Little Doctor zero day: violate chat applications

Little Doctor: Hackers who want to gain access to popular chat applications to use the camera and user sound can do it very easily by using a worm published online.

At this time it is still zero day, which means that the security gap has not been repaired. Little Doctor

The framework, named “Little DoctorIs a super weapon that can violate JavaScript-based chat applications. So many popular chat applications are at risk because of their architecture. Services that have been developed in Electron, or that contain a built-in webview, are in a very difficult position.

Let's say that Rocket Chat released a patch 13 hours after the reveal, and Ryver within a day. And the Slack app uses WebViews, though, so it seems to be safe.

Australian hacker Shubham Shah and former co-worker Matt Bryant developed the framework worm and found an unpatched Microsoft Azure Storage Explorer zero day.

“This worm is cross-platform, and it can steal από όποια εφαρμογή έχει πρόσβαση στα APIs του , and Cordova APIs,” Moloch said at the Kiwicon hacking conference held in Wellington.

The team uncovered the error in Microsoft, but after 90 days, it did not receive a response.

The trio didn't stop there, having found and demonstrated the exploit in the Rocket Chat and Ryver apps, turning a cross-site scripting attack into code execution for container apps.

See PoC and download Little Doctor

The Little Doctor framework is available in GitHub for all security researchers and their testers.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.082 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).