Zoom - turning on someone's camera using SQL injection vulnerability - Bug Bounty Reports Explained

Опубликовано: 28 Март 2026
на канале: Bug Bounty Reports Explained
225,249
8.4k

📧 Subscribe to BBRE Premium: https://bbre.dev/premium
✉️ Sign up for the mailing list: https://bbre.dev/nl
📣 Follow me on Twitter: https://bbre.dev/tw

This video is about local SQLinjection vulnerability in Linux and MacOS desktop applications of Zoom - conference app that gained even more popularity as remote meeting got more common in 2020. Exploiting the SQLi required to bypass doubling quotes protection that Zoom app used.

Original writeup:
  / patched-zoom-exploit-altering-camera-setti...  
Keegan's twitter:
  / inf_0_  

Follow me on twitter:
  / gregxsunday  

Timestamps:
00:00 Intro
00:25 Initial discovery - zoommtg:// links
01:24 Analysing the binary
03:06 SQLi protection
03:55 ASCII & UTF-8
05:17 bypassing the SQLi protection
06:45 Impact


#sqli