时间:2026-05-23 15:51:09 来源:网络整理编辑:娛樂
A security researcher has uncovered a flaw in Slack that could've been exploited to steal files over
A security researcher has uncovered a flaw in Slack that could've been exploited to steal files over the business messaging app and potentially spread malware.
The flaw involves Slack's Windows desktop app, and how it can automatically send downloaded files to a certain destination—whether it be on your PC or to an online storage server. You can set a download location in the app's preferences section. However, David Wells, a researcher at the security firm Tenable, noticed there's another way to configure the option: Via a special link.
"Crafting a link like 'slack://settings/?update={ 'PrefSSBFileDownloadPath':
Wells realized the same function could be abused. Imagine a hacker using the links to secretly reconfigure a Slack desktop app to send all downloaded files to an outside server. "Using this attack vector, an insider could exploit this vulnerability for corporate espionage, manipulation, or to gain access to documents outside of their purview," Well's security firm Tenable said in a separate report.
Credit: david wells / medium / screenshotThe vulnerability can also pave the way for potential malware infections. Any downloaded files sent to the hacker-controller server can be altered and booby-trapped to include malicious code. The attack will commence once the victim opens the file on the Slack desktop app.
The main obstacle of carrying out this attack is circulating the hacker-created links to people on Slack, which keeps its channels private to paying clients and their companies. To pull this off, Wells noticed how Slack channels can be configured to subscribe to RSS feeds, including threads on Reddit.
"I could make a post to a very popular Reddit community that Slack users around the world are subscribed to," Wells said. The hacker-created link will then populate inside the Slack channel and possibly attract some clicks.
"This technique could be unmasked by savvy Slack users, however if decades of phishing campaigns have taught us anything, it's that users click links, and when leveraged through an untrusted RSS feed, the impact can get much more interesting," he added.
Slack has patched the flaw in version 3.4.0 of the Windows desktop app. "We investigated and found no indication that this vulnerability was ever utilized, nor reports that our users were impacted," the company said in an email.
Man stumbles upon his phone background in real life2026-05-23 15:44
哈蘭德下家賠率:曼城巨大優勢領跑 皇馬僅第四2026-05-23 15:29
梅羅時代畫上句號 !16年來首均無緣八強 輸給了時間2026-05-23 15:03
梅羅時代畫上句號!16年來首均無緣八強 輸給了時間2026-05-23 14:45
Tesla's rumored P100D could make Ludicrous mode even more Ludicrous2026-05-23 14:10
河北隊確認金鍾夫將執掌帥印 教練組核心成員已抵華隔離2026-05-23 14:08
歐冠20球最年輕球員:哈蘭德姆巴佩領銜 梅西排第三2026-05-23 13:30
日本男足25日約戰韓國隊 僅國足40強賽前無國際熱身賽2026-05-23 13:22
Two astronauts just installed a new parking spot on the International Space Station2026-05-23 13:18
泰山隊做好2巴西外援不能歸隊準備 姚均晟離隊僅差官宣2026-05-23 13:10
Make money or go to Stanford? Katie Ledecky is left with an unfair choice.2026-05-23 15:15
青島外援武科維奇結束隔離 跟隊進行恢複性訓練2026-05-23 15:08
曝吳曦更傾向加盟申花 廣州隊沒有具體引進動作2026-05-23 15:03
泰山隊拒放孫準浩回韓國國家隊 金玟哉也將缺席熱身2026-05-23 14:52
This coloring book is here for all your relationship goals2026-05-23 14:50
曼聯五大候選新門 :德赫亞換奧布拉克 免簽多納魯馬2026-05-23 14:43
科曼 :梅西看到了巴薩正回歸正軌 我認為他會留下2026-05-23 14:33
梅西走到生涯十字路口 豪賭巴薩or赴巴黎抱大腿?2026-05-23 14:23
Xiaomi accused of copying again, this time by Jawbone2026-05-23 14:07
泰山隊曾準備兩套均衡陣容欲搏亞冠 遺憾被取消資格2026-05-23 13:43