A security researcher has uncovered a flaw in Slack that could've been exploited to steal files over the business messaging app and Watch Japanese black stockings female doctor gives oral sex service to patients Onlinepotentially spread malware.
The flaw involves Slack's Windows desktop app, and how it can automatically send downloaded files to a certain destination—whether it be on your PC or to an online storage server. You can set a download location in the app's preferences section. However, David Wells, a researcher at the security firm Tenable, noticed there's another way to configure the option: Via a special link.
"Crafting a link like 'slack://settings/?update={ 'PrefSSBFileDownloadPath':
Wells realized the same function could be abused. Imagine a hacker using the links to secretly reconfigure a Slack desktop app to send all downloaded files to an outside server. "Using this attack vector, an insider could exploit this vulnerability for corporate espionage, manipulation, or to gain access to documents outside of their purview," Well's security firm Tenable said in a separate report.
The vulnerability can also pave the way for potential malware infections. Any downloaded files sent to the hacker-controller server can be altered and booby-trapped to include malicious code. The attack will commence once the victim opens the file on the Slack desktop app.
The main obstacle of carrying out this attack is circulating the hacker-created links to people on Slack, which keeps its channels private to paying clients and their companies. To pull this off, Wells noticed how Slack channels can be configured to subscribe to RSS feeds, including threads on Reddit.
"I could make a post to a very popular Reddit community that Slack users around the world are subscribed to," Wells said. The hacker-created link will then populate inside the Slack channel and possibly attract some clicks.
"This technique could be unmasked by savvy Slack users, however if decades of phishing campaigns have taught us anything, it's that users click links, and when leveraged through an untrusted RSS feed, the impact can get much more interesting," he added.
Slack has patched the flaw in version 3.4.0 of the Windows desktop app. "We investigated and found no indication that this vulnerability was ever utilized, nor reports that our users were impacted," the company said in an email.
5 extremely weird scenes that were cut from the new Beauty and the BeastHundreds of David Bowie stamps quite literally fell to earth from the sky'This Is Us' bosses promise less tears and more laughs in Season 2Ben Affleck opens up about his alcohol addiction on FacebookBill Nye wants Trump to send humans to MarsThis iPhone case just ended the war between Android and iOSCanada's Girl Scouts have also had enough of TrumpOnly those with dirty minds will appreciate this Ed Sheeran hashtagSure you're not a robot? Solve this chess puzzle and prove it.Talks of a 'Matrix' reboot are sending Twitter into a spiral of despairNBD, Allo could just tell your Google history to your mom8 pro tips for climbing Mount Everest from the guys who Snapchatted their journey10 Disney animals we would totally dateIn case eggplants are too subtle, Grindr releases more, um, expressive emojiHey law students: Want a job? Well, you better learn to code.Want VR work? Turning your resumé into an immersive experience is a good startIn case eggplants are too subtle, Grindr releases more, um, expressive emojiWant VR work? Turning your resumé into an immersive experience is a good startWar Stories'This Is Us' season finale pulls off the show's cruelest twist yet Samsung Notebook 7 is essentially a MacBook Pro with more ports Dash cam captures intense video of attempted car jacking A look at the 'Russian Doll' fan account that tweets the same photo every week Meizu 16Xs will make you question $1,000 flagships 'Blood & Truth' review: The best and worst of VR gaming in 2019 'Swamp Thing' review: The best thing DC has produced in a long time 'When They See Us' review: Central Park Five miniseries is riveting Here's what professionals really want from a new Mac Pro 'Fire Zuck' projected onto location of Facebook shareholders' meeting That 'Baby Shark' remix from Coachella has been released Facebook is talking to CFTC about its cryptocurrency, report says The BBC's in trouble for a story it ran on the new king of Thailand Google Cloud outage breaks Snapchat, YouTube, Gmail, and more Crisis counselors were on set for 'When They See Us' cast and crew Pornhub wishes you a horny Christmas in surprisingly SFW ad Drifting Martian clouds sail over NASA's Mars rover Apple reveals iOS 13 with dark mode and improved Maps This year's Stanley Cup Final will be huge for fans of 'The Office' 'Kids introducing themselves': An enthusiastic '80s meme is taking over Google AR search now pulls animals off the screen and into your room
2.0769s , 10138.734375 kb
Copyright © 2025 Powered by 【Watch Japanese black stockings female doctor gives oral sex service to patients Online】,Unobstructed Information Network