Skip to content

Instantly share code, notes, and snippets.

@lrvick
Created April 13, 2018 21:14
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save lrvick/6e600d8484cfb415d1e2b06e8b3452c2 to your computer and use it in GitHub Desktop.
Save lrvick/6e600d8484cfb415d1e2b06e8b3452c2 to your computer and use it in GitHub Desktop.

Lifesize security audit

Lifesize Icon 450

Firmware Audited: Build date: Mon Aug 28 07:08:05 CDT 2017 Build host: ausbuildlifesizecodecicon02 (127.0.1.1) Build location: http://artifacts.lifesize.com/artifactory/lifesize.icon.production/lifesize.icon.production.master.sequoia.full-3.4.0.2268.tar.gz Build version: LS_RM3_3.4.0 (2268) Build type: PRODUCTION Build target: sequoia SVN; SVN%

Findings:

Lifesize Screen Sharing And Scheduling - Chrome Plugin

Version: Chrome Web Store release as of 09/0/17

Findings:

  • Full access to browser history and *.lifesize.com domains
  • Jquery 2.1.4
  • NPM dependencies are locked using only fuzzy versions and no hash locking. Dependency attacks are on the table if no other mitigations are present.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment