Abstract:
Web-based conferencing systems are widely used, but security claims rarely backed up by thorough analysis. In this thesis, we audit server components of BigBlueButton, a conferencing system for distance education, for resilience against malicious clients. Our evaluation finds a total of 45 security vulnerabilities affecting BigBlueButton 2.3.3. These include broken access control, NoSQL injections, and multiple vulnerabilities that allow for eavesdropping.