiple passwords could be tried.

Anthony wrote on his blog: “Zoom meetings were default protected by a 6 digit numeric password, meaning 1 million maximum passwords.

Zoom has now fixed the flaw

2

Zoom has now fixed the flawCredit: Getty Images – Getty

“I discovered a vulnerability in the Zoom web client that allowed checking if a password is correct for a meeting, due to broken CSRF and no rate limiting.

“This enabled an attacker to attempt all 1 million passwords in a matter of minutes and gain access to other people’s private (password protected) Zoom meetings.

“This also raises the troubling question as to whether others were potentially already using this vulnerability to listen in to other people’s calls (e.g. the UK Cabinet Meeting!).”

Hackers can use something called a Python program to try a huge number of passwords in minutes.

Batch-scheduled meetings set at regular intervals were particularly vulnerable to this as the same passcode can be used for all of them.

Fortunately, the flaw has been patched.

Anthony wrote: “I reported the issue to Zoom, who quickly took the web client offline to fix the problem.

“They seem to have mitigated it by both requiring a user logs in to join meetings in the web client, and updating default meeting passwords to be non-numeric and longer. Therefore this attack no longer works.”

The problem was revealed to Zoom on April 1, which led to a one week outage for it to be fixed.

Zoom passwords now need to be longer and contain non-numerical characters.

Zoom explained in a statement: “We have since improved rate limiting and relaunched the web client on April 9.

“With these fixes, the issue was fully resolved, and no user action was required. We are not aware of any instances of this exploit being used in the wild.”

However, Anthony noted that a hacker may have infiltrated a meeting without the other participants noticing by using a generic ID like “iPhone” or “Home PC”.

What is Zoom?

  • Popular chat app Zoom is best-known for offering video calls – including calls with huge numbers of people
  • There’s a free tier with unlimited meetings, but these group chats are capped at 40 minutes
  • The most expensive tier gets you meetings with up to 1,000 participants, but there are cheaper options
  • Perhaps the only downside is that Zoom has had privacy issues in the past, which may put some businesses off
  • Signing up to Zoom is free and easy
  • You just need a valid email address, and the willingness to accept Zoom’s privacy policy and terms – which are fairly standard
  • Anyone can sign up to Zoom by download the app, or heading to the official website

ROCK AND A HARD PLACE

Mystery of where giant Stonehenge rocks came from finally SOLVED

Live Blog

OUT OF THIS WORLD

Nasa launches mission to Mars carrying robot to hunt for alien life

INCEPTION!

You can choose your DREAMS with new ‘brain manipulator’ Dormio device

GAL-HALLA

Face of 1,000-year-old Viking warrior woman with gruesome battle wound revealed

Warning

PET HATE

How TikTok has become a hotbed of animal cruelty as thugs PUNCH helpless dogs

BONE BEATS

Apple reveals concept AirPods that ‘vibrate music through your skull’

In other news, Android users are being warned about 29 malicious apps that have been downloaded by millions.

Netflix lovers are being warned about a new email scam claiming to offer a year’s free subscription to the service.

And, Garmin is back online after being targeted by hackers.

Have you experienced any problems with Zoom? Let us know in the comments…

We pay for your stories! Do you have a story for The Sun Online Tech & Science team? Email us at tech@the-sun.co.uk

Related posts

London Marathon planning for world-record 100,000 runners in October

London Marathon planning for world-record 100,000 runners in October

21 January 2021
3pm Arsenal transfer news LIVE: Smith Rowe NEW DEAL, Ozil set for Fenerbache wage cut, Odegaard LATEST

3pm Arsenal transfer news LIVE: Smith Rowe NEW DEAL, Ozil set for Fenerbache wage cut, Odegaard LATEST

21 January 2021



Source link

Previous Post

Man Utd news: Dortmund chief makes fresh Jadon Sancho comment after £60m agreement | Football | Sport

Next Post

BBC Breakfast host Charlie Stayt slammed for 'car crash' Matt Hancock interview

Next Post
BBC Breakfast host Charlie Stayt slammed for 'car crash' Matt Hancock interview

BBC Breakfast host Charlie Stayt slammed for 'car crash' Matt Hancock interview

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

RECOMMENDED NEWS

EU snub: Iceland opened door to special fishing partnership for Brexit Britain | UK | News

EU snub: Iceland opened door to special fishing partnership for Brexit Britain | UK | News

2 months ago
Britain’s biggest family get into festive spirit with pumpkin carving night

Britain’s biggest family get into festive spirit with pumpkin carving night

3 months ago
Neymar’s sensational world record Puma boot deal worth £23m a year moves him ahead of Ronaldo and Messi

Neymar’s sensational world record Puma boot deal worth £23m a year moves him ahead of Ronaldo and Messi

4 months ago
Coutinho for Guendouzi SWAP, Willian LATEST, Ozil OUT of FA Cup final, Balogun linked – The Sun

Coutinho for Guendouzi SWAP, Willian LATEST, Ozil OUT of FA Cup final, Balogun linked – The Sun

6 months ago

FOLLOW US

  • 79 Followers
  • 43k Followers
  • 93.2k Subscribers

BROWSE BY CATEGORIES

BROWSE BY TOPICS

2018 League Balinese Culture Bali United Budget Travel Champions League Chopper Bike Doctor Terawan Istana Negara Market Stories National Exam Visit Bali

POPULAR NEWS

  • Bryson DeChambeau reveals 3500-calorie-a-day diet including SEVEN protein shakes which saw him pack on 3 stone of muscle – The Sun

    Bryson DeChambeau reveals 3500-calorie-a-day diet including SEVEN protein shakes which saw him pack on 3 stone of muscle – The Sun

    0 shares
    Share 0 Tweet 0
  • Who is the traitor in Assassin’s Creed Valhalla?

    0 shares
    Share 0 Tweet 0
  • Ozo emerges new Head of House

    0 shares
    Share 0 Tweet 0
Athletics

London Marathon planning for world-record 100,000 runners in October

LONDON MARATHON bosses plan to host the biggest event of its kind in the world – with 100,000 runners on Sunday October 3. ...

21 January 2021
HOME

Struggling mums ‘irresponsible’ for having kids they can’t afford, says Olympic champ – World News

An Olympic champion has slammed struggling mums for having children they can't afford - branding them "irresponsible". Karolina Sevastyanova, ...

21 January 2021
AFRICA

Buhari will be held squarely responsible if… ― SMBLF

Southern and Middle-Belt Leaders Forum (SMBLF) has called on the Federal Government to withdraw its overt support for Miyetti ...

21 January 2021
Business

Eriksen ‘loan bid’ eyed, Sancho could join THIS month, Sergio Ramos ‘contact’

OVER TO BRU Paul Pogba has proved he can play alongside Bruno Fernandes in the midfield, claimed Rio Ferdinand. ...

21 January 2021
Arsenal email

3pm Arsenal transfer news LIVE: Smith Rowe NEW DEAL, Ozil set for Fenerbache wage cut, Odegaard LATEST

MESUT OZIL is taking a huge wage cut as he prepares to join Turkish side Fenerbache. Meanwhile, Emile Smith ...

21 January 2021
247newscentre

We bring you the Latest News around the World.

Follow us on social media:

Recent News

  • London Marathon planning for world-record 100,000 runners in October
  • Struggling mums ‘irresponsible’ for having kids they can’t afford, says Olympic champ – World News
  • Buhari will be held squarely responsible if… ― SMBLF

Category

Recent News

London Marathon planning for world-record 100,000 runners in October

London Marathon planning for world-record 100,000 runners in October

21 January 2021
Struggling mums ‘irresponsible’ for having kids they can’t afford, says Olympic champ – World News

Struggling mums ‘irresponsible’ for having kids they can’t afford, says Olympic champ – World News

21 January 2021
  • About
  • Advertise
  • Careers
  • Contact

Copyright © 2020 247NewsCentre. All rights reserved.

No Result
View All Result
  • Home
  • Politics
  • News
  • Business
  • SHOWBIZ &TV
  • National
  • Sports
  • Lifestyle
  • Travel
  • ENTERTAINMENT

Copyright © 2020 247NewsCentre. All rights reserved.

Login to your account below

Forgotten Password?

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In