ZOOM Vanity URLÇå¾²Îó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-07-210x00 Îó²î¸ÅÊö
|
CVE ID |
ÔÝÎÞ |
ʱ ¼ä |
2020-07-21 |
|
Àà ÐÍ |
|
µÈ ¼¶ |
¸ßΣ |
|
Ô¶³ÌʹÓà |
ÊÇ |
Ó°Ïì¹æÄ£ |
|
0x01 Îó²îÏêÇé
Ëæ×ÅCOVID-19µÄÉú³¤£¬£¬£¬£¬Ô½À´Ô½¶àµÄ¹«Ë¾¡¢Õþ¸®ºÍѧУ½ÓÄÉÔ¶³Ì°ì¹«£¬£¬£¬£¬ZoomµÄʹÓÃÁ¿´Ó2019Äê12ÔÂÌìÌì1000ÍòµÄ¾Û»á¼ÓÈëÕßÃÍÔöµ½2020Äê4ÔÂÌìÌì3Òڶ࣬£¬£¬£¬°üÀ¨¡°Zoom¡±µÄÐÂÓòÃûµÄ×¢²áÁ¿Ò²±¬Õ¨ÐÔÔöÌí£¬£¬£¬£¬ÕâÅú×¢¹¥»÷Õß½«ZoomÓòÃû×÷ΪÓÕ¶üÀ´ÓÕÆÊܺ¦Õߣ¬£¬£¬£¬Í¬Ê±»¹·ºÆðÁËð³äZoom×°ÖóÌÐòµÄ¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£
¿ËÈÕ£¬£¬£¬£¬Check PointµÄÑо¿Ö°Ô±ÔÚZoom Vanity URLÖз¢Ã÷ÁËÒ»¸öÎó²î£¬£¬£¬£¬¹«Ë¾¿ÉÒÔʹÓÃVanity URL½¨ÉèZoomÔ¼ÇëÁ´½ÓµÄ×Ô½ç˵°æ±¾£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²î¾ÙÐÐÍøÂç´¹ÂÚ¹¥»÷¡£¡£¡£¡£¡£¡£¡£
Ñо¿Ö°Ô±ÌåÏÖ£¬£¬£¬£¬URLÏÖʵÉÏÖ¸Ïò¹¥»÷Õß×¢²áµÄ×ÓÓò£¬£¬£¬£¬¹¥»÷ÕßÖ¼ÔÚÓÕʹÊܺ¦ÕßÌύСÎÒ˽¼Òƾ֤»òÆäËûÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÓÐÁ½ÖÖÒªÁì¿ÉÒÔ½øÈë¾Û»á£¬£¬£¬£¬¾Û»áID»òͨ¹ý¹«Ë¾×Ô½ç˵Web½çÃæ£¬£¬£¬£¬Á½ÖÖ¹¥»÷·½·¨ÈçÏ£º
ͨ¹ý¾Û»áID¹¥»÷£º
? ¸ü¸ÄÔ¼ÇëURL£¬£¬£¬£¬ÀýÈçhttps://zoom.us/j/###########£¬£¬£¬£¬¸Ä³Éhttps://<¹«Ë¾Ãû³Æ> .zoom.us/j/###########£»£»£»£»£»£»£»
? ±ðµÄ£¬£¬£¬£¬»¹¿ÉÒÔ½«Á´½Ó´Ó/j/¸ü¸ÄΪ/s/£¬£¬£¬£¬https://<¹«Ë¾Ãû³Æ>.Zoom.us/s/7470812100¡£¡£¡£¡£¡£¡£¡£
ͨ¹ýZoom Web½çÃæ¹¥»÷£º
ÁíÒ»ÖÖÒªÁìÊÇʹÓù«Ë¾×¨ÓÃ×ÓÓòWeb UI£¬£¬£¬£¬ÈçͼËùʾ£º
µ±Óû§½øÈëÍøÕ¾²¢µ¥»÷¡°Join¡±°´Å¥Ê±£¬£¬£¬£¬½«ÏÔʾÒÔÏÂÆÁÄ»£º
Óû§ÔÚ´ËÊäÈë¾Û»áID²¢¼ÓÈëZoom»á»°¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÕ©ÆÍøÕ¾ÓÕʹÊܺ¦Õß¼ÓÈë»á»°£¬£¬£¬£¬µ«Êܺ¦Õß²¢²»ÖªµÀ¸ÃÔ¼ÇëÊÇ·ñÀ´×ÔÕýµ±ÇëÇ󡣡£¡£¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐû²¼²¹¶¡£¬£¬£¬£¬ÏÂÔØÁ´½Ó£º
https://zoom.us/
0x03 Ïà¹ØÐÂÎÅ
https://securityaffairs.co/wordpress/106120/hacking/zooms-vanity-url-flaw.html?utm_source=rss&utm_medium=rss&utm_campaign=zooms-vanity-url-flaw
0x04 ²Î¿¼Á´½Ó
https://blog.checkpoint.com/2020/07/16/fixing-the-zoom-vanity-clause-check-point-and-zoom-collaborate-to-fix-vanity-url-issue/
0x05 ʱ¼äÏß
2020-07-21 VSRCÐû²¼Îó²îͨ¸æ


¾©¹«Íø°²±¸11010802024551ºÅ