Exploiting the post‐attendee URL feature in Zoom webinar to distribute malware. Issue 2 (13th December 2022)
- Record Type:
- Journal Article
- Title:
- Exploiting the post‐attendee URL feature in Zoom webinar to distribute malware. Issue 2 (13th December 2022)
- Main Title:
- Exploiting the post‐attendee URL feature in Zoom webinar to distribute malware
- Authors:
- Cauley, Austin
McCoy, Mark - Abstract:
- Abstract: The post‐attendee Uniform Resource Locator (URL) feature within the video conferencing application known as Zoom is often overlooked by digital forensic experts as a potential risk for malware transmission. However, with the ability to redirect webinar participants to any URL set by the host for the webinar, the post‐attendee URL can be abused by bad actors to expose webinar participants to malicious websites or, in the worst‐case scenario, force participants to download a file through the use of a direct download link URL. This study aims to showcase how this exploit can be replicated by creating an experimental environment involving four Windows 10 desktops running Zoom version 5.7.5 and creating a webinar with four user accounts acting as webinar participants and setting the post‐attendee URL value to the URL of a website that contained a keylogger. In another trial, the same experimental environment was utilized, with the only difference being the post‐attendee URL that was set to redirect webinar participants to a download link for a .jpg file. In both instances, every user account that joined the webinar via clicking on the invitation link that was emailed to each user account after registering for the webinar was redirected to the post‐attendee URL regardless of their user account role. These results not only prove that the post‐attendee URL can be exploited, but also provide insight as to how this type of attack can be prevented.
- Is Part Of:
- Journal of forensic sciences. Volume 68:Issue 2(2023)
- Journal:
- Journal of forensic sciences
- Issue:
- Volume 68:Issue 2(2023)
- Issue Display:
- Volume 68, Issue 2 (2023)
- Year:
- 2023
- Volume:
- 68
- Issue:
- 2
- Issue Sort Value:
- 2023-0068-0002-0000
- Page Start:
- 425
- Page End:
- 433
- Publication Date:
- 2022-12-13
- Subjects:
- digital artifacts -- exploitation -- malware -- phishing -- vulnerabilities -- Zoom
Medical jurisprudence -- Periodicals
Forensic sciences -- Periodicals
Forensic Medicine -- Periodicals
Gerechtelijke geneeskunde
Gerechtelijke chemie
Gerechtelijke psychiatrie
363.2505 - Journal URLs:
- http://catalog.hathitrust.org/api/volumes/oclc/1754597.html ↗
http://onlinelibrary.wiley.com/journal/10.1111/(ISSN)1556-4029 ↗
http://www.blackwell-synergy.com/loi/jfo ↗
http://onlinelibrary.wiley.com/ ↗ - DOI:
- 10.1111/1556-4029.15185 ↗
- Languages:
- English
- ISSNs:
- 0022-1198
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 4984.600000
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 26120.xml