A security researcher has uncovered a flaw in Slack that could've been exploited to steal files over the business messaging app and potentially spread malware.
The flaw involves Slack's Windows desktop app, and how it can automatically send downloaded files to a certain destination—whether it be on your PC or to an online storage server. You can set a download location in the app's preferences section. However, David Wells, a researcher at the security firm Tenable, noticed there's another way to configure the option: Via a special link.
"Crafting a link like 'slack://settings/?update={ 'PrefSSBFileDownloadPath':
Wells realized the same function could be abused. Imagine a hacker using the links to secretly reconfigure a Slack desktop app to send all downloaded files to an outside server. "Using this attack vector, an insider could exploit this vulnerability for corporate espionage, manipulation, or to gain access to documents outside of their purview," Well's security firm Tenable said in a separate report.
Credit: david wells / medium / screenshotThe vulnerability can also pave the way for potential malware infections. Any downloaded files sent to the hacker-controller server can be altered and booby-trapped to include malicious code. The attack will commence once the victim opens the file on the Slack desktop app.
The main obstacle of carrying out this attack is circulating the hacker-created links to people on Slack, which keeps its channels private to paying clients and their companies. To pull this off, Wells noticed how Slack channels can be configured to subscribe to RSS feeds, including threads on Reddit.
"I could make a post to a very popular Reddit community that Slack users around the world are subscribed to," Wells said. The hacker-created link will then populate inside the Slack channel and possibly attract some clicks.
"This technique could be unmasked by savvy Slack users, however if decades of phishing campaigns have taught us anything, it's that users click links, and when leveraged through an untrusted RSS feed, the impact can get much more interesting," he added.
Slack has patched the flaw in version 3.4.0 of the Windows desktop app. "We investigated and found no indication that this vulnerability was ever utilized, nor reports that our users were impacted," the company said in an email.
(责任编辑:探索)
Two astronauts just installed a new parking spot on the International Space Station
Best and worst of 2021 Emmys
'The Office' stars share the story behind the famous Michael screaming meme
How to use Tinder's new Explore feature
Metallica to seek and destroy your eardrums with new album this fallMajor earthquake and multiple aftershocks rock central Italy
UPDATE: Aug. 25, 2016, 8:22 a.m. BST
。 Death toll is now at least 247 dead: 190 in Rieti province and
...[详细]How sextech aims to help people with disabilities masturbate
Sextech is bringing a much-needed cultural shift in how we view, talk about, and sell sex. Ushered i
...[详细]How much does every iPhone 13 cost?
Better hope you're making that pro money. Apple is known for its sleek and pricey phones, and at its
...[详细]Google Meet declares war on that sunny window behind you that's making you underexposed
Google Meet's camera software is getting smarter. On Monday, Google announced a neat little upgrade
...[详细]'The Flying Bum' aircraft crashes during second test flight
Airlander 10, the world's largest aircraft, on Wednesday crashed at its Cardington Airfield base in
...[详细]14 coolest Tesla features that put your regular car to shame
Tesla's reputation often precedes it. But no matter what you think of the electric car company's "un
...[详细]'The Office' almost had a different theme song: A legendary pop hit.
Doo DOO do do do do do, do do dodododo...The Officehas one of the most beloved, catchy, unique theme
...[详细]Best podcasts for when you're on vacation, traveling, or taking a road trip
After over a year of isolation, wanderlust is swirling in the air, as many seek safe ways to re-emer
...[详细]Visualizing July's astounding global temperature records
July set a rare temperature record during a year that is featuring off the charts warmth. The month
...[详细]'Golden' is an insightful and necessary post
Filmed in the months leading up to the Tokyo 2020 Olympics, Peacock's docuseries Golden: The Journey
...[详细]Nate Parker is finally thinking about the woman who accused him of rape

The size and price of every iPhone ever released
