Slack quick to whack account hijack crack
Summary
Slack quickly squashed a potential account hijack bug hours after it was reported. Frans Rosén, a security researcher at Detectify, discovered a vulnerability in Slack that created a means for a malicious website to steal a users Slack token, potentially seizing control of their account in the process. In a statement, Slack said subsequent inquiries revealed that the flaw was never actually abused. Veteran security expert Graham Cluley praised Slacks prompt response to fix a flaw that, left unresolved, might have been abused in targeted attacks but not in mass compromises. "[A potential attack] methodology really requires a Slack user to be specifically targeted, and for that targeted user to click on a link or deliberately visit a booby-trapped webpage, containing the code that begins the attack," he said.