• Stars
    star
    285
  • Rank 145,115 (Top 3 %)
  • Language
    Go
  • License
    GNU General Publi...
  • Created over 4 years ago
  • Updated about 4 years ago

Reviews

There are no reviews yet. Be the first to send feedback to the community and the maintainers!

Repository Details

Tangalanga: the Zoom conference scanner hacking tool

Tangalanga

Zoom Conference scanner.

This scanner will check for a random meeting id and return information if available.

Install

First try to see if there's any prebaked version for the date: https://github.com/elcuervo/tangalanga/releases.

This versions already have a token ready to use.

Either way you can find the Windows, Linux and Mac version on Releases https://github.com/elcuervo/tangalanga/releases.

Download, uncompress and enjoy.

Usage

This are all the possible flags:

tangalanga \
    -token=user-token \   # [default: env TOKEN]  user token to use.

    -colors=false \       # [default: true]    enable/disable colors
    -censor=true \        # [default: false]   censors output
    -output=history \     # [default: stdout]  write found meetings to file
    -debug=true \         # [default: false]   show all the attmpts
    -tor=true \           # [default: false]   enable tor connection (will use default socks proxy)
    -hidden=true \        # [default: false]   enable embedded tor connection (only linux)
    -rate=7 \             # [default: ncpu]    overwrite the default worker pool

    -proxy=socks5://... \ # [default: socks5://127.0.0.1:9150]   proxy url to use

Tokens

Unfortunately I couldn't find the way the tokens are being generated but the core concept is that the zpk cookie key is being sent during a Join will be usable for ~24 hours before expiring. This makes trivial to join several known meetings, gether some tokens and then use them for the scans.

Tokens can be sniffed after a join attempt to a meeting. This means that to "fish" a token you'll need a setup that can sniff traffic and also spoof certificates.

Using Wireshark, Charles or any other of the ssl-proxying-capable tools out there will do the trick.

TOR (only linux)

Tangalanga has a tor runtime embedded so it can connect to the onion network and run the queries there instead of exposing your own ip.

For any other system I recommend a VPN

Why the bizarre name?

This makes reference to a famous 80s/90s personality in the Rio de la Plata. Doctor Tangalanga who loved to do phone pranks.

More Repositories

1

airplay

Airplay bindings to Ruby
Ruby
1,071
star
2

minuteman

Fast analytics using Redis
Ruby
629
star
3

vcr.js

VCR for javascript
JavaScript
152
star
4

lodis

LOcal Dictionary Server
CoffeeScript
115
star
5

minuteman-rails

Use Minuteman easily in your Rails app
Ruby
64
star
6

gerbil

Gerbil: Inquisitive, friendly animals that rarely bite, TDD for the rest of us
JavaScript
59
star
7

minimalweather

Minimal Weather
JavaScript
30
star
8

cuba-sugar

Give cuba some sugar!
Ruby
20
star
9

shibe

The microframework for Doges
Ruby
15
star
10

dashcat

DashCat - The GitHub viewer
Objective-C
12
star
11

random-octocat

Get a random octocat app
Ruby
12
star
12

picomachine

PicoMachine: minimal finite state machine
JavaScript
11
star
13

flag

Simple feature flags
Ruby
11
star
14

smoking

Simple Mocking and Stubbing for javascript
JavaScript
10
star
15

net-http-pool

Persistent HTTP connection pool
Ruby
9
star
16

shoden

The elephant god
Ruby
8
star
17

minimail

The minimal desktop mail client
JavaScript
7
star
18

nginx_http_redis

Mirror from wiki.nginx.org
C
7
star
19

pythomnic3k

Mirror from sourceforge
Python
7
star
20

net-ptth

Reverse HTTP ruby client
Ruby
7
star
21

phonetap

PhoneTap: give all the PhoneTap js methods to do some testing or develop outside the simulator
CoffeeScript
6
star
22

whereisfoca.com

HTML
6
star
23

backbone-atlas

Backbone compatible json to models converter
JavaScript
5
star
24

coworking-law

5
star
25

limelight_video

Limelight video platform ruby client
Ruby
5
star
26

firma

Adds a secure signature to pdf
Ruby
5
star
27

rpm

Shell
4
star
28

GenUy

Proyecto de bรบsqueda de personas uruguayas
4
star
29

hugware.org

Less hate, more hugs
JavaScript
3
star
30

proof_of_work

A Hashcash algorithm implementation
Ruby
3
star
31

timelapsy

JavaScript
3
star
32

elcuervo.co

Home Page
CSS
3
star
33

cachoo

Ruby
2
star
34

AMD-Backbone-Gerbil-JSDom

Full integration example
JavaScript
2
star
35

hubot-consul-brain

JavaScript
2
star
36

net-http-auth-hmac

Signs Net::HTTP requests
Ruby
2
star
37

macos

Nix
2
star
38

spikefish

Go
2
star
39

twitcher

Twitcher. The ticker with update
Go
2
star
40

wire

HTML5 workers without a separate file
JavaScript
2
star
41

dry-types-json-schema

Ruby
2
star
42

gadget

DNS Docker inspector
Go
2
star
43

geocoder

Go
1
star
44

internationalrubyband.com

1
star
45

pydayuy2011

slides del python day uy 2011
1
star
46

dotfiles-old

Vim Script
1
star
47

spirit

Ruby
1
star
48

cisco_decrypt

Decrypt cisco encrypted passwords
C
1
star
49

dash.cat

The DashCat website
Ruby
1
star
50

dockerfiles

Makefile
1
star
51

machina

Ruby
1
star
52

rubyconfar-2011

JavaScript
1
star
53

phreak

PhoneGap wrapper
JavaScript
1
star
54

ph

Ruby
1
star
55

nixos

Nix
1
star
56

dashcat-test-repo

1
star
57

bankrupt

Ruby
1
star
58

gpm-link

gpm link plugin
Shell
1
star
59

ohm-find_by

find_by to Ohm::Model
Ruby
1
star
60

mobility_bug

Ruby
1
star
61

rest_ejabberd

Ruby interface for ejabberd's mod_restful
Ruby
1
star
62

pythomnic3k-sample-webserver

Python
1
star