ZOOM Vanity URLÇå¾²Îó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-07-21

0x00 Îó²î¸ÅÊö


CVE   ID

ÔÝÎÞ

ʱ    ¼ä

2020-07-21

Àà   ÐÍ

µÈ    ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£


0x01 Îó²îÏêÇé


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ëæ×ÅCOVID-19µÄÉú³¤£¬£¬£¬£¬£¬£¬£¬Ô½À´Ô½¶àµÄ¹«Ë¾¡¢Õþ¸®ºÍѧУ½ÓÄÉÔ¶³Ì°ì¹«£¬£¬£¬£¬£¬£¬£¬ZoomµÄʹÓÃÁ¿´Ó2019Äê12ÔÂÌìÌì1000ÍòµÄ¾Û»á¼ÓÈëÕßÃÍÔöµ½2020Äê4ÔÂÌìÌì3Òڶ࣬£¬£¬£¬£¬£¬£¬°üÀ¨¡°Zoom¡±µÄÐÂÓòÃûµÄ×¢²áÁ¿Ò²±¬Õ¨ÐÔÔöÌí£¬£¬£¬£¬£¬£¬£¬ÕâÅú×¢¹¥»÷Õß½«ZoomÓòÃû×÷ΪÓÕ¶üÀ´ÓÕÆ­Êܺ¦Õߣ¬£¬£¬£¬£¬£¬£¬Í¬Ê±»¹·ºÆðÁËð³äZoom×°ÖóÌÐòµÄ¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£

¿ËÈÕ£¬£¬£¬£¬£¬£¬£¬Check PointµÄÑо¿Ö°Ô±ÔÚZoom Vanity URLÖз¢Ã÷ÁËÒ»¸öÎó²î£¬£¬£¬£¬£¬£¬£¬¹«Ë¾¿ÉÒÔʹÓÃVanity URL½¨ÉèZoomÔ¼ÇëÁ´½ÓµÄ×Ô½ç˵°æ±¾£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²î¾ÙÐÐÍøÂç´¹ÂÚ¹¥»÷¡£¡£¡£¡£¡£¡£¡£

Ñо¿Ö°Ô±ÌåÏÖ£¬£¬£¬£¬£¬£¬£¬URLÏÖʵÉÏÖ¸Ïò¹¥»÷Õß×¢²áµÄ×ÓÓò£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÖ¼ÔÚÓÕʹÊܺ¦ÕßÌύСÎÒ˽¼Òƾ֤»òÆäËûÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÓÐÁ½ÖÖÒªÁì¿ÉÒÔ½øÈë¾Û»á£¬£¬£¬£¬£¬£¬£¬¾Û»áID»òͨ¹ý¹«Ë¾×Ô½ç˵Web½çÃæ£¬£¬£¬£¬£¬£¬£¬Á½ÖÖ¹¥»÷·½·¨ÈçÏ£º

ͨ¹ý¾Û»áID¹¥»÷£º

? ¸ü¸ÄÔ¼ÇëURL£¬£¬£¬£¬£¬£¬£¬ÀýÈçhttps://zoom.us/j/###########£¬£¬£¬£¬£¬£¬£¬¸Ä³Éhttps://<¹«Ë¾Ãû³Æ> .zoom.us/j/###########£»£»£»

? ±ðµÄ£¬£¬£¬£¬£¬£¬£¬»¹¿ÉÒÔ½«Á´½Ó´Ó/j/¸ü¸ÄΪ/s/£¬£¬£¬£¬£¬£¬£¬https://<¹«Ë¾Ãû³Æ>.Zoom.us/s/7470812100¡£¡£¡£¡£¡£¡£¡£

ͨ¹ýZoom Web½çÃæ¹¥»÷£º

ÁíÒ»ÖÖÒªÁìÊÇʹÓù«Ë¾×¨ÓÃ×ÓÓòWeb UI£¬£¬£¬£¬£¬£¬£¬ÈçͼËùʾ£º


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨



µ±Óû§½øÈëÍøÕ¾²¢µ¥»÷¡°Join¡±°´Å¥Ê±£¬£¬£¬£¬£¬£¬£¬½«ÏÔʾÒÔÏÂÆÁÄ»£º


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨



Óû§ÔÚ´ËÊäÈë¾Û»áID²¢¼ÓÈëZoom»á»°¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÕ©Æ­ÍøÕ¾ÓÕʹÊܺ¦Õß¼ÓÈë»á»°£¬£¬£¬£¬£¬£¬£¬µ«Êܺ¦Õß²¢²»ÖªµÀ¸ÃÔ¼ÇëÊÇ·ñÀ´×ÔÕýµ±ÇëÇ󡣡£¡£¡£¡£¡£¡£


0x02 ´¦Öóͷ£½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼²¹¶¡£¬£¬£¬£¬£¬£¬£¬ÏÂÔØÁ´½Ó£º

https://zoom.us/


0x03 Ïà¹ØÐÂÎÅ


https://securityaffairs.co/wordpress/106120/hacking/zooms-vanity-url-flaw.html?utm_source=rss&utm_medium=rss&utm_campaign=zooms-vanity-url-flaw


0x04 ²Î¿¼Á´½Ó


https://blog.checkpoint.com/2020/07/16/fixing-the-zoom-vanity-clause-check-point-and-zoom-collaborate-to-fix-vanity-url-issue/


0x05 ʱ¼äÏß


2020-07-21 VSRCÐû²¼Îó²îͨ¸æ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨