A security researcher has uncovered a flaw in Slack that could've been exploited to steal files over the business messaging app and potentially spread malware.
The flaw involves Slack's Windows desktop app, and how it can automatically send downloaded files to a certain destination—whether it be on your PC or to an online storage server. You can set a download location in the app's preferences section. However, David Wells, a researcher at the security firm Tenable, noticed there's another way to configure the option: Via a special link.
"Crafting a link like 'slack://settings/?update={ 'PrefSSBFileDownloadPath':
Wells realized the same function could be abused. Imagine a hacker using the links to secretly reconfigure a Slack desktop app to send all downloaded files to an outside server. "Using this attack vector, an insider could exploit this vulnerability for corporate espionage, manipulation, or to gain access to documents outside of their purview," Well's security firm Tenable said in a separate report.
Credit: david wells / medium / screenshotThe vulnerability can also pave the way for potential malware infections. Any downloaded files sent to the hacker-controller server can be altered and booby-trapped to include malicious code. The attack will commence once the victim opens the file on the Slack desktop app.
The main obstacle of carrying out this attack is circulating the hacker-created links to people on Slack, which keeps its channels private to paying clients and their companies. To pull this off, Wells noticed how Slack channels can be configured to subscribe to RSS feeds, including threads on Reddit.
"I could make a post to a very popular Reddit community that Slack users around the world are subscribed to," Wells said. The hacker-created link will then populate inside the Slack channel and possibly attract some clicks.
"This technique could be unmasked by savvy Slack users, however if decades of phishing campaigns have taught us anything, it's that users click links, and when leveraged through an untrusted RSS feed, the impact can get much more interesting," he added.
Slack has patched the flaw in version 3.4.0 of the Windows desktop app. "We investigated and found no indication that this vulnerability was ever utilized, nor reports that our users were impacted," the company said in an email.
(责任编辑:休閑)
The five guys who climbed Australia's highest mountain, in swimwear
Climbing a freezing cold mountain is already hard enough work. But in briefs? Nope.。It's too late fo
...[详细]
生菜是一種常見的蔬菜,生菜的味道很特別
,生吃也是可以的,耗油生菜是一道很受歡迎的菜 ,蠔油生菜的做法是什麽呢?生菜中含有很多的營養元素,那麽生菜的營養價值有哪些?生菜也是很好種植的一種蔬菜,生菜的種植
...[详细]
假如女性朋友出現外陰瘙癢,有較多的乳白色豆渣樣白帶等病症 ,並且覺得私處灼熱感,憋不住尿、尿疼和性交疼痛。可能便是得了了私處陰道念珠菌病
。克黴唑栓陰道片是治療這類病的。那麼 ,用克黴唑栓陰道片實際效果如何
...[详细]
香蕉有不少的創意吃法 ,這可能是很多人都不知道的吧!直接吃它實在是太落伍了
,發揮一下自己的創意
,就可以把香蕉做成不同的美食了。香蕉的功效也有很多
,常吃它可以幫助保健身體,具體一起來看文章了解一下吧。香
...[详细]Tesla's rumored P100D could make Ludicrous mode even more Ludicrous
A Tesla Model S P100D begs the question: What's more Ludicrous than Ludicrous?Right now, the biggest
...[详细]
南瓜怎麽做好吃?雖然說南瓜直接蒸熟了就可以吃
,但是如果稍微加工一下的話,味道會更好哦!南瓜的功效與作用有哪些?這種食物含有的營養成分很高,常吃的話有益健康。南瓜的食用禁忌有哪些 ?一起來看下文吧。南瓜
...[详细]
黃金百香果的營養成分較為高,適當服用有益於身體健康 ,但黃金百香果味兒呈酸性,很多人吃不消,因此有些人想把它和純蜂蜜一起泡來喝,那麼黃金百香果能夠喝蜂蜜泡水喝嗎?黃金百香果泡純蜂蜜的恰當方式 是啥?點擊
...[详细]
龍須藤是一種中草藥材
,很多人都對它並不是非常的掌握
,尤其是它的綠色植物形狀、作用與功效、使用方法使用量等都並不是十分的清晰
,因此今日我就需要為大夥兒來介紹一下龍須藤,看一下它究竟有什麽功效。點擊圖片進
...[详细]PlayStation Now game streaming is coming to PC
Sony's PlayStation Now service is launching for Windows PC, meaning subscribers will soon be able to
...[详细]
鴿子肉是一種很好的補品
,有很多的營養物質,吃了對身體也有很多的好處 ,那麽鴿子肉的做法有哪些?吃鴿子肉對身體好,鴿子肉的功效和作用有哪些呢?很多人擔心吃了鴿子肉會上火,鴿子肉上火嗎?鴿子肉的做法材料主
...[详细]