This popular presentation tool has some major security flaws

The cybersecurity firm F-Secure has discovered several exploitable vulnerabilities in a popular wireless presentation system the could allo...

The cybersecurity firm F-Secure has discovered several exploitable vulnerabilities in a popular wireless presentation system the could allow an attacker to manipulate information during presentations, steal passwords and other sensitive information and even install backdoors and other malware.

The firm found the vulnerabilities in Barco's ClickShare wireless presentation system which is a collaboration tool that allows users to present content from a variety of devices.

Senior consultant at F-Secure Consulting, Dmitry Janushkevich explained that the popularity of user-friendly tools makes them the perfect targets for hackers, saying:

“The system is so practical and easy to use, people can’t see any reason to mistrust it. But its deceptive simplicity hides extremely complex inner workings, and this complexity makes security challenging. The everyday objects that people trust without a second thought make the best targets for attackers, and because these systems are so popular with companies, we decided to poke at it and see what we could learn.” 

Barco ClickShare

Janushkevich and his colleagues at F-Secure consulting then began researching the ClickShare system on-an-off for several months after noticing how popular it was during red team assessments. The team discovered multiple exploitable flaws, 10 of which have CVE (Common Vulnerabilities and Exposures) identifiers.

These different issues facilitated a wide variety of attacks including intercepting information shared through the system, using the system to install backdoors or other malware on users' computers and stealing information and passwords. Exploiting some of the vulnerabilities requires physical access but F-Secure consulting also found that others can be executed remotely if the system uses its default settings.

According to Janushkevich, the execution of the exploits in Barco ClickShare can be done quickly by a skilled attacker with physical access (possibly while posing as a cleaner or office worker), allowing them to inconspicuously compromise the device.

F-Secure Consulting shared its research with Barco back in November and the two companies then worked together in a coordinated disclosure effort. Barco has now published a firmware update on their website to mitigate the most critical vulnerabilities though several of the issues involve hardware components that require physical maintenance to address and are unlikely to get fixed.



from TechRadar - All the latest technology news https://ift.tt/2PPiKSV
via IFTTT

COMMENTS

BLOGGER
Name

Latest from TechRadar,63, 9to5Mac,7, AI News & Artificial Intelligence | TechCrunch,2, Apple,10, Cointelegraph.com News,9, Electrek,5, Space Explored,2, Technology,108, The Verge,45, TrendlyNews,27, YouTube - 9to5Google,13,9to5Mac,10,AI,2,Apps,4063,Business,151,Camera,1162,Crypto,9,Earn $$$,3,Gadgets,1741,Games,927,GTA,1,IFTTT,7,Innovations,3,Mobile,1700,Paid Promotions,5,Promotions,5,Space,2,Sports,1,Technology,8808,Trailers,796,Travel,37,Trending,4,Trendly News,25458,TrendlyNews,342,Vehicles,5,Video,5,XIAOMI,13,YouTube - 9to5Google,219,
ltr
item
TrendlyNews | #ListenNow #Everyday #100ShortNews #TopTrendings #PopularNews #Crypto #Ai #TrendlyNews: This popular presentation tool has some major security flaws
This popular presentation tool has some major security flaws
TrendlyNews | #ListenNow #Everyday #100ShortNews #TopTrendings #PopularNews #Crypto #Ai #TrendlyNews
http://www.trendlynews.in/2019/12/this-popular-presentation-tool-has-some.html
http://www.trendlynews.in/
http://www.trendlynews.in/
http://www.trendlynews.in/2019/12/this-popular-presentation-tool-has-some.html
true
3372890392287038985
UTF-8
Loaded All Posts Not found any posts VIEW ALL Readmore Reply Cancel reply Delete By Home PAGES POSTS View All RECOMMENDED FOR YOU LABEL ARCHIVE SEARCH ALL POSTS Not found any post match with your request Back Home Sunday Monday Tuesday Wednesday Thursday Friday Saturday Sun Mon Tue Wed Thu Fri Sat January February March April May June July August September October November December Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec just now 1 minute ago $$1$$ minutes ago 1 hour ago $$1$$ hours ago Yesterday $$1$$ days ago $$1$$ weeks ago more than 5 weeks ago Followers Follow THIS PREMIUM CONTENT IS LOCKED STEP 1: Share. STEP 2: Click the link you shared to unlock Copy All Code Select All Code All codes were copied to your clipboard Can not copy the codes / texts, please press [CTRL]+[C] (or CMD+C with Mac) to copy