exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

BigBlueButton 2.2.29 Brute Force

BigBlueButton 2.2.29 Brute Force
Posted Nov 25, 2020
Authored by Ismail Saygili

BigBlueButton versions 2.2.29 and below suffer from a meeting access code brute forcing vulnerability.

tags | exploit, cracker
advisories | CVE-2020-29042
SHA-256 | 7779a47f90e53f789a2fbce3072e0d2ff2ac04320c70d8126d32c0cd38ef8a28

BigBlueButton 2.2.29 Brute Force

Change Mirror Download
# Title: BigBlueButton Meeting Access Code Brute Force Vulnerability

# Google Dork: N/A

# Date: 24.11.2020

# Author: Seccops (https://seccops.com)

# Vendor Homepage: bigbluebutton.org

# Version: 2.2.29 and previous versions

# CVE: CVE-2020-29042





=== Summary ===

An issue was discovered in BigBlueButton through 2.2.29.

A brute-force attack may occur because an unlimited number of codes can be
entered for a meeting that is protected by an access code.





=== Description ===

BigBlueButton is an open source web conferencing solution for online
learning that provides real-time sharing of audio, video, slides,
whiteboard, chat and screen. It also allows participants to join the
conferences with their webcams and invite guest speakers.



An unlimited number of codes can be entered for a meeting that is protected
by an access code. This situation causes a brute force attack.

The following is a brute force attack for the access code of a meeting with
a known meeting link: https://imgur.com/a/jaoOkwT





=== Impact ===

An attacker who knows a meeting link protected by an access code; By
breaking the access code with brute force attack, it can make social
engineering attacks in the meeting, collect all the confidential
information/documents that were spoken and shared in the meeting, disturb
other users in the meeting or sabotage the meeting.

Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    63 Files
  • 14
    Nov 14th
    18 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close