Live data from Hacker News

Remote Code Execution in Slack desktop apps

hackerone.com

51–60 of 201 posts

Re: Remote Code Execution in Slack desktop apps

#51

$1750 for that?! Security researchers need to organize! I have no idea what I’m talking about but my guess would be that the security economics of finding an RCE make it very valuable. The disclosure would be worth considerably more to Slack than this bounty. Something in the order of months’ worth of skilled labour, not hours. I suppose the economics also mean Slack only have to outpay the bad guys, so this is reall…

How would you even monetize that? This requires an existing employee access to be able to post a message to the company slack and hope other employees click it. The vulnerability could do great to pown a company as long as you already have a compromised user account in the company. That's not a wormable RCE, that's not zero click (I'm not saying it's not bad). Is there a market for high touch highly targeted attacks,…

Twitter was vulnerable because of a social engineering attack via their Slack, so definitely possible to get access to post a message.

Re: Remote Code Execution in Slack desktop apps

#52
post #46

It is my belief that most people would not use Slack if it did not have the business buy-in it now has. Most people are forced to use Slack.

Curious what the hate for Slack is. I use a 1-person Slack workspace for personal note-taking and memory extension, and I find it is also a super useful tool to manage ideas, photos, shared files in romantic relationships. For either use case the ability to write bots for it, and the fact that it syncs across devices with multiple simultaneous logins is awesome.

Once you use it with a decent amount of people for work, things just get ‘lost’, because the frequency of messages in a channel is so high, info is missed, or employees working on different shifts need to spend a decent amount of time at the beginning of their day to review all the missed messages, some are relevant, most are not.

As you mentioned, there is also an inclination to send alerts or tasks to a channel, and similarly, the alert gets buried w additional messages, or you want up creating a bunch of ‘alert’ channels that you mute, or become hijacked and people start convos in those channels.

Also, the threading sucks. It is very difficult to get users to use threads.

Re: Remote Code Execution in Slack desktop apps

#53
post #50

Earlier quoted context omitted.

Unfortunately, we live in a world governed by money as a motivator. While you might not be in it for the money, many people are, to a certain degree (you know, to make a living and to be able to afford a decent life). If companies are unwilling to pay anything remotely close to what researchers' time is worth, then they shouldn't wonder when people prefer to sell the exploits that they find to those who do value thei…

I agree with you. It's super low, but I and others will just ignore it in the future and ultimately they lose. However, bug bounties are not a job. Nobody is forced or obligated to do anything. I'm giving them 'a pass' in the future :) It's great people are discussing this and surely it will improve things for future researchers. I consider bug bounties like competitions. The 'prize money' is defined beforehand. You…

What you do, though, is objectively more valuable to Slack than you were paid. They have reframed security as the competition you mention, but the stakes are much higher and they're sidestepping with this issue of "responsible reporting".

Re: Remote Code Execution in Slack desktop apps

#54
post #20

Earlier quoted context omitted.

They would've spent multiples of that internally, just fumbling about trying to reproduce the vulnerability.

Considering their new desktop app didn't have even the most basic error handling for connection failures (during downtime people had bricked apps that displayed a white screen with a HTTP error), I have absolutely zero faith in Slack's engineering capabilities. That's not an indictment of the engineers, but it's an indictment of the executives and managers responsible for the lazy stagnation they're currently in. The…

The sooner Slack is out of my life, the happier I will be.

Re: Remote Code Execution in Slack desktop apps

#56
post #39

I wrote that exploit & report. Just some thoughts on comments here. Sure the bounty is low, but ultimately it's their money and their decision. They will deal with the 'consequences' of others skipping their program and some public shaming. I find everyone talking about black markets etc. kind of ridiculous. Really? You would sell something like this, so someone can be spied upon or maybe literally chopped to pieces?…

Unfortunately, we live in a world governed by money as a motivator. While you might not be in it for the money, many people are, to a certain degree (you know, to make a living and to be able to afford a decent life). If companies are unwilling to pay anything remotely close to what researchers' time is worth, then they shouldn't wonder when people prefer to sell the exploits that they find to those who do value thei…

So, what is the right thing to do if you find a vulnerability in Slack?

Re: Remote Code Execution in Slack desktop apps

#57
post #14
post #11

Earlier quoted context omitted.

>$1750 for that?! Security researchers need to organize! https://hackerone.com/slack?type=team It says right on the tin what the payout is going to be. If you don't like the terms of the program, don't participate. It's not really that difficult a concept.

Had the researchers (unethically) published it as a zero-day vulnerability in e.g. a blog post stating "the slack payout wasn't enough for us to care" - what would've been their legal risks? I assume that would be _one_ way to get companies to care more about rewarding people who spend substantial amounts of time researching their security

A friend of mine swears that you can be sued for 'business damages' over improper disclosure. Sadly, the US is a non-permissive environment so I tend to believe it.

Re: Remote Code Execution in Slack desktop apps

#58
post #34
post #30

Earlier quoted context omitted.

It's a hyperbolic cheeky way of pointing out that they're getting off the hook for their first gross transgression. The GP isn't in any way suggesting mishandling this security issue was equivalent to murder. They're pointing out that if the transgression were more severe, we'd easily see right through the hole in the reasoning.

You can’t just substitute different transgressions and use the same reasoning. There are plenty of crimes where it’s reasonable to be more lenient to a first-time offender, but murder is not one of them.

There's a difference in kind between leniency and suspending all judgement. The GP was explicitly in favour of suspending all judgement.

They didn't accidentally spin this so hard into a cover-up. Sure, if they showed a repeated pattern of such behavior, they should see greater consequences, but they still deserve to get called out hard on their first cover-up.

Re: Remote Code Execution in Slack desktop apps

#59
post #34
post #30

Earlier quoted context omitted.

It's a hyperbolic cheeky way of pointing out that they're getting off the hook for their first gross transgression. The GP isn't in any way suggesting mishandling this security issue was equivalent to murder. They're pointing out that if the transgression were more severe, we'd easily see right through the hole in the reasoning.

You can’t just substitute different transgressions and use the same reasoning. There are plenty of crimes where it’s reasonable to be more lenient to a first-time offender, but murder is not one of them.

There are no crimes where it is reasonable to be lenient to a first-time offender. It's a matter of intent: Lenience is given to accidents (usually still only the first occurrence), which may or may not have caused a crime.

What they did was to silence a security researcher, produce marketing material with falsehoods, and as a result ultimately damage their customers by allowing a security vulnerability to remain present, and not raise alarms afterwards that customers need to ensure that they were not exploited. They actively decided that harming their customers was okay if it allowed them to avoid attention.

This is not an accident, but an intentionally committed crime. No lenience is warranted.

Post reply on HN