ZOOM Vanity URL°²È«·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-07-210x00 ·ì϶¸ÅÊö
|
CVE ID |
ÔÝÎÞ |
ʱ ¼ä |
2020-07-21 |
|
Àà ÐÍ |
|
µÈ ¼¶ |
¸ßΣ |
|
Ô¶³ÌÀûÓà |
ÊÇ |
Ó°ÏìÁìÓò |
|
0x01 ·ì϶ÏêÇé
Ëæ×ÅCOVID-19µÄ·¢Õ¹£¬£¬£¬£¬£¬£¬£¬Ô½À´Ô½¶àµÄ¹«Ë¾¡¢µ±¾ÖºÍѧÌÃѡȡԶ³Ì°ì¹«£¬£¬£¬£¬£¬£¬£¬ZoomµÄʹÓÃÁ¿´Ó2019Äê12ÔÂÿÌì1000ÍòµÄ»áÒé²Î¼ÓÕßÃÍÔöµ½2020Äê4ÔÂÿÌì3Òڶ࣬£¬£¬£¬£¬£¬£¬Ô̺¬¡°Zoom¡±µÄÐÂÓòÃûµÄ×¢²áÁ¿Ò²±¬Õ¨ÐÔÔö³¤£¬£¬£¬£¬£¬£¬£¬ÕâÅú×¢¹¥»÷Õß½«ZoomÓòÃû×÷Ϊµö¶üÀ´ÓÕÆÊܺ¦Õߣ¬£¬£¬£¬£¬£¬£¬Í¬Ê±»¹³öÏÖÁ˼ÙÒâZoom×°Ö÷¨Ê½µÄ¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£
½üÈÕ£¬£¬£¬£¬£¬£¬£¬Check PointµÄ×êÑÐÈËÔ±ÔÚZoom Vanity URLÖз¢ÏÖÁËÒ»¸ö·ì϶£¬£¬£¬£¬£¬£¬£¬¹«Ë¾Äܹ»Ê¹ÓÃVanity URL´´½¨ZoomÔ¼ÇëÁ´½ÓµÄ×Ô½ç˵°æ±¾£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶½øÐÐÍøÂç´¹µö¹¥»÷¡£¡£¡£¡£¡£¡£
×êÑÐÈËÔ±°µÊ¾£¬£¬£¬£¬£¬£¬£¬URLÏÖʵÉÏÖ¸Ïò¹¥»÷Õß×¢²áµÄ×ÓÓò£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÖ¼ÔÚÓÕʹÊܺ¦ÕßÌá½»Ó×ÎÒÍ´´¦»òÆäËûÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£ÓÐÁ½ÖÖ²½ÖèÄܹ»½øÈë»áÒ飬£¬£¬£¬£¬£¬£¬»áÒéID»òͨ¹ý¹«Ë¾×Ô½ç˵Web½çÃæ£¬£¬£¬£¬£¬£¬£¬Á½ÖÖ¹¥»÷·½Ê½ÈçÏ£º
ͨ¹ý»áÒéID¹¥»÷£º
? ¸ü¸ÄÔ¼ÇëURL£¬£¬£¬£¬£¬£¬£¬ÀýÈçhttps://zoom.us/j/###########£¬£¬£¬£¬£¬£¬£¬¸Ä³Éhttps://<¹«Ë¾Ãû³Æ> .zoom.us/j/###########£»£»£»£»£»£»£»
? ´Ë±í£¬£¬£¬£¬£¬£¬£¬»¹Äܹ»½«Á´½Ó´Ó/j/¸ü¸ÄΪ/s/£¬£¬£¬£¬£¬£¬£¬https://<¹«Ë¾Ãû³Æ>.Zoom.us/s/7470812100¡£¡£¡£¡£¡£¡£
ͨ¹ýZoom Web½çÃæ¹¥»÷£º
ÁíÒ»ÖÖ²½ÖèÊÇʹÓù«Ë¾×¨ÓÃ×ÓÓòWeb UI£¬£¬£¬£¬£¬£¬£¬ÈçͼËùʾ£º
µ±Óû§½øÈëÍøÕ¾²¢µ¥»÷¡°Join¡±°´Å¥Ê±£¬£¬£¬£¬£¬£¬£¬½«ÏÔʾÒÔÏÂÆÁÄ»£º
Óû§ÔÚ´ËÊäÈë»áÒéID²¢²ÎÓëZoom»á»°¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»Í¨¹ýÚ¿ÆÍøÕ¾ÓÕʹÊܺ¦Õß²ÎÓë»á»°£¬£¬£¬£¬£¬£¬£¬µ«Êܺ¦Õß²¢²»ÖªÂ·¸ÃÔ¼ÇëÊÇ·ñÀ´×ԺϷ¨ÒªÇ󡣡£¡£¡£¡£¡£
0x02 ´ëÖý¨Òé
Ŀǰ³§ÉÌÒѰ䲼²¹¶¡£¬£¬£¬£¬£¬£¬£¬ÏÂÔØÁ´½Ó£º
https://zoom.us/
0x03 ÓйØÐÂÎÅ
https://securityaffairs.co/wordpress/106120/hacking/zooms-vanity-url-flaw.html?utm_source=rss&utm_medium=rss&utm_campaign=zooms-vanity-url-flaw
0x04 ²Î¿¼Á´½Ó
https://blog.checkpoint.com/2020/07/16/fixing-the-zoom-vanity-clause-check-point-and-zoom-collaborate-to-fix-vanity-url-issue/
0x05 ¹¦·òÏß
2020-07-21 VSRC°ä²¼·ì϶¹«¸æ


¾©¹«Íø°²±¸11010802024551ºÅ