时间:2026-05-23 14:42:27 来源:网络整理编辑:娛樂
A security researcher has uncovered a flaw in Slack that could've been exploited to steal files over
A security researcher has uncovered a flaw in Slack that could've been exploited to steal files over the business messaging app and potentially spread malware.
The flaw involves Slack's Windows desktop app, and how it can automatically send downloaded files to a certain destination—whether it be on your PC or to an online storage server. You can set a download location in the app's preferences section. However, David Wells, a researcher at the security firm Tenable, noticed there's another way to configure the option: Via a special link.
"Crafting a link like 'slack://settings/?update={ 'PrefSSBFileDownloadPath':
Wells realized the same function could be abused. Imagine a hacker using the links to secretly reconfigure a Slack desktop app to send all downloaded files to an outside server. "Using this attack vector, an insider could exploit this vulnerability for corporate espionage, manipulation, or to gain access to documents outside of their purview," Well's security firm Tenable said in a separate report.
Credit: david wells / medium / screenshotThe vulnerability can also pave the way for potential malware infections. Any downloaded files sent to the hacker-controller server can be altered and booby-trapped to include malicious code. The attack will commence once the victim opens the file on the Slack desktop app.
The main obstacle of carrying out this attack is circulating the hacker-created links to people on Slack, which keeps its channels private to paying clients and their companies. To pull this off, Wells noticed how Slack channels can be configured to subscribe to RSS feeds, including threads on Reddit.
"I could make a post to a very popular Reddit community that Slack users around the world are subscribed to," Wells said. The hacker-created link will then populate inside the Slack channel and possibly attract some clicks.
"This technique could be unmasked by savvy Slack users, however if decades of phishing campaigns have taught us anything, it's that users click links, and when leveraged through an untrusted RSS feed, the impact can get much more interesting," he added.
Slack has patched the flaw in version 3.4.0 of the Windows desktop app. "We investigated and found no indication that this vulnerability was ever utilized, nor reports that our users were impacted," the company said in an email.
Aly Raisman catches Simone Biles napping on a plane like a champion2026-05-23 13:52
《夜空中最閃亮的星》熱播 黃子韜變身鄭柏旭強勢圈粉2026-05-23 13:44
揭秘傳奇八門 《外八門之黃金羅盤》定檔優酷3.282026-05-23 13:21
《出線了 ,初戀》熱播 鄭合惠子被“公主扛”? 網友 :我酸了 !2026-05-23 13:06
Metallica to seek and destroy your eardrums with new album this fall2026-05-23 13:05
《當她戀愛時》今日甜蜜上線 正式開啟愛情進行時2026-05-23 13:01
趙寶剛《青春鬥》熱度升級 鄭爽領銜“反套路青春”2026-05-23 12:56
《平凡的榮耀》深耕社會現狀 聚焦現實進行深度創作2026-05-23 12:54
Michael Phelps says goodbye to the pool with Olympic gold2026-05-23 12:09
《青春鬥》持續熱搜刷屏 直麵“問題青春”詮釋成長真諦2026-05-23 12:06
You will love/hate Cards Against Humanity's new fortune cookies2026-05-23 14:39
《青春鬥》曝“青春群像”版海報 鄭爽領銜青年成長史2026-05-23 14:15
《看不清的真相》廈門殺青 紮實拍好警察故事打造刑偵懸疑精品網劇2026-05-23 14:08
《錦衣之下血滴子》今日上線,少女離奇失蹤,錦衣衛浴血殺敵2026-05-23 13:57
Hiddleswift finally followed each other on Instagram after 3 excruciating days2026-05-23 13:22
秦嵐《夜空中最閃亮的星》 化身“弟控”禦姐範十足2026-05-23 13:16
《破冰行動》昨日收關,來奇異果tv盤點最慘的五個女性角色!2026-05-23 12:51
《鳳弈》定檔5月28日 徐正溪的熱血將軍魏廣,終於等到你!!2026-05-23 12:10
Balloon fanatic Tim Kaine is also, of course, very good at harmonica2026-05-23 12:08
經超《白發》收視攀升 傅籌情話不斷皆是柔情2026-05-23 12:06