时间:2025-09-14 08:09:20 来源:网络整理编辑:熱點
A security researcher has uncovered a flaw in Slack that could've been exploited to steal files over
A security researcher has uncovered a flaw in Slack that could've been exploited to steal files over the business messaging app and potentially spread malware.
The flaw involves Slack's Windows desktop app, and how it can automatically send downloaded files to a certain destination—whether it be on your PC or to an online storage server. You can set a download location in the app's preferences section. However, David Wells, a researcher at the security firm Tenable, noticed there's another way to configure the option: Via a special link.
"Crafting a link like 'slack://settings/?update={ 'PrefSSBFileDownloadPath':
Wells realized the same function could be abused. Imagine a hacker using the links to secretly reconfigure a Slack desktop app to send all downloaded files to an outside server. "Using this attack vector, an insider could exploit this vulnerability for corporate espionage, manipulation, or to gain access to documents outside of their purview," Well's security firm Tenable said in a separate report.
Credit: david wells / medium / screenshotThe vulnerability can also pave the way for potential malware infections. Any downloaded files sent to the hacker-controller server can be altered and booby-trapped to include malicious code. The attack will commence once the victim opens the file on the Slack desktop app.
The main obstacle of carrying out this attack is circulating the hacker-created links to people on Slack, which keeps its channels private to paying clients and their companies. To pull this off, Wells noticed how Slack channels can be configured to subscribe to RSS feeds, including threads on Reddit.
"I could make a post to a very popular Reddit community that Slack users around the world are subscribed to," Wells said. The hacker-created link will then populate inside the Slack channel and possibly attract some clicks.
"This technique could be unmasked by savvy Slack users, however if decades of phishing campaigns have taught us anything, it's that users click links, and when leveraged through an untrusted RSS feed, the impact can get much more interesting," he added.
Slack has patched the flaw in version 3.4.0 of the Windows desktop app. "We investigated and found no indication that this vulnerability was ever utilized, nor reports that our users were impacted," the company said in an email.
Over 82,000 evacuate as Blue Cut fire rapidly spreads in southern California2025-09-14 07:59
曝蘇寧俱樂部二十年老員工到手補償 隻有所欠金額一半不到2025-09-14 07:53
曝萊萬心屬巴薩拒切爾西邀約 雙方已談妥個人條款2025-09-14 07:46
曝萊萬心屬巴薩拒切爾西邀約 雙方已談妥個人條款2025-09-14 07:46
You can now play 'Solitaire' and 'Tic2025-09-14 07:01
2022東亞杯賽程:中國男足首戰韓國 女足對陣中國台北2025-09-14 07:01
白菜價?萊萬已接受巴薩合同 年薪僅800萬簽約3年2025-09-14 06:36
國足本年度將不會再組織集訓 亦不可能參加任何國際比賽2025-09-14 06:25
Fyvush Finkel, Emmy winner for 'Picket Fences,' dies at 932025-09-14 06:02
有一種極為微小的可能 曼城利物浦加賽定英超冠軍2025-09-14 05:25
Fake news reports from the Newseum are infinitely better than actual news2025-09-14 08:06
克洛普 :利物浦當然對姆巴佩有意 我們又不是瞎子2025-09-14 08:01
神邏輯 !一球迷偷球衣被抓:穆氏羅馬讓我情難自已2025-09-14 07:36
曝蘇寧球員自行墊付百萬醫療費 還沒報銷俱樂部已解散2025-09-14 06:56
Olympic security asks female Iranian fan to drop protest sign2025-09-14 06:54
吃一塹長兩智!曼聯擱置兩主力續約 靜待滕哈格拍板2025-09-14 06:25
克洛普:賽前不會和傑拉德交流 末輪就是做好自己2025-09-14 06:10
足協本周將官宣中超賽程 揭幕戰山東泰山VS重慶兩江競技2025-09-14 06:08
Felix the cat just raised £5000 for charity because she's the hero we all need2025-09-14 05:59
生涯最佳交易?馬洛塔:免簽博格巴 再高價賣給曼聯2025-09-14 05:35