ZOOM Vanity URL°²È«·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-07-210x00 ·ì϶¸ÅÊö
|
CVE ID |
ÔÝÎÞ |
ʱ ¼ä |
2020-07-21 |
|
Àà ÐÍ |
|
µÈ ¼¶ |
¸ßΣ |
|
Ô¶³ÌÀûÓà |
ÊÇ |
Ó°ÏìÁìÓò |
|
0x01 ·ì϶ÏêÇé
Ëæ×ÅCOVID-19µÄ·¢Õ¹£¬Ô½À´Ô½¶àµÄ¹«Ë¾¡¢µ±¾ÖºÍѧÌÃѡȡԶ³Ì°ì¹«£¬ZoomµÄʹÓÃÁ¿´Ó2019Äê12ÔÂÿÌì1000ÍòµÄ»áÒé²Î¼ÓÕßÃÍÔöµ½2020Äê4ÔÂÿÌì3Òڶ࣬Ô̺¬¡°Zoom¡±µÄÐÂÓòÃûµÄ×¢²áÁ¿Ò²±¬Õ¨ÐÔÔö³¤£¬ÕâÅú×¢¹¥»÷Õß½«ZoomÓòÃû×÷Ϊµö¶üÀ´ÓÕÆÊܺ¦Õߣ¬Í¬Ê±»¹³öÏÖÁ˼ÙÒâZoom×°Ö÷¨Ê½µÄ¶ñÒâÈí¼þ¡£
½üÈÕ£¬Check PointµÄ×êÑÐÈËÔ±ÔÚZoom Vanity URLÖз¢ÏÖÁËÒ»¸ö·ì϶£¬¹«Ë¾Äܹ»Ê¹ÓÃVanity URL´´½¨ZoomÔ¼ÇëÁ´½ÓµÄ×Ô½ç˵°æ±¾£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶½øÐÐÍøÂç´¹µö¹¥»÷¡£
×êÑÐÈËÔ±°µÊ¾£¬URLÏÖʵÉÏÖ¸Ïò¹¥»÷Õß×¢²áµÄ×ÓÓò£¬¹¥»÷ÕßÖ¼ÔÚÓÕʹÊܺ¦ÕßÌá½»Ó×ÎÒÍ´´¦»òÆäËûÃô¸ÐÐÅÏ¢¡£ÓÐÁ½ÖÖ²½ÖèÄܹ»½øÈë»áÒ飬»áÒéID»òͨ¹ý¹«Ë¾×Ô½ç˵Web½çÃæ£¬Á½ÖÖ¹¥»÷·½Ê½ÈçÏ£º
ͨ¹ý»áÒéID¹¥»÷£º
? ¸ü¸ÄÔ¼ÇëURL£¬ÀýÈçhttps://zoom.us/j/###########£¬¸Ä³Éhttps://<¹«Ë¾Ãû³Æ> .zoom.us/j/###########£»
? ´Ë±í£¬»¹Äܹ»½«Á´½Ó´Ó/j/¸ü¸ÄΪ/s/£¬https://<¹«Ë¾Ãû³Æ>.Zoom.us/s/7470812100¡£
ͨ¹ýZoom Web½çÃæ¹¥»÷£º
ÁíÒ»ÖÖ²½ÖèÊÇʹÓù«Ë¾×¨ÓÃ×ÓÓòWeb UI£¬ÈçͼËùʾ£º
µ±Óû§½øÈëÍøÕ¾²¢µ¥»÷¡°Join¡±°´Å¥Ê±£¬½«ÏÔʾÒÔÏÂÆÁÄ»£º
Óû§ÔÚ´ËÊäÈë»áÒéID²¢²ÎÓëZoom»á»°¡£¹¥»÷ÕßÄܹ»Í¨¹ýÚ¿ÆÍøÕ¾ÓÕʹÊܺ¦Õß²ÎÓë»á»°£¬µ«Êܺ¦Õß²¢²»ÖªÂ·¸ÃÔ¼ÇëÊÇ·ñÀ´×ԺϷ¨ÒªÇó¡£
0x02 ´ëÖý¨Òé
Ŀǰ³§ÉÌÒѰ䲼²¹¶¡£¬ÏÂÔØÁ´½Ó£º
https://zoom.us/
0x03 ÓйØÐÂÎÅ
https://securityaffairs.co/wordpress/106120/hacking/zooms-vanity-url-flaw.html?utm_source=rss&utm_medium=rss&utm_campaign=zooms-vanity-url-flaw
0x04 ²Î¿¼Á´½Ó
https://blog.checkpoint.com/2020/07/16/fixing-the-zoom-vanity-clause-check-point-and-zoom-collaborate-to-fix-vanity-url-issue/
0x05 ¹¦·òÏß
2020-07-21 VSRC°ä²¼·ì϶¹«¸æ


¾©¹«Íø°²±¸11010802024551ºÅ