Stanza smuggling attacks are a dangerous and underexplored attack surface in XMPP protocol that can be found using fuzzing. These attacks can lead to message spoofing, interception of private communication, and even zero-click RCE.
- Stanza smuggling attacks are a dangerous and underexplored attack surface in XMPP protocol
- Fuzzing can be used to find these types of attacks
- Stanza smuggling attacks can lead to message spoofing, interception of private communication, and even zero-click RCE
The speaker demonstrated a zero-click RCE attack on Zoom using stanza smuggling. The attack involved intercepting the victim's communication and launching a payload in the background after the victim updated Zoom. Instead of launching the updated version of Zoom, the victim's computer launched a calculator. This attack was possible due to a vulnerability in the XMPP protocol that allowed for stanza smuggling.