Android Century
  • Home
  • Android Zone
    • Android Apps
    • Android Games
    • Apps APk Files
    • Games Apk Files
    • Apps Hack Tricks
  • Reviews
  • Fantasy Zone
    • Entertainment
    • Quotes and Status
    • Life Style
    • Home Made Tips
    • Hair Care
    • Skin Care
    • Fantasy Tips
  • Tricks
    • Free Recharge
    • Free Internet
    • shopping Cashback
    • Recharge Cashback
  • Tech
  • Mobiles
  • Gadgets
  • News
  • How To's
  • Software
Breaking
Loading...

Featured post

How to Take Great Photos With Apple's iPhone X

Recent Posts

Labels

  • Android Apk Files
  • Android Apps
  • Android Games
  • Apps Apk Files
  • Entertainment
  • Fantasy Tips
  • Gadgets
  • Hair Care
  • HomeMade Tips
  • How To's
  • News
  • Quotes
  • Quotes & Status
  • Recharge Cashback
  • Recharge Promo Codes
  • Shopping Cashback
  • Technology
  • skin care
Home / News / Slack bug paved the way for a hack that can steal user access

Slack bug paved the way for a hack that can steal user access

Latest Govt. Jobs 22:06:00 News Edit
p1200475

One bug in Slack, the popular work chat application, was enough for a security researcher to design a hack that could trick users into handing over access to their accounts.
Bug bounty hunter Frans Rosen noticed he could steal Slack access tokens to user accounts due to a flaw in the way the application communicates data in an internet browser.
“Slack missed an important step when using a technology called postMessage,” Rosen said on Wednesday in an email.  
PostMessage is a kind of command that can let separate browser windows communicate with each other. In Slack, it’s used whenever the chat application opens a new window to enable a voice call.
Ideally, an application that uses postMessage will validate the origin of all data exchanged between separate windows, to keep the process secure. However, Slack wasn’t doing this, according to Rosen.
“Not validating them was a clear indication to me that I could start to do fun stuff,” he wrote in a blog post for security firm Detectify, which he advises.
Last week, he discovered the problem and realized he could siphon a user’s access token through the postMessage bug.
“If you have a browser window, and open a new window by clicking on a link, those two windows can communicate using postMessage,” he said in an email.
But what if one of those windows is an imposter? That’s what Rosen essentially created with a malicious webpage that can hijack the Slack application.
He demonstrated the theoretical hack in a video. The malicious webpage will open a Slack window that then forces a victim’s account to handover its access token.
Fortunately, Slack has fixed the issue. The company has found after a thorough investigation that the flaw was never exploited, according to a posting on HackerOne, a bug bounty platform.
"To work securely with postMessage you always need to verify the origin of every message," Rosen added.
Share on Facebook Share on Twitter Share on Google Plus

RELATED POSTS


LG G7 with iPhone X-like notch

Oppo F7 India launch confirmed

Alcatel 1x with Android Oreo (Go ed...
Slack bug paved the way for a hack that can steal user access Slack bug paved the way for a hack that can steal user access Reviewed by Latest Govt. Jobs on 22:06:00 Rating: 5

0 comments:

Post a Comment

Newer Post Older Post Home
Subscribe to: Post Comments ( Atom )

Search This Blog

TEST BOOK FOR GOVT ENTRANCE TEST

TEST BOOK FOR GOVT ENTRANCE TEST
Find All Latest book for preparation of SSC,RAILWAYBANK PO,RBI,BANK CLERK,GATE ME,GATE CE are available here in less prices, to check out the books click here

Translate

  • Popular Post
  • Random posts
  • Category

Popular Posts

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & Earn Offer:  Hey Guys! Today I make an article about Teen Patti Referral ...
  • Taotronics TT-BH22 Headphones Review
    We make it a addiction to now not look up pricing of a product sooner than reviewing and if ...
  • Reliance Jio to offer sharp tariff discounts for customers signing up by March-end
    Reliance Industries' Jio unit will charge a tariff for its services from April, but will offer ...
  • Pentagon strongly condemns North Korea missile test
    The Pentagon on Monday strongly condemned North Korea’s latest missile test, adding that the ...
  • Fitbit Zip 2017 review
    Fitbit PROS: Clever, accurate tracking Expandable online service Integration with 3rd ...
  • Bank wallets growing faster than e-wallets
    In the  bank  versus  e-wallets  sweepstakes,  lenders  have now gained lost ground. As of ...

Random Posts

  • Freecharge POWER – Get 10% Cashback On Electricity Bills Payment
    Freecharge POWER – Get 10% Cashback On Electricity Bills Payment
    06.03.2016 - 0 Comments
    Freecharge has come up with a new offer for electricity bills payment. Now get 10% cashback on electricity…
  • Asus Zenfone 3 Deluxe  Review
    Asus Zenfone 3 Deluxe Review
    12.02.2017 - 0 Comments
    Asus VERDICT Asus Zenfone 3 Deluxe is a much better Android phone than its predecessor thanks to its…
  • Lenovo Vibe K5 and Vibe K5 Plus First Impression
    Lenovo Vibe K5 and Vibe K5 Plus First Impression
    25.02.2016 - 0 Comments
    Lenovo Vibe K5 and Vibe K5 Plus First Impression: Lenovo had launched two new handsets at the Mobile…
  • Now Samsung ups the rich messaging ante with RCS support on all Marshmallow and Nougat phones 2017
    Now Samsung ups the rich messaging ante with RCS support on all Marshmallow and Nougat phones 2017
    01.03.2017 - 0 Comments
    The battle over RCS is starting to get serious. Last week, Google shifted the branding of…
  • EZVIZ Husky review: This weatherproof camera gives you an eye on the outside of your home
    EZVIZ Husky review: This weatherproof camera gives you an eye on the outside of your home
    11.02.2017 - 0 Comments
    Ezviz recently released the second iteration of its indoor home security camera, the Ezviz Mini Plus. At…

Labels

Android Apk Files Android Apps Android Games Apps Apk Files Apps Hack Tricks Entertainment Free Internet Freecharge Gadgets Games Apk Files How To's Laptops Guide Mobiles Reviews Technology Viral's android zone free recharge

Entertainment

Tricks

Popular Posts

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & ...
  • Taotronics TT-BH22 Headphones Review
    We make it a ...
  • Hands-on with the home windows 10 Creators update for the Xbox One: Beam recreation streaming arrives
    The Windows ...
  • Pentagon strongly condemns North Korea missile test
    The Pentagon on ...
  • Reliance Jio to offer sharp tariff discounts for customers signing up by March-end
    Reliance Industries' Jio unit will charge a tariff for its services from April, but will offer ...
  • Fitbit Zip 2017 review
    Fitbit PROS ...
  • Bank wallets growing faster than e-wallets
    In the  bank ...

Random Posts

  • China 'has deployed missiles in South China Sea' - reports
    China 'has deployed missiles in South China Sea' - reports
    17.02.2016 - 0 Comments
    Previous satellite images of Woody Island show extensive building work including a runwayChina appears to…
  • RHA MA 750 Review
    RHA MA 750 Review
    14.01.2018 - 0 Comments
    British audio company RHA is the latest to enter the Indian market with Bluetooth headphones via Headphone…
  • Why pick AIB when comedy is everyone's forte?
    Why pick AIB when comedy is everyone's forte?
    22.02.2017 - 0 Comments
    For most branded content players, you think of the one man behind them.That's not the case…
  • Samsung Galaxy S8 launch date to be announced at MWC 2017: Report
    Samsung Galaxy S8 launch date to be announced at MWC 2017: Report
    15.02.2017 - 0 Comments
    Some reports indicate Samsung will hold an event in New York on March 29 to unveil its flagship Galaxy S8…
  • How to Turn Off Siri App Suggestions on the iPhone
    How to Turn Off Siri App Suggestions on the iPhone
    05.03.2017 - 0 Comments
    iOS 10 includes a feature that gives you quick shortcuts to apps it thinks you want to use—either…

Most Popular

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & ...
  • SAMSUNG GALAXY J7 (2016) REVIEWS
    SAMSUNG GALAXY J7 (2016) REVIEWS
    SAMSUNG GALAXY J ...
  • Top 5 Best SmartPhones under 7000 Rs (March 2017)
    Looking for the ...
  • Apple, IBM, Cisco are huge because of Indians, do not deny them H-1B visa: RBI Governor Urjit Patel
    ...
  • SAMSUNG GALAXY J7 (2016) Specifications
    SAMSUNG GALAXY J ...
  • BlackBerry Teases Marshmallow Beta Testing for Priv by Next Week
    Blackberry ...
  • LG Q6 Review
    LG Q6 Review
    2017 is ...

Contact Form

Name

Email *

Message *

Offers Zone

Created By Android Century Distributed by Android Century
  • Home
  • About us
  • Contact us
  • Privacy policy
  • Terms of use
  • Advertise here
Subscribe Via Email Subscribe To Android Century By Email And Get Free Updates. ;-)


Your email address is safe with us!