Jonkman Microblog
  • Login
Show Navigation
  • Public

    • Public
    • Network
    • Groups
    • Popular
    • People

Conversation

Notices

  1. Haelwenn /элвэн/ :triskell: (lanodan@queer.hacktivis.me)'s status on Monday, 08-Jul-2019 23:30:34 EDT Haelwenn /элвэн/ :triskell: Haelwenn /элвэн/ :triskell:

    https://medium.com/@jonathan.leitschuh/zoom-zero-day-4-million-webcams-maybe-an-rce-just-get-them-to-visit-your-website-ac75c83f4ef5

    Additionally, if you’ve ever installed the Zoom client and then uninstalled it, you still have a localhost web server on your machine

    This is why I put in a package anything needing more than user permissions at installation time, also why I do not want something like session startup other than ~/.profile and similar (and don’t even try to edit theses or it’s a permanent ban from my sandbox(1) config).

    In conversation Monday, 08-Jul-2019 23:30:34 EDT from queer.hacktivis.me permalink
    1. Haelwenn /элвэн/ :triskell: (lanodan@queer.hacktivis.me)'s status on Monday, 08-Jul-2019 23:40:04 EDT Haelwenn /элвэн/ :triskell: Haelwenn /элвэн/ :triskell:
      in reply to

      UPDATE: June 7th, 2019: There has been a regression in the fix implemented by Zoom thus allowing this vulnerability to be exploited with the video camera activated.

      A regression on a FIX?! Holy shit.

      In conversation Monday, 08-Jul-2019 23:40:04 EDT from queer.hacktivis.me permalink
      1. Haelwenn /элвэн/ :triskell: (lanodan@queer.hacktivis.me)'s status on Monday, 08-Jul-2019 23:46:25 EDT Haelwenn /элвэн/ :triskell: Haelwenn /элвэн/ :triskell:
        in reply to

        During this call, they promised Mozilla and me that this vulnerability would be patched well before the end of the 90-day disclosure deadline. This turned out to be false.

        Well fucking done Mozilla. (I’m of course going to try it with webkitgtk)

        In conversation Monday, 08-Jul-2019 23:46:25 EDT from queer.hacktivis.me permalink
        1. Haelwenn /элвэн/ :triskell: (lanodan@queer.hacktivis.me)'s status on Monday, 08-Jul-2019 23:49:41 EDT Haelwenn /элвэн/ :triskell: Haelwenn /элвэн/ :triskell:
          in reply to

          According to the Zoom team, the only reason this localhost server continues to exist is that Apple’s Safari doesn’t support URI handlers.

          WebKit is able to so it would be really awkward for Safari to not have it.

          In conversation Monday, 08-Jul-2019 23:49:41 EDT from queer.hacktivis.me permalink
          1. Haelwenn /элвэн/ :triskell: (lanodan@queer.hacktivis.me)'s status on Monday, 08-Jul-2019 23:56:44 EDT Haelwenn /элвэн/ :triskell: Haelwenn /элвэн/ :triskell:
            in reply to

            Oh wow… Safari actually doesn’t. Badwolf doesn’t either btw but that’s just because I have no reason to support this and I consider it to be a fingerprintable API.

            https://caniuse.com/registerprotocolhandler

            In conversation Monday, 08-Jul-2019 23:56:44 EDT from queer.hacktivis.me permalink
        2. Haelwenn /элвэн/ :triskell: (lanodan@queer.hacktivis.me)'s status on Tuesday, 09-Jul-2019 00:51:39 EDT Haelwenn /элвэн/ :triskell: Haelwenn /элвэн/ :triskell:
          in reply to

          [Error] Refused to load https://localhost:1337/screen.png because it does not appear in the img-src directive of the Content Security Policy.

          Weh.

          In conversation Tuesday, 09-Jul-2019 00:51:39 EDT from queer.hacktivis.me permalink
          1. Haelwenn /элвэн/ :triskell: (lanodan@queer.hacktivis.me)'s status on Tuesday, 09-Jul-2019 00:52:25 EDT Haelwenn /элвэн/ :triskell: Haelwenn /элвэн/ :triskell:
            in reply to

            Aaaand thanks pleroma for trying to load it, lol.


            screen.png
            In conversation Tuesday, 09-Jul-2019 00:52:25 EDT from queer.hacktivis.me permalink
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

Jonkman Microblog is a social network, courtesy of SOBAC Microcomputer Services. It runs on GNU social, version 1.2.0-beta5, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All Jonkman Microblog content and data are available under the Creative Commons Attribution 3.0 license.

Switch to desktop site layout.