A Broken Commercial Metaverse-based Virtual Office Platform by Team MetaVersPloit | Nullcon Berlin
About this talk
This talk discusses the security vulnerabilities identified in metaverse-based virtual office platforms, highlighting 31 critical vulnerabilities across four platforms. The speakers present various attack scenarios, including remote code execution, local privilege escalation, eavesdropping, cross-site scripting, and denial of service attacks, supported by proof-of-concept code. They analyze 13 common functionalities found in these platforms, outline the technology stack for each, and detail the potential impact of these vulnerabilities, such as unauthorized function access and service interruptions. The session also offers countermeasures for platforms like Gethertown, Orbis, Kumospace, and Space, while addressing potential threats from other metaverse environments and suggesting technical measures to enhance security during the design phase.
More from this event
See all 19 talks →
Keynote | High-assurance Code Reviews: How Consulting Works When The Risks Are High by Dan Guido
49:15
Night Track | GNU Anastasis: Privacy-Preserving Key Backup And Recovery by Christian Grothoff
28:47
Fuzzware: Automating & Scaling Fuzzing For Firmware by Tobias Scharnowski & Marius Muench | Nullcon
39:10
CXO Panel | Digital Identity In The Age Of Fintech | Nullcon Berlin 2022
56:07