If the WhatsApp exploit works without answering, then it must be in the signaling code, which would have a very small attack surface. So maybe calls include pushing contact info over (eg, display name, avatar, etc) and the bug is in that code (seems more likely)... any info yet?
-
- Show this thread
-
Documentation is here: https://m.facebook.com/security/advisories/cve-2019-3568 … Bug in SRTCP https://tools.ietf.org/html/rfc3711 So it is in signaling, but I’d think you’d need to answer the call to do RTP. Unless WhatsApp doesn’t do a normal VOIP trapezoid.
Show this thread -
This WhatsApp exploit would be perfect for counterterrorism as WhatsApp is fairly popular as a comms channel for jihadists.
Show this thread -
Ok, the not answering kinda makes sense. SRTCP is used to calculate keys for encrypting the media so it might make sense as an optimization to do that while the call is ringing, rather than introduce a delay after answering. (Pure speculation)
Show this thread -
“specially crafted series of SRTCP packets” — sounds complex. Hope someone is diffing the patch and does a write up.
Show this thread -
The NYT article mentions that a target received a number of missed calls overnight. Sounds like the exploit isn’t super reliable, or maybe heap massage via missed calls is pretty complicated. Can’t believe the NSO implant didn’t do basic anti forensics and clean up the mess.
Show this thread End of conversation
New conversation -
-
-
oh yeah, I’m sure they’re just gonna fax you a copy right away...
-
It’ll be in metasploit inside a month ;)
-
YOU’RE GONNA LEAK IT!?!?!?!1/1/1/1/11
-
I’m gonna leak like Snowden with someone else’s PKI card and a Linux USB stick! Woo!
-
As if you have any idea how to use SharePoint...
-
Maybe they need a wget specialist?
-
next infiltrate talk confirmed.
End of conversation
New conversation -
-
-
Available at your local
#APT outlet. The Woozy BearsUse code MOSSAD25 for a 25% discount
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.