时间:2025-07-16 03:47:10 来源:网络整理编辑:熱點
A security researcher has uncovered a flaw in Slack that could've been exploited to steal files over
A security researcher has uncovered a flaw in Slack that could've been exploited to steal files over the business messaging app and potentially spread malware.
The flaw involves Slack's Windows desktop app, and how it can automatically send downloaded files to a certain destination—whether it be on your PC or to an online storage server. You can set a download location in the app's preferences section. However, David Wells, a researcher at the security firm Tenable, noticed there's another way to configure the option: Via a special link.
"Crafting a link like 'slack://settings/?update={ 'PrefSSBFileDownloadPath':
Wells realized the same function could be abused. Imagine a hacker using the links to secretly reconfigure a Slack desktop app to send all downloaded files to an outside server. "Using this attack vector, an insider could exploit this vulnerability for corporate espionage, manipulation, or to gain access to documents outside of their purview," Well's security firm Tenable said in a separate report.
The vulnerability can also pave the way for potential malware infections. Any downloaded files sent to the hacker-controller server can be altered and booby-trapped to include malicious code. The attack will commence once the victim opens the file on the Slack desktop app.
The main obstacle of carrying out this attack is circulating the hacker-created links to people on Slack, which keeps its channels private to paying clients and their companies. To pull this off, Wells noticed how Slack channels can be configured to subscribe to RSS feeds, including threads on Reddit.
"I could make a post to a very popular Reddit community that Slack users around the world are subscribed to," Wells said. The hacker-created link will then populate inside the Slack channel and possibly attract some clicks.
"This technique could be unmasked by savvy Slack users, however if decades of phishing campaigns have taught us anything, it's that users click links, and when leveraged through an untrusted RSS feed, the impact can get much more interesting," he added.
Slack has patched the flaw in version 3.4.0 of the Windows desktop app. "We investigated and found no indication that this vulnerability was ever utilized, nor reports that our users were impacted," the company said in an email.
Mom discovers security cameras hacked, kids' bedroom livestreamed2025-07-16 03:29
定位球將成國足“必殺技” 大概率身穿紅色主場球衣2025-07-16 03:18
阿裏和瓜帥女兒再次約會被拍 今年5月曾當眾擁吻2025-07-16 03:18
武磊 :長期封閉非常困難 國足有信心拿下越南2025-07-16 02:57
Fyvush Finkel, Emmy winner for 'Picket Fences,' dies at 932025-07-16 02:50
67%球迷認為內馬爾不該首發 名宿:被換下純因差2025-07-16 01:54
國足後防線麵臨傷病困擾 李鐵愛將表決心 :贏下越南隊2025-07-16 01:51
阿裏和瓜帥女兒再次約會被拍 今年5月曾當眾擁吻2025-07-16 01:43
Visualizing July's astounding global temperature records2025-07-16 01:38
越南主帥用盡招數激勵球員 曾多次觀看中國隊比賽錄像2025-07-16 01:37
Major earthquake and multiple aftershocks rock central Italy2025-07-16 03:42
韓國國腳被女友指控 :與十餘名女性有不正當關係2025-07-16 03:32
滬媒:國足若負越南將重創中國足球 李鐵迎關鍵考驗2025-07-16 03:07
大瓜!曝皮克離間拉波爾塔科曼 甚至推動梅西離開2025-07-16 02:44
Olympian celebrates by ordering an intimidating amount of McDonald's2025-07-16 02:30
亞足聯官網 :中國隊取分仍要靠武磊 他的威脅性最大2025-07-16 02:12
一年無球可踢!昔日廣州隊射手王仍失業 也將要退役?2025-07-16 01:56
越南後衛自信麵對中國歸化:到時就知道我們能做到什麽2025-07-16 01:50
Daughter gives her 1002025-07-16 01:09
吳曦:球員做好了戰鬥準備 要獲勝需做到四點2025-07-16 01:06