Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Data egress via audio #175

Open
TonyWildish-BH opened this issue Oct 10, 2024 · 0 comments
Open

Data egress via audio #175

TonyWildish-BH opened this issue Oct 10, 2024 · 0 comments
Assignees
Labels
bug Something isn't working EPIC - Pen-test fixes Fixing security issues found during penetration testing MVP Things that need to be considered for the MVP release

Comments

@TonyWildish-BH
Copy link
Collaborator

TonyWildish-BH commented Oct 10, 2024

The penetration testing report showed that (page 21):

Narration tools available by default could be used to exfiltrate data from the environment, whereby an attacker could leverage speech to text tools to convert to its original format.

This can be addressed via Guacamole, by setting disable-audio to true in the guacamole.properties file.

It would also be useful to allow the possibility of enabling audio, if needed for accessibility purposes.

This is a medium level risk, but is something we must fix before the next pen-test.

@TonyWildish-BH TonyWildish-BH added bug Something isn't working MVP Things that need to be considered for the MVP release EPIC - Pen-test fixes Fixing security issues found during penetration testing labels Oct 10, 2024
@TonyWildish-BH TonyWildish-BH self-assigned this Oct 10, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working EPIC - Pen-test fixes Fixing security issues found during penetration testing MVP Things that need to be considered for the MVP release
Projects
None yet
Development

No branches or pull requests

1 participant