ZOOM Vanity URL°²È«·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-07-21

0x00 ·ì϶¸ÅÊö


CVE   ID

ÔÝÎÞ

ʱ    ¼ä

2020-07-21

Àà   ÐÍ

µÈ    ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò


0x01 ·ì϶ÏêÇé


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ëæ×ÅCOVID-19µÄ·¢Õ¹£¬Ô½À´Ô½¶àµÄ¹«Ë¾¡¢µ±¾ÖºÍѧÌÃѡȡԶ³Ì°ì¹«£¬ZoomµÄʹÓÃÁ¿´Ó2019Äê12ÔÂÿÌì1000ÍòµÄ»áÒé²Î¼ÓÕßÃÍÔöµ½2020Äê4ÔÂÿÌì3Òڶ࣬Ô̺¬¡°Zoom¡±µÄÐÂÓòÃûµÄ×¢²áÁ¿Ò²±¬Õ¨ÐÔÔö³¤£¬ÕâÅú×¢¹¥»÷Õß½«ZoomÓòÃû×÷Ϊµö¶üÀ´ÓÕÆ­Êܺ¦Õߣ¬Í¬Ê±»¹³öÏÖÁ˼ÙÒâZoom×°Ö÷¨Ê½µÄ¶ñÒâÈí¼þ ¡£

½üÈÕ£¬Check PointµÄ×êÑÐÈËÔ±ÔÚZoom Vanity URLÖз¢ÏÖÁËÒ»¸ö·ì϶£¬¹«Ë¾Äܹ»Ê¹ÓÃVanity URL´´½¨ZoomÔ¼ÇëÁ´½ÓµÄ×Ô½ç˵°æ±¾£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶½øÐÐÍøÂç´¹µö¹¥»÷ ¡£

×êÑÐÈËÔ±°µÊ¾£¬URLÏÖʵÉÏÖ¸Ïò¹¥»÷Õß×¢²áµÄ×ÓÓò£¬¹¥»÷ÕßÖ¼ÔÚÓÕʹÊܺ¦ÕßÌá½»Ó×ÎÒÍ´´¦»òÆäËûÃô¸ÐÐÅÏ¢ ¡£ÓÐÁ½ÖÖ²½ÖèÄܹ»½øÈë»áÒ飬»áÒéID»òͨ¹ý¹«Ë¾×Ô½ç˵Web½çÃæ£¬Á½ÖÖ¹¥»÷·½Ê½ÈçÏ£º

ͨ¹ý»áÒéID¹¥»÷£º

? ¸ü¸ÄÔ¼ÇëURL£¬ÀýÈçhttps://zoom.us/j/###########£¬¸Ä³Éhttps://<¹«Ë¾Ãû³Æ> .zoom.us/j/########### £»

? ´Ë±í£¬»¹Äܹ»½«Á´½Ó´Ó/j/¸ü¸ÄΪ/s/£¬https://<¹«Ë¾Ãû³Æ>.Zoom.us/s/7470812100 ¡£

ͨ¹ýZoom Web½çÃæ¹¥»÷£º

ÁíÒ»ÖÖ²½ÖèÊÇʹÓù«Ë¾×¨ÓÃ×ÓÓòWeb UI£¬ÈçͼËùʾ£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



µ±Óû§½øÈëÍøÕ¾²¢µ¥»÷¡°Join¡±°´Å¥Ê±£¬½«ÏÔʾÒÔÏÂÆÁÄ»£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



Óû§ÔÚ´ËÊäÈë»áÒéID²¢²ÎÓëZoom»á»° ¡£¹¥»÷ÕßÄܹ»Í¨¹ýÚ¿Æ­ÍøÕ¾ÓÕʹÊܺ¦Õß²ÎÓë»á»°£¬µ«Êܺ¦Õß²¢²»ÖªÂ·¸ÃÔ¼ÇëÊÇ·ñÀ´×ԺϷ¨ÒªÇó ¡£


0x02 ´ëÖý¨Òé


Ŀǰ³§ÉÌÒѰ䲼²¹¶¡£¬ÏÂÔØÁ´½Ó£º

https://zoom.us/


0x03 ÓйØÐÂÎÅ


https://securityaffairs.co/wordpress/106120/hacking/zooms-vanity-url-flaw.html?utm_source=rss&utm_medium=rss&utm_campaign=zooms-vanity-url-flaw


0x04 ²Î¿¼Á´½Ó


https://blog.checkpoint.com/2020/07/16/fixing-the-zoom-vanity-clause-check-point-and-zoom-collaborate-to-fix-vanity-url-issue/


0x05 ¹¦·òÏß


2020-07-21 VSRC°ä²¼·ì϶¹«¸æ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾