Researchers found a way to hijack devices through Zoom screen sharing
Researchers found a way to hijack devices through Zoom screen sharing
研究人员发现可以通过 Zoom 屏幕共享劫持设备
As AI models gain advanced capabilities to find vulnerabilities in software, develop ways to exploit them, and even carry out autonomous hacking sprees, researchers offered a sobering new example on Tuesday, disclosing vulnerabilities in the video conferencing platform Zoom that could have been exploited to take over targets’ devices.
随着人工智能模型在发现软件漏洞、开发利用方式甚至进行自主黑客攻击方面获得先进能力,研究人员周二提供了一个令人警醒的新案例,披露了视频会议平台 Zoom 中存在的漏洞,这些漏洞曾可被利用来接管目标设备。
Anyone on a call that involved screen sharing, whether participants or the host, would have been vulnerable to a silent attack that could be carried out with no indication and no interaction from the victim.
任何参与屏幕共享通话的人,无论是参会者还是主持人,都可能遭受静默攻击,这种攻击可以在没有任何迹象且无需受害者交互的情况下执行。
Researchers from the digital defense firm A Security say the bug was discovered in early June using publicly available AI models, and that it took fewer than 20 prompts to uncover the vulnerabilities and create a working attack.
数字防御公司 A Security 的研究人员表示,该漏洞是于 6 月初利用公开的人工智能模型发现的,仅用了不到 20 个提示词(prompts)就揭示了这些漏洞并创建了有效的攻击方式。
Zoom issued a security advisory on Tuesday, including details about fixes the company has already begun rolling out to address the flaws, which affected devices running all operating systems that Zoom supports—Windows, macOS, Linux, iOS, and Android.
Zoom 周二发布了安全公告,详细说明了公司已开始推出的修复程序,以解决这些缺陷。这些缺陷影响了 Zoom 所支持的所有操作系统设备,包括 Windows、macOS、Linux、iOS 和 Android。
“What is interesting for us and what we believe is dangerous is the democratization of these capabilities—the barrier to entry is dropping rapidly,” A Security cofounder Omer Gull told WIRED ahead of the disclosure. “Before it would have taken a team of five people maybe six months with a lot of refining and iteration to find this. Now people can reach the same results with under 20 prompts. And Zoom is an important type of target because people assume trust when using it. They don’t see it as a threat.”
“对我们来说,有趣且我们认为危险的是这些能力的民主化——准入门槛正在迅速降低,”A Security 联合创始人 Omer Gull 在披露前告诉《连线》(WIRED)。“以前,一个五人团队可能需要六个月的时间,经过大量的改进和迭代才能发现这一点。现在,人们用不到 20 个提示词就能达到同样的结果。Zoom 是一个重要的目标类型,因为人们在使用它时会默认信任它。他们并不认为它是一种威胁。”
The vulnerabilities were specifically in the protocol used to facilitate real-time annotation during screen sharing. The researchers say that their AI bug hunting systems specifically delved into this component because, like human bug hunters, they have been trained that convoluted and obscure functions often contain overlooked vulnerabilities.
这些漏洞具体存在于屏幕共享期间用于实现实时标注的协议中。研究人员表示,他们的人工智能漏洞挖掘系统专门深入研究了这一组件,因为像人类漏洞猎人一样,它们经过训练,知道复杂且晦涩的功能往往包含被忽视的漏洞。
This is particularly true with proprietary, closed-source software. An established company like Zoom presumably does extensive code review and vetting on all components and functions, but without the benefit of public, open review, esoteric yet complex features like annotation are more likely to contain mistakes.
对于专有的闭源软件来说尤其如此。像 Zoom 这样成熟的公司理应会对所有组件和功能进行广泛的代码审查和验证,但由于缺乏公开、透明的审查,像标注这样深奥而复杂的功能更容易出现错误。
Zoom did not respond to multiple requests for comment from WIRED about the A Security findings. The bugs are now patched, with Zoom issuing both server and client-side fixes—or patches for both Zoom’s own servers and the applications that run on customer devices.
Zoom 没有回应《连线》就 A Security 的发现提出的多次置评请求。目前这些漏洞已得到修复,Zoom 发布了服务器端和客户端的修复程序,即针对 Zoom 自身服务器以及运行在客户设备上的应用程序的补丁。
But the researchers emphasize that it was alarming to contemplate bugs that could have been exploited to take over a target device simply by getting someone onto a Zoom call. Joining a call is in itself a gesture of trust, but given how ubiquitous video calling is in both personal and professional contexts—and given that Zoom in particular is also widely used for events and semipublic activities like webinars—people typically have their guard down when joining a Zoom.
但研究人员强调,想到仅通过让某人加入 Zoom 通话就能利用漏洞接管目标设备,这令人担忧。加入通话本身就是一种信任的表示,但考虑到视频通话在个人和职业环境中是多么普遍,且考虑到 Zoom 特别广泛地用于活动和网络研讨会等半公开活动,人们在加入 Zoom 时通常会放松警惕。
“If you just get on a Zoom with us, we can take over your device,” A Security cofounder Yossi Torati told WIRED on a call. (It was, incidentally, hosted on Microsoft Teams.) “The worst-case scenario is that we can take over an enterprise just by having this vulnerability in our hands. If I’m an attacker, I can be on a call with someone from a company, take control of their computer and their credentials, and then use them to move laterally in the enterprise.”
“如果你只是和我们进行 Zoom 通话,我们就能接管你的设备,”A Security 联合创始人 Yossi Torati 在一次通话中告诉《连线》。(顺便提一下,这次通话是在 Microsoft Teams 上进行的。)“最坏的情况是,我们只需掌握这个漏洞就能接管一家企业。如果我是攻击者,我可以与某家公司的人通话,控制他们的电脑和凭据,然后利用这些凭据在企业内部进行横向移动。”
Practitioners often call security a “cat-and-mouse game,” but as AI bug hunting proliferates, this delicate dance has become an all-out race.
从业者常将安全称为“猫鼠游戏”,但随着人工智能漏洞挖掘的普及,这种微妙的博弈已演变成一场全面的竞赛。