时间:2025-11-13 15:31:01 来源:网络整理编辑:熱點
A security researcher has uncovered a flaw in Slack that could've been exploited to steal files over
A security researcher has uncovered a flaw in Slack that could've been exploited to steal files over the business messaging app and potentially spread malware.
The flaw involves Slack's Windows desktop app, and how it can automatically send downloaded files to a certain destination—whether it be on your PC or to an online storage server. You can set a download location in the app's preferences section. However, David Wells, a researcher at the security firm Tenable, noticed there's another way to configure the option: Via a special link.
"Crafting a link like 'slack://settings/?update={ 'PrefSSBFileDownloadPath':
Wells realized the same function could be abused. Imagine a hacker using the links to secretly reconfigure a Slack desktop app to send all downloaded files to an outside server. "Using this attack vector, an insider could exploit this vulnerability for corporate espionage, manipulation, or to gain access to documents outside of their purview," Well's security firm Tenable said in a separate report.
Credit: david wells / medium / screenshotThe vulnerability can also pave the way for potential malware infections. Any downloaded files sent to the hacker-controller server can be altered and booby-trapped to include malicious code. The attack will commence once the victim opens the file on the Slack desktop app.
The main obstacle of carrying out this attack is circulating the hacker-created links to people on Slack, which keeps its channels private to paying clients and their companies. To pull this off, Wells noticed how Slack channels can be configured to subscribe to RSS feeds, including threads on Reddit.
"I could make a post to a very popular Reddit community that Slack users around the world are subscribed to," Wells said. The hacker-created link will then populate inside the Slack channel and possibly attract some clicks.
"This technique could be unmasked by savvy Slack users, however if decades of phishing campaigns have taught us anything, it's that users click links, and when leveraged through an untrusted RSS feed, the impact can get much more interesting," he added.
Slack has patched the flaw in version 3.4.0 of the Windows desktop app. "We investigated and found no indication that this vulnerability was ever utilized, nor reports that our users were impacted," the company said in an email.
Australian football makes history with first LGBT Pride Game2025-11-13 14:52
荷蘭 VS 阿根廷前瞻 :阿根廷 24 年來的第一場半決賽(荷蘭阿根廷半決賽)2025-11-13 14:40
【波盈足球】 世足韓國主帥抱怨 :休息72小時太短 對巴西必苦戰 ( 巴西,葡萄牙 )2025-11-13 14:24
【波盈足球】 世足門將撲救3球 克羅埃西亞PK大戰3比1勝出 ( 西亞,克羅 )2025-11-13 14:10
Fyvush Finkel, Emmy winner for 'Picket Fences,' dies at 932025-11-13 13:57
【波盈足球】 世足梅西怒罵荷蘭前鋒「笨蛋」 意外把老婆逗笑了 ( 梅西,美聯社 )2025-11-13 13:48
【波盈足球】 世足C羅明年確定加盟沙烏地聯賽 身價曝光達161億 ( 納斯,葡萄牙 )2025-11-13 13:48
第22屆世界杯足球賽小組賽綜述及淘汰賽展望(巴西隊為什麽那麽強)2025-11-13 13:44
U.S. pole vaulter skids to a halt for national anthem2025-11-13 13:35
【波盈足球】 世足韓國主帥抱怨 :休息72小時太短 對巴西必苦戰 ( 巴西,葡萄牙 )2025-11-13 13:05
Here's what 'Game of Thrones' actors get up to between takes2025-11-13 15:30
【波盈足球】 足球華南勇敢足夢計畫 助偏鄉足球發展 ( 華南,南投縣 )2025-11-13 15:27
掀起進球狂潮!“中關村杯”區職工足球聯賽小組賽第二輪16場比賽全部結束 !(世界杯預選賽第二階段分組)2025-11-13 14:52
阿根廷難贏荷蘭 ?黑馬終結C羅?世界杯四強預測來了(世界杯阿根廷對荷蘭分析)2025-11-13 13:31
Nate Parker is finally thinking about the woman who accused him of rape2025-11-13 13:08
2022卡塔爾世界杯16強隊伍全部出爐(卡塔爾世界杯最好成績是哪一年)2025-11-13 13:07
【波盈足球】 世足C羅明年確定加盟沙烏地聯賽 身價曝光達161億 ( 納斯,葡萄牙 )2025-11-13 13:05
【波盈足球】 世足「FIFA最佳門將」落難 本屆被踢7球黯然出局 ( 塞內加爾,英格蘭 )2025-11-13 12:54
This company is hiring someone just to drink all day2025-11-13 12:48
世界杯曆史數據紀錄大匯總!(巴西世界杯成績單查詢)2025-11-13 12:45