NewsBytes Stage
    Hindi
    More
    In the news
    Narendra Modi
    Amit Shah
    Box Office Collection
    Bharatiya Janata Party (BJP)
    OTT releases
    Hindi
    NewsBytes Stage
    India
    Business
    World
    Politics
    Sports
    Technology
    Entertainment
    Auto
    Lifestyle
    Career
    Visual Stories
    Find Cricket Statistics

    Download Android App

    Follow us on
    • Facebook
    • Twitter
    • Linkedin
    Home / News / Technology News / Zoom bug allowed breaking into private password-protected meetings
    Next Article
    Zoom bug allowed breaking into private password-protected meetings

    Zoom bug allowed breaking into private password-protected meetings

    By Shubham Sharma
    Jul 30, 2020
    07:11 pm

    What's the story

    Even after all the promises, video conferencing giant Zoom keeps running into security issues.

    Just recently, we detailed a bug in the service that allowed mimicking of reputed organizations, and now, in another case, a researcher has reported a vulnerability that allowed cracking of private meeting passwords in a matter of minutes.

    Here is all you need to know about it.

    Passcodes

    No rate limiting in six-digit passcode of meetings

    In a recent tweet, Tom Anthony, the Product VP at SearchPilot, revealed that Zoom's web client, in April, was not rate-limiting the attempts to enter the default 6-digit passcode of video meetings.

    The issue, he found, could easily be exploited by anyone to brute-force all possible passcode combinations, 1 million in all, and enter into private conferences, without the consent of the host.

    Demo

    He tested the theory, broke into a meeting

    Anthony tested his theory and was able to break into a private Zoom meeting in a matter of just 25 minutes.

    He used an AWS machine for the hack and brute-forced some 91,000 combinations until the correct one appeared and worked.

    "With improved threading, and distributing across 4-5 cloud servers, you could check the entire password space within a few minutes," he emphasized.

    Twitter Post

    Here is Anthony's tweet

    So a few months ago I realised Zoom doesn't rate limit password attempts for meetings, and has only 1 million passwords. Meaning you could join private meetings within minutes. 😮 https://t.co/NDUEmzUprX

    — Tom Anthony (@TomAnthonySEO) July 29, 2020

    Report

    Then, the bug was reported to Zoom, fix was deployed

    After discovering the flaw, Anthony reported the matter to Zoom, prompting the company to take its web client down - to prevent any exploit.

    Then, in about a week, the video-conference giant deployed a fix for the flaw by requiring a "user to log in to join meetings in the web client, and updating the default meeting passwords to be non-numeric and longer."

    Statement

    No evidence of issue being exploited, Zoom clarified

    In an official statement issued in light of Anthony's report, Zoom clarified that it "improved rate-limiting, addressed the CSRF token issues, and relaunched the web client on April 9."

    "The issue was fully resolved, and no user action was required," the company said, noting that it is not aware of any instances where a hijacker used this vulnerability to break into a meeting.

    Facebook
    Whatsapp
    Twitter
    Linkedin
    Related News
    Latest
    Security
    Anthony Russo
    Amazon Web Services
    Zoom

    Latest

    Who is India's most successful Test captain on England soil? Indian Cricket Team
    No duty cuts on British wine in India-UK trade deal United Kingdom
    Sneh Rana records career-best WODI returns against SL; Amanjot shines Indian Women's Cricket Team
    TVS's cheapest e-scooter to be launched soon: What we know TVS Motor Company

    Security

    Google removed 600 apps from Play Store: Here's why Google
    Google sued for spying on students through Chromebooks: Details here WhatsApp
    Hackers are mysteriously stealing from PayPal accounts for online shopping PayPal
    New bug exposes Wi-Fi traffic of billion devices (including phones) Google

    Anthony Russo

    Interesting secret behind Captain America's 'Infinity War' phone number Hollywood
    In 'Avengers 4' wrap, a confusing photo drives fans crazy Marvel
    'Avengers: Endgame' directors, Russo brothers, troll Marvel fans Instagram
    'Avengers: Endgame' to have 3 hours runtime, directors confirm Joe Russo

    Amazon Web Services

    Succumbing to cloud rivals, Rackspace goes private in an acquisition European Union Intellectual Property Office (EUIPO)
    Amazon posts third-quarter earnings; misses estimates Amazon
    Database can help Mumbaiites to watch out for sex-offenders Mumbai
    Microsoft mulls on investing $100 million in Ola's parent firm India

    Zoom

    Zoom sued for covertly sending user data to Facebook Facebook
    Now, Slack users can call those on Microsoft Teams Microsoft
    #TechBytes: How to get the most out of Zoom Google
    Rivaling Zoom, Skype releases 'Meet Now' calling feature Microsoft
    Indian Premier League (IPL) Celebrity Hollywood Bollywood UEFA Champions League Tennis Football Smartphones Cryptocurrency Upcoming Movies Premier League Cricket News Latest automobiles Latest Cars Upcoming Cars Latest Bikes Upcoming Tablets
    About Us Privacy Policy Terms & Conditions Contact Us Ethical Conduct Grievance Redressal News News Archive Topics Archive Download DevBytes Find Cricket Statistics
    Follow us on
    Facebook Twitter Linkedin
    All rights reserved © NewsBytes 2025