Only zoom AFAIK however others run xmpp servers and clients, and it might be useful to understand this oversight.
neoxhas joined
jgarthas joined
millesimushas left
millesimushas joined
Silvio Titzmannhas joined
yushyinhas left
test1has joined
yushyinhas joined
writer77has joined
Samhas joined
jchas left
test1has left
test1has joined
antranigvhas left
stampirlhas joined
thndrbvrhas joined
myjabber1337has left
myjabber1337has joined
MSavoritias (she,they)has joined
antranigvhas joined
jl4has left
greenkeeperhas joined
Silvio Titzmannhas left
jchas joined
Silvio Titzmannhas joined
Licaon_Kterhas left
thndrbvr
So since that company is monetarily wealthy and hugely popular, how much code and money (or documentation, security audits, et. al.) have they been contributing to the wider XMPP ecosystem?
Licaon_Kterhas joined
jgarthas left
Licaon_Kter
thndrbvr: it's ~opensource~free so just put a note on the site, in the basement, unde the cupboard, behind the sign that reads "beware of the communism"✎
Licaon_Kter
thndrbvr: it's ~opensource~free so just put a note on the site, in the basement, under the cupboard, behind the sign that reads "beware of the communism" ✏
Licaon_Kter
ejabberd is just GPL2 you silly libre fanboi, not AGPL...
Samhas left
yushyinhas left
antranigvhas left
antranigvhas joined
yushyinhas joined
yushyinhas left
yushyinhas joined
大明白20210720has left
ianhas left
ianhas joined
greenkeeperhas left
greenkeeperhas joined
adrian@kiess.onlhas left
TheCoffeMakerhas left
bakehas joined
adrian@kiess.onlhas joined
myjabber1337has left
abdullahhas left
abdullahhas joined
antranigvhas left
abdullah
Where are Jabber's emails?
大明白20210720has joined
patascahas joined
ernst.on.tour
> Where are Jabber's emails?
*What* are Jabber's emails ?
TheCoffeMakerhas joined
abdullah
You cannot receive messages on your membership as an email
John has left
John has joined
abdullah
> I wrote:
> You cannot receive messages on your membership as an email
Or rather, you use Jabber
's membership as your mailing address
Licaon_Kter
abdullah: you'd need some sort of xmpp-to-email gateway I guess
abdullah
> Licaon_Kter wrote:
> abdullah: you'd need some sort of xmpp-to-email gateway I guess
How is that
svenhas left
svenhas joined
ianhas left
ianhas joined
mathieui
thndrbvr: considering the scale at which zoom operates, I would suppose they are in a rather lucrative paid contract with the ejabberd company, which contributes to the ecosystem
վարյաhas left
վարյաhas joined
barlashas left
barlashas joined
bookadouhas left
antranigvhas joined
վարյաhas left
վարյաhas joined
jl4has joined
bookadouhas joined
Menelhas left
jl4has left
balabol.imhas left
quantumwingshas left
ernst.on.tour
> abdullah: you'd need some sort of xmpp-to-email gateway I guess
I've prepared a little python script that is running in my prosody-server and it listen on port 25 and "forward" as a xmpp-msg the senders email, subject and plaintext-body to your xmpp-account.
So you will get informed about wrong use of your xxmp-address and you are able to open your mail-client to answer him something like "Wrong address, please use a xmpp-client or deliver your mail to xyz@mailbox"
balabol.imhas joined
abdullah
> ernst.on.tour wrote:
> I've prepared a little python script that is running in my prosody-server and it listen on port 25 and "forward" as a xmpp-msg the senders email, subject and plaintext-body to your xmpp-account.
> So you will get informed about wrong use of your xxmp-address and you are able to open your mail-client to answer him something like "Wrong address, please use a xmpp-client or deliver your mail to xyz@mailbox"
Thanks
greenkeeperhas left
greenkeeperhas joined
վարյաhas left
վարյաhas joined
balabol.imhas left
Bjarkanhas left
balabol.imhas joined
patascahas left
Bjarkanhas joined
վարյաhas left
վարյաhas joined
Bjarkanhas left
ilmaisin_has left
pseikoheikohas left
greenkeeperhas left
greenkeeperhas joined
Bjarkanhas joined
Bjarkanhas left
վարյաhas left
վարյաhas joined
վարյաhas left
վարյաhas joined
Samhas joined
*IM*has left
beanhas joined
Silvio Titzmannhas left
Samhas left
Bjarkanhas joined
antranigvhas left
antranigvhas joined
Menelhas joined
*IM*has joined
writer77has left
Bjarkanhas left
antranigvhas left
antranigvhas joined
վարյաhas left
վարյաhas joined
millesimushas left
Silvio Titzmannhas joined
Menelhas left
antranigvhas left
antranigvhas joined
antranigvhas left
antranigvhas joined
վարյաhas left
վարյաhas joined
test1has left
kazihas joined
վարյաhas left
վարյաhas joined
վարյաhas left
վարյաhas joined
purhas joined
froghas left
froghas joined
candyman188has left
greenkeeperhas left
greenkeeperhas joined
վարյաhas left
վարյաhas joined
pseikoheikohas joined
test1has joined
test1has left
test1has joined
mazenghubarihas joined
myjabber1337has joined
hotaruhas left
վարյաhas left
վարյաhas joined
b43has left
hotaruhas joined
Bjarkanhas joined
b43has joined
abdullahhas left
balabol.imhas left
b43has left
b43has joined
balabol.imhas joined
kikuchiyohas joined
abdullahhas joined
waelhas left
waelhas joined
millesimushas joined
Ivan A.has left
mazenghubarihas left
Tyler B. Joneshas left
test1has left
croaxhas left
croaxhas joined
Ivan A.has joined
test1has joined
test1has left
test1has joined
Wojtekhas joined
WojtekIMhas joined
gooyahas joined
Silvio Titzmannhas left
b43has left
վարյաhas left
վարյաhas joined
Tyler B. Joneshas joined
croaxhas left
croaxhas joined
վարյաhas left
վարյաhas joined
balabol.imhas left
andrey.utkinhas left
surenhas left
surenhas joined
վարյաhas left
balabol.imhas joined
abdullahhas left
Ivan A.has left
greyhas left
greyhas joined
abdullahhas joined
somenamehas joined
greyhas left
greyhas joined
Samhas joined
Ivan A.has joined
Ivan A.has left
Ivan A.has joined
somenamehas left
somenamehas joined
վարյաhas joined
Katherinehas left
Holgerhas left
abdullahhas left
Holgerhas joined
abdullahhas joined
karmehas left
im0209has joined
antranigvhas left
ianhas left
ianhas joined
Tyler B. Joneshas left
Tyler B. Joneshas joined
im0209has left
ianhas left
ianhas joined
emushas joined
homebeachhas left
homebeachhas joined
Ivan A.has left
Ivan A.has joined
Silvio Titzmannhas joined
anamulhaquehas joined
Ivan A.has left
Ivan A.has joined
antranigvhas joined
jl4has joined
Holgerhas left
Holgerhas joined
myjabber1337has left
myjabber1337has joined
anamulhaquehas left
barlashas left
surenhas left
surenhas joined
վարյաhas left
վարյաhas joined
Tyler B. Joneshas left
Tyler B. Joneshas joined
candyman188has joined
barlashas joined
Ivan A.has left
Ivan A.has joined
*IM*has left
test1has left
test1has joined
andrey.utkinhas joined
test1has left
test1has joined
Ivan A.has left
Ivan A.has joined
RayTutuhas joined
patascahas joined
*IM*has joined
jl4has left
jl4has joined
rosshas left
rosshas joined
barlashas left
henrikhas left
karmehas joined
barlashas joined
Samhas left
froghas left
Samhas joined
somenamehas left
somenamehas joined
大明白20210720has left
jl4has left
大明白20210720has joined
Steven Roosehas left
kryptoshas joined
Steven Roosehas joined
ianhas left
ianhas joined
patascahas left
surenhas left
henrikhas joined
surenhas joined
RayTutu
> SJM: who operates Zoom on their servers?
FWIW, the vulnerability was in the expat XML library (used by ejabberd and others). Expat version 2.4.5 fixed the issue back in February.
https://blog.hartwork.org/posts/expat-2-4-5-released/
pseikoheikohas left
surenhas left
rosshas left
surenhas joined
rosshas joined
barlashas left
RayTutu
At high level, someone could send a message to a user which could have appeared to come from the server due to a UTF-8 parsing vulnerability in libexpat. Exploitability was demonstrated with Zoom by causing the client to perform a software upgrade, which would be a malicious package.
barlashas joined
Wojtekhas left
WojtekIMhas left
abdullahhas left
Holgerhas left
大明白20210720has left
MattJ
RayTutu, Zoom is not using libexpat, but gloox
MattJ
The Zoom RCE is different to the libexpat CVEs
purhas left
moparisthebest
right but there are 2 libexpat CVEs in there and an additional ejabberd bug no one bothered reporting to ejabberd (I pinged them in their MUC yesterday)
moparisthebest
also pinged the only client anyone knows of that uses gloox which is vulnerable to the impersonation bug, which is Renga on Haiku
myjabber1337has left
大明白20210720has joined
moparisthebest
actually might be ok if you've upgraded your expat https://github.com/processone/fast_xml/issues/46
patascahas joined
Holgerhas joined
大明白20210720has left
RayTutu
MattJ: correct, I agree. I prefixed my statement with "high level" because it's actually a vulnerability chain but perhaps I shouldn't have. Vulnerabilities in the Zoom client (which uses gloox) were combined with a vulnerability in Zoom server (ejabberd/fast_xml/libexpat) to achieve results. The CVEs this community should be concerned about are the updates to libexpat and fast_xml. The other CVEs were specific to Zoom (RCE), but were _enabled_ by the expat vulnerability. Expat alone did not have an RCE vulnerability.
RayTutu
moparisthebest: from what I can tell, assuming your distribution has picked up expat 2.4.5 or later, I think it's fine.
Wojtekhas joined
WojtekIMhas joined
emushas left
emushas joined
abdullahhas joined
大明白20210720has joined
homebeachhas left
homebeachhas joined
moparisthebest
RayTutu, and anything using gloox, but as far as I know that's just the 1 client on Haiku
moparisthebest
gloox has not released a fix, I pinged the author with no response