时间:2026-04-08 12:04:48 来源:网络整理编辑:娛樂
A security researcher has uncovered a flaw in Slack that could've been exploited to steal files over
A security researcher has uncovered a flaw in Slack that could've been exploited to steal files over the business messaging app and potentially spread malware.
The flaw involves Slack's Windows desktop app, and how it can automatically send downloaded files to a certain destination—whether it be on your PC or to an online storage server. You can set a download location in the app's preferences section. However, David Wells, a researcher at the security firm Tenable, noticed there's another way to configure the option: Via a special link.
"Crafting a link like 'slack://settings/?update={ 'PrefSSBFileDownloadPath':
Wells realized the same function could be abused. Imagine a hacker using the links to secretly reconfigure a Slack desktop app to send all downloaded files to an outside server. "Using this attack vector, an insider could exploit this vulnerability for corporate espionage, manipulation, or to gain access to documents outside of their purview," Well's security firm Tenable said in a separate report.
Credit: david wells / medium / screenshotThe vulnerability can also pave the way for potential malware infections. Any downloaded files sent to the hacker-controller server can be altered and booby-trapped to include malicious code. The attack will commence once the victim opens the file on the Slack desktop app.
The main obstacle of carrying out this attack is circulating the hacker-created links to people on Slack, which keeps its channels private to paying clients and their companies. To pull this off, Wells noticed how Slack channels can be configured to subscribe to RSS feeds, including threads on Reddit.
"I could make a post to a very popular Reddit community that Slack users around the world are subscribed to," Wells said. The hacker-created link will then populate inside the Slack channel and possibly attract some clicks.
"This technique could be unmasked by savvy Slack users, however if decades of phishing campaigns have taught us anything, it's that users click links, and when leveraged through an untrusted RSS feed, the impact can get much more interesting," he added.
Slack has patched the flaw in version 3.4.0 of the Windows desktop app. "We investigated and found no indication that this vulnerability was ever utilized, nor reports that our users were impacted," the company said in an email.
This app is giving streaming TV news a second try2026-04-08 11:41
曝紐卡盯上克羅斯願為其付2350萬鎊 拉姆塞也是目標2026-04-08 11:39
申花外援敦比亞 :進球打破精神束縛 期待上海德比2026-04-08 11:34
前女友:巴洛特利明知女兒是他的 還要求做DNA檢測2026-04-08 11:08
The five guys who climbed Australia's highest mountain, in swimwear2026-04-08 10:31
真香!國米妖鋒上半場夢遊 下半場梅西附體一條龍2026-04-08 10:28
阿曼戰國足名單兩主力因傷落選 3人在海外聯賽效力2026-04-08 10:25
國足戰深圳首發或為主力班底 國腳去留李鐵已有答案2026-04-08 10:23
These glasses hide a fitness tracker on your face2026-04-08 09:56
網傳李鐵雕像疑似被潑漆破壞 或許與掉漆生鏽有關2026-04-08 09:39
'Rocket League' Championship Series Season 2 offers $250,000 prize pool2026-04-08 11:47
國足有9人12強賽前4輪仍未出場 裁員名單或從中產生2026-04-08 11:32
米蘭開局11輪奪10勝橫掃亞平寧 兩數據創隊史新紀錄2026-04-08 11:31
再見卡裏烏斯!曝利物浦已做決定 讓他提前走人2026-04-08 10:55
What brands need to know about virtual reality2026-04-08 10:46
國足成12強賽所在小組唯一沒有主場球隊 全隊7日赴西亞2026-04-08 10:31
比賽日:阿斯頓維拉12026-04-08 10:24
馬圖伊迪點破巴黎一隱憂 如無此劫可保戰無不勝2026-04-08 09:45
Uber's $100M settlement over drivers as contractors may not be enough2026-04-08 09:39
大連足球名宿:靠金元足球奪個冠軍就能當足協主席2026-04-08 09:20