Slack vulnerability in the "Create snippet" feature can trick users to execute malicious filetypes



Slack’s snippet feature allows users to quickly and easily share pieces of code, configuration files, or log files within their workspace.

Researcher Kevin McSheehan discovered the bug in the snippet feature and reported it in the Slack’s bug bounty program.

"They need to click on the file, so let's trick Slack into making it look benign. CSV should work" he said.

Slack will also show the user that a .CSV file is being downloaded when it is actually a .BAT executable.

The issue, present in both the mobile and desktop versions of the app, allowed a malicious actor to disguise dangerous files as benign, due to a flaw in the create snippet feature.

The researcher discovered that by including a long file name and certain ASCII characters in the snipped content, an attacker could trick Slack into showing that a .CSV file was being downloaded when it was actually a .BAT executable.

Full details of the vulnerability can be found here - https://hackerone.com/reports/833080 and video demonstration here - https://www.youtube.com/watch?v=cIlGfnn4iG8

Twitter: @journothinker 
Instagram: @journothinker 


Comments

Popular posts from this blog

Security researcher earns $15000 biggest bug bounty for Russian internet company giant Mail.Ru

Over $105 Million in cash has been delivered by postmen to bank account holders across India at their doorstep