时间:2025-10-14 13:25:02 来源:网络整理编辑:熱點
A security researcher has uncovered a flaw in Slack that could've been exploited to steal files over
A security researcher has uncovered a flaw in Slack that could've been exploited to steal files over the business messaging app and potentially spread malware.
The flaw involves Slack's Windows desktop app, and how it can automatically send downloaded files to a certain destination—whether it be on your PC or to an online storage server. You can set a download location in the app's preferences section. However, David Wells, a researcher at the security firm Tenable, noticed there's another way to configure the option: Via a special link.
"Crafting a link like 'slack://settings/?update={ 'PrefSSBFileDownloadPath':
Wells realized the same function could be abused. Imagine a hacker using the links to secretly reconfigure a Slack desktop app to send all downloaded files to an outside server. "Using this attack vector, an insider could exploit this vulnerability for corporate espionage, manipulation, or to gain access to documents outside of their purview," Well's security firm Tenable said in a separate report.
The vulnerability can also pave the way for potential malware infections. Any downloaded files sent to the hacker-controller server can be altered and booby-trapped to include malicious code. The attack will commence once the victim opens the file on the Slack desktop app.
The main obstacle of carrying out this attack is circulating the hacker-created links to people on Slack, which keeps its channels private to paying clients and their companies. To pull this off, Wells noticed how Slack channels can be configured to subscribe to RSS feeds, including threads on Reddit.
"I could make a post to a very popular Reddit community that Slack users around the world are subscribed to," Wells said. The hacker-created link will then populate inside the Slack channel and possibly attract some clicks.
"This technique could be unmasked by savvy Slack users, however if decades of phishing campaigns have taught us anything, it's that users click links, and when leveraged through an untrusted RSS feed, the impact can get much more interesting," he added.
Slack has patched the flaw in version 3.4.0 of the Windows desktop app. "We investigated and found no indication that this vulnerability was ever utilized, nor reports that our users were impacted," the company said in an email.
5 people Tim Cook calls for advice on running the biggest company in the world2025-10-14 13:05
海港遭中乙隊阻擊險翻車 李申圓絕殺難掩攻擊乏力2025-10-14 13:02
韓喬生談唐佳麗:處理世界級 相信女足新帥會招她2025-10-14 12:43
足球博主辟謠足協限製歸化使用 反對李鐵執教但別潑髒水2025-10-14 12:02
U.S. pole vaulter skids to a halt for national anthem2025-10-14 12:00
性感OR變態?C羅手持咖啡沐浴陽光 隻穿了1條內褲2025-10-14 11:48
米蘭官方:邁尼昂手術休戰10周 簽38歲老門將應急2025-10-14 11:47
金童獎20人:佩德裏薩卡領銜 小小馬爾蒂尼入選2025-10-14 11:36
Teacher absolutely nails it with new homework policy2025-10-14 11:13
真大佬!法國總統馬克龍參加慈善賽 對手不敢防他2025-10-14 11:01
PlayStation Now game streaming is coming to PC2025-10-14 13:16
AC米蘭官宣與薩勒馬科爾斯續約 雙方簽約至2026年2025-10-14 12:49
被踢急了?梅西怒噴裁判 :每次都這樣 就像故意的2025-10-14 12:24
洛國富曬國足生涯首球視頻:很高興穿上中國隊服2025-10-14 12:00
17 questions you can answer if you're a good communicator2025-10-14 11:52
阿根廷前瞻 :遭遇客場蟲 梅西率隊欲延續不敗神話2025-10-14 11:46
廣州隊一線隊未集結 中超複賽時將是何種麵貌仍是問號2025-10-14 11:32
C羅熬雞湯:第10次戴帽有特殊意義 感謝隊友球迷2025-10-14 11:29
Give your kitchen sponge a rest on this adorable bed2025-10-14 11:29
中國足協暫無換帥想法 國足倉促換帥曾有慘痛教訓2025-10-14 10:53