HomeSecurityBug Gave Hackers Access to Accounts!

Slack bug gave hackers access to accounts!

A bug found in the popular work chat app Slack allowed attackers to hijack people's accounts, taking control of all their communications. Fortunately, the issue has been fixed, so you might want to update your apps.

slack

The flaw was discovered by Frans Rosen, a security researcher at cybersecurity firm Detectify. According to his blog on the subject, Slack users' tokens could be stolen by tricking people into opening malicious websites.

Rosén explains that he noticed the problem when he encountered a glitch in the browser version of Slack that allowed him to hang up on other people's calls. Another flaw in the call allowed the researcher to intercept messages sent with the Mail app.

"Now simply submitting that an origin-validation string was missing is no joke at all and probably didn't show them the severity of the problem. I had to come up with a better script to look through the code," Rosén writes.

So an exploit was built to steal Slack tokens by building a malicious page designed to grab and store them. In short, when someone opened the malicious page a Slack call was opened, causing a WebSocket to reconnect to the rogue server.

Grabbing these tokens that could be used to gain access to people's accounts is equally concerning.

It's nice to see such quick responses, the vulnerabilities reported, especially given that attacker payloads could find ways inside the apps to wreak havoc. Luckily for Slack, this time a security researcher is looking for bugs, not cybercriminals.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS