what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

WebEx Man-In-The-Middle

WebEx Man-In-The-Middle
Posted Jun 26, 2019
Authored by RDX Guy

WebEx appears to suffer from man-in-the-middle attacks due to accepting any TLS certificates as valid.

tags | advisory
SHA-256 | 22e3cd7a64dcb66910ad59f0e79c228bad57d0d9720924bbaa649a7da3e814a8

WebEx Man-In-The-Middle

Change Mirror Download
https://pankajupadhyay.in/2019/06/24/webex-meetings-are-vulnerable-to-mitm/

"In my free time, I was looking at some Android applications and noticed
that I was able to intercept SSL traffic for Webex Meetings app. When
explored it further, I found that Webex Meetings mobile app accepts
self-signed certificates. Also there is no certificate pinning enabled.

This makes Webex meet app vulnerable to Man in the middle attack.

Users of this app, if connected to a public Wi-Fi spot, can be targeted by
any person in the same network. If connected to a rogue Wi-Fi hotspot,
Wi-Fi provider may have access to the data passed from the app to the
server. Malwares on the device can also exploit this vulnerability to
intercept any sensitive data while it’s traveling across the wire."


Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    69 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close