HomeSecurityLittle Doctor zero day: hack chat apps

Little Doctor zero day: hack chat apps

Little Doctor: Hackers who wish to gain access to popular chat applications to use users' cameras and audio can do so very easily using a worm published online.

At the moment it is still a zero day which means the security flaw has not been patched. Little Doctor

The framework, dubbed “Little Doctor,” is a super weapon that can compromise JavaScript-based chat apps. So many popular chat apps are at risk due to their architecture. Services developed in Electron, or that contain an embedded webview, are in a very difficult position.

It should be noted that Rocket Chat released a patch within 13 hours of the disclosure, and Ryver within a day. The Slack app also uses WebViews, but they appear to be secure.

Australian hacker Shubham Shah and former colleague Matt Bryant developed the framework worm and found an unpatched Microsoft Azure Storage Explorer zero day.

"This worm is cross-platform, and can steal files from any application that has access to the WebRTC APIs, and the Cordova APIs," Moloch said at the Kiwicon hacking conference held in Wellington.

The team disclosed the bug to Microsoft, but after 90 days, they had not received a response.

The trio didn't stop there, finding and demonstrating the exploit in the Rocket Chat and Ryver apps, turning a cross-site scripting attack into remote code execution for the container apps.

View the PoCs and download Little Doctor

The Little Doctor framework is available on GitHub for all security researchers and penetration testers.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS