exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

BigBlueButton 2.2.29 Brute Force

BigBlueButton 2.2.29 Brute Force
Posted Nov 25, 2020
Authored by Ismail Saygili

BigBlueButton versions 2.2.29 and below suffer from a meeting access code brute forcing vulnerability.

tags | exploit, cracker
advisories | CVE-2020-29042
SHA-256 | 7779a47f90e53f789a2fbce3072e0d2ff2ac04320c70d8126d32c0cd38ef8a28

BigBlueButton 2.2.29 Brute Force

Change Mirror Download
# Title: BigBlueButton Meeting Access Code Brute Force Vulnerability

# Google Dork: N/A

# Date: 24.11.2020

# Author: Seccops (https://seccops.com)

# Vendor Homepage: bigbluebutton.org

# Version: 2.2.29 and previous versions

# CVE: CVE-2020-29042





=== Summary ===

An issue was discovered in BigBlueButton through 2.2.29.

A brute-force attack may occur because an unlimited number of codes can be
entered for a meeting that is protected by an access code.





=== Description ===

BigBlueButton is an open source web conferencing solution for online
learning that provides real-time sharing of audio, video, slides,
whiteboard, chat and screen. It also allows participants to join the
conferences with their webcams and invite guest speakers.



An unlimited number of codes can be entered for a meeting that is protected
by an access code. This situation causes a brute force attack.

The following is a brute force attack for the access code of a meeting with
a known meeting link: https://imgur.com/a/jaoOkwT





=== Impact ===

An attacker who knows a meeting link protected by an access code; By
breaking the access code with brute force attack, it can make social
engineering attacks in the meeting, collect all the confidential
information/documents that were spoken and shared in the meeting, disturb
other users in the meeting or sabotage the meeting.

Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close