$1750 for that?! Security researchers need to organize! I have no idea what I’m talking about but my guess would be that the security economics of finding an RCE make it very valuable. The disclosure would be worth considerably more to Slack than this bounty. Something in the order of months’ worth of skilled labour, not hours. I suppose the economics also mean Slack only have to outpay the bad guys, so this is reall…
How would you even monetize that? This requires an existing employee access to be able to post a message to the company slack and hope other employees click it. The vulnerability could do great to pown a company as long as you already have a compromised user account in the company. That's not a wormable RCE, that's not zero click (I'm not saying it's not bad). Is there a market for high touch highly targeted attacks,…
Remote Code Execution in Slack desktop apps
61–70 of 201 posts
Re: Remote Code Execution in Slack desktop apps
#62It is my belief that most people would not use Slack if it did not have the business buy-in it now has. Most people are forced to use Slack.
Curious what the hate for Slack is. I use a 1-person Slack workspace for personal note-taking and memory extension, and I find it is also a super useful tool to manage ideas, photos, shared files in romantic relationships. For either use case the ability to write bots for it, and the fact that it syncs across devices with multiple simultaneous logins is awesome.
Re: Remote Code Execution in Slack desktop apps
#63Earlier quoted context omitted.
Curious what the hate for Slack is. I use a 1-person Slack workspace for personal note-taking and memory extension, and I find it is also a super useful tool to manage ideas, photos, shared files in romantic relationships. For either use case the ability to write bots for it, and the fact that it syncs across devices with multiple simultaneous logins is awesome.
How do you use a 1-person Slack workspace for shared files in relationships?
I also find the 1-person workspace to sadly be the easiest way to transfer files between my computers and phones. Like for example when I need to take a PDF with me to the airport or elsewhere, I just drag the PDF into my 1-person Slack workspace and head out the door. Every other method I've tried involves more steps. The mobile clients of Dropbox and Google Drive make it unreasonably hard to actually download files.
Re: Remote Code Execution in Slack desktop apps
#64I hope Slack review the payment and give you a bit more.
Re: Remote Code Execution in Slack desktop apps
#65Earlier quoted context omitted.
I agree with you. It's super low, but I and others will just ignore it in the future and ultimately they lose. However, bug bounties are not a job. Nobody is forced or obligated to do anything. I'm giving them 'a pass' in the future :) It's great people are discussing this and surely it will improve things for future researchers. I consider bug bounties like competitions. The 'prize money' is defined beforehand. You…
What you do, though, is objectively more valuable to Slack than you were paid. They have reframed security as the competition you mention, but the stakes are much higher and they're sidestepping with this issue of "responsible reporting".
This is a meaningless statement.
Obviously all work is more valuable to the company than what they pay you to do the work... otherwise they wouldn't pay you would they? Because they'd get nothing out of it.
If your work generates £5 for a company, then why would they pay you £5 or £6 for it? What's in it for them?
Re: Remote Code Execution in Slack desktop apps
#66Great report on a critical RCE vulnerability in Slack. However, I will bite. $1,750 for a detailed report on a critical RCE is like rewarding sniffer-dogs with breadcrumbs. One could sell this exploit at least for 5 figures on the black market. In all cases, since Electron brings XSS to the desktop, it is a hackers paradise.
Re: Remote Code Execution in Slack desktop apps
#67I wrote that exploit & report. Just some thoughts on comments here. Sure the bounty is low, but ultimately it's their money and their decision. They will deal with the 'consequences' of others skipping their program and some public shaming. I find everyone talking about black markets etc. kind of ridiculous. Really? You would sell something like this, so someone can be spied upon or maybe literally chopped to pieces?…
It would be interesting if security reporters had a habit of ending their reports with what they feel is the fair market rate.
Re: Remote Code Execution in Slack desktop apps
#68Earlier quoted context omitted.
Curious what the hate for Slack is. I use a 1-person Slack workspace for personal note-taking and memory extension, and I find it is also a super useful tool to manage ideas, photos, shared files in romantic relationships. For either use case the ability to write bots for it, and the fact that it syncs across devices with multiple simultaneous logins is awesome.
Once you use it with a decent amount of people for work, things just get ‘lost’, because the frequency of messages in a channel is so high, info is missed, or employees working on different shifts need to spend a decent amount of time at the beginning of their day to review all the missed messages, some are relevant, most are not. As you mentioned, there is also an inclination to send alerts or tasks to a channel, an…
I think a big part of it is it's not obvious how to create threads on mobile. A facebook-like UI for that would be nice.
I wonder if this type of live UI modification could be implemented as a Chrome extension and deployed across an enterprise.
Re: Remote Code Execution in Slack desktop apps
#69I wrote that exploit & report. Just some thoughts on comments here. Sure the bounty is low, but ultimately it's their money and their decision. They will deal with the 'consequences' of others skipping their program and some public shaming. I find everyone talking about black markets etc. kind of ridiculous. Really? You would sell something like this, so someone can be spied upon or maybe literally chopped to pieces?…
Out of curiosity, what do you feel a competitive bug bounty would be for this type of report? It would be interesting if security reporters had a habit of ending their reports with what they feel is the fair market rate.
depends on exploit, program, company etc
Re: Remote Code Execution in Slack desktop apps
#70Earlier quoted context omitted.
Unfortunately, we live in a world governed by money as a motivator. While you might not be in it for the money, many people are, to a certain degree (you know, to make a living and to be able to afford a decent life). If companies are unwilling to pay anything remotely close to what researchers' time is worth, then they shouldn't wonder when people prefer to sell the exploits that they find to those who do value thei…
So, what is the right thing to do if you find a vulnerability in Slack?
The problem with starting with the baseline of "the right thing to do is always to disclose the vulnerability to Slack regardless of how little they pay" is that it perpetuates the exploitation of legitimate and important work by skilled workers. The onus should be on Slack to provide fair compensation, not on people doing this important work to "do it out of the good of their hearts".
Slack as a company had a revenue of $401 million last year and the average payout in their bug bounty program is $1376 (https://github.blog/2018-03-14-four-years-of-bug-bounty/). That's just disgusting.