Zoom,erotice torture cartoon the videoconferencing software that's skyrocketed in popularity as much of the globe sits at home due to the coronavirus outbreak, is quickly turning into a privacy and security nightmare.
BleepingComputer reports about a newly found vulnerability in Zoom that allows an attacker to steal Windows login credentials from other users. The problem lies with the way Zoom's chat handles links, as it converts Windows networking UNC (Universal Naming Convention) paths into clickable links. If a user clicks on such a link, Windows will leak the user's Windows login name and password.
The good thing is that the password is hashed; but the bad thing is that it is in many cases simple to reveal it using password recovery tools such as Hashcat.
The vulnerability was first found by security researcher @_g0dmode and verified by security researcher Matthew Hickey. Additionally, Hickey told the news outlet that this vulnerability can be used to launch programs on a victim's computer when they click on a link, though Windows will (by default) at least give a security warning before launching the program.
As far as security vulnerabilities go, this one is pretty bad, as it doesn't require a lot of knowledge to exploit. It does require the victim to actually click on a link, and it can be mitigated by tinkering with Windows' security settings, but it's definitely something Zoom should fix by changing the way the platform's chat handles UNC links.
In the meantime, for a quick fix, go to Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> Network security: Restrict NTLM: Outgoing NTLM traffic to remote servers and set to "Deny all".
Mashable has contacted Zoom for comment on this story, and we'll update it when we hear back.
SEE ALSO: Zoom's iOS app no longer sends data to FacebookThis is not the only privacy/security-related issue that has been unearthed at Zoom in the past couple of weeks. Just yesterday, The Intercept reported that Zoom doesn't actually use an end-to-end encrypted connection for its calls, despite claiming to do so. There's also the issue of leaking users' emails and photos to unrelated parties, and the fact that the company's iOS app, until recently, sent data to Facebook for no good reason.
Zoom software also has a couple of worrying privacy features, and although this isn't Zoom's fault, it's worth noting that hackers are using the app's newfound popularity to trick users into downloading malware.
Topics Cybersecurity
How to make the most of the Olympics on PeacockSamsung Galaxy Watch Ultra handsByteDance launches Trae AI IDE in China with DoubaoUnitree robotics opens official store on AliExpress · TechNodeScientists capture absolutely stunning image of the Andromeda galaxyAgiBot unveils Lingxi X2, an advanced humanoid robot with multimodal intelligence · TechNodeIn rare move, BMW and China’s Huawei sign deal for inEmbodied intelligence appears in government work report for the first time at NPC · TechNodeBest iPad deals: Save on multiple iPad models ahead of Amazon Prime Day 2024NASA plane swooped over the Arctic. It detected a buried military base.Apple issues yet another ‘spyware’ iPhone warning to users in nearly 100 countriesByteDance dismisses hundreds of employees for corruption · TechNodeNASA video shows its next Martian helicopter soaring over MarsSamsung and SK Hynix saw strong growth in China in 2024 as chip demand rose · TechNodeWebb telescope spots curious objects that aren't stars, or planetsByteDance dismisses hundreds of employees for corruption · TechNodeA secretive U.S. spaceplane just snapped a stunning view of EarthEmbodied intelligence appears in government work report for the first time at NPC · TechNodeNASA just jumped online to correct outrageous space station misinformationChinese expert predicts small Best Fire tablet deal: Get the Amazon Fire HD 8 Kids Pro tablet for just $99.99 at Amazon China holds 49.4% of global new energy light vehicles market by Q1 sales · TechNode Best streaming device deal: The Amazon Fire TV Cube is on sale for just $114.99 at Amazon Phone maker Honor may soon return to Google Mobile Services · TechNode ChatGPT vs. Gemini: Which AI chatbot won our 5 How to screenshot an entire webpage on iPhone How to turn on 3D buildings in Google Maps navigation Baidu posts Q2 revenue of $4.7 billion, sees 15% year Facebook releases 'Community Help' disaster relief for Facebook Lite NYT's The Mini crossword answers for April 17 Beijing forbids generative AI in online medical prescriptions · TechNode Is AI good or bad? A deeper look at its potential and pitfalls Best free online courses from University of Michigan GT vs. DC 2024 livestream: Watch IPL for free How to log out of Netflix on Apple TV, Roku, Fire, and more Fish are friends, not food: Meet the world's first known omnivorous shark The Space Between Trump's EPA wants to kill our most ambitious climate change plan Best tablet deal: The Amazon Fire Max 11 tablet is 30% off at Amazon Amazon deals of the day: Samsung Galaxy Tab A9+, Echo Pop bundle, and more
3.1947s , 8262.1796875 kb
Copyright © 2025 Powered by 【erotice torture cartoon】,New Knowledge Information Network