Live data from Hacker News

Remote Code Execution in Slack desktop apps

hackerone.com

81–90 of 201 posts

Re: Remote Code Execution in Slack desktop apps

#81
post #53

Earlier quoted context omitted.

What you do, though, is objectively more valuable to Slack than you were paid. They have reframed security as the competition you mention, but the stakes are much higher and they're sidestepping with this issue of "responsible reporting".

> What you do, though, is objectively more valuable to Slack than you were paid. This is a meaningless statement. Obviously all work is more valuable to the company than what they pay you to do the work... otherwise they wouldn't pay you would they? Because they'd get nothing out of it. If your work generates £5 for a company, then why would they pay you £5 or £6 for it? What's in it for them?

Obviously the point is that the gap between how much the person deserves and how much they're paid is particularly significant in this case

Re: Remote Code Execution in Slack desktop apps

#83
post #79
post #73

Earlier quoted context omitted.

> You would sell something like this, so someone can be spied upon or maybe literally chopped to pieces? Jesus, not everything is about money If you haven't had food for a few days everything is indeed about money. Either you reward someone properly for the work that they can do or they'll find someone else who does. I doubt most people get fuzzy warm feelings helping a big US corporation that's too greedy to actuall…

> If you haven't had food for a few days everything is indeed about money I doubt anybody capable of finding an exploit like this is in that situation

They can be when they try to live off of bug bounties alone.

There are a lot of young folks that try to make this their full time job after some success, then get into a dry spell. The panic robs them of the lateral thinking that brought them to the dance to begin with, and they get into spirals of ravenously hunting simple bugs that end up as dupes and out of scope.

Re: Remote Code Execution in Slack desktop apps

#84
post #79
post #73

Earlier quoted context omitted.

> You would sell something like this, so someone can be spied upon or maybe literally chopped to pieces? Jesus, not everything is about money If you haven't had food for a few days everything is indeed about money. Either you reward someone properly for the work that they can do or they'll find someone else who does. I doubt most people get fuzzy warm feelings helping a big US corporation that's too greedy to actuall…

> If you haven't had food for a few days everything is indeed about money I doubt anybody capable of finding an exploit like this is in that situation

Most software is made entirely free with no source of income. The job market for software is terrible, and those people work entirely seperate jobs from it. Many program on a very minimum life expenditure.

Re: Remote Code Execution in Slack desktop apps

#85
post #13
post #12

Earlier quoted context omitted.

> since Electron brings XSS to the desktop, it is a hackers paradise. Just curious - what makes XSS on the desktop different from other kinds of RCE vulnerability?

Nothing, but if Slack was a web application and not an Electron application it would mean XSS would not immediately lead to RCE, you would need XSS and a vulnerability in the browser to get an RCE. Electron is basically that for you already: a vulnerable browser.

[deleted]

Re: Remote Code Execution in Slack desktop apps

#86
post #6

Great report on a critical RCE vulnerability in Slack. However, I will bite. $1,750 for a detailed report on a critical RCE is like rewarding sniffer-dogs with breadcrumbs. One could sell this exploit at least for 5 figures on the black market. In all cases, since Electron brings XSS to the desktop, it is a hackers paradise.

Damn, didn't know $1750 was low. I got something similar for reporting an exploit to Microsoft, where opening an attached ICS/calendar entry in Outlooks web client allowed me to execute arbitrary JavaScript on outlook.microsoft.com as the current user. Should have asked for more!

Yes... yes you should have.

Re: Remote Code Execution in Slack desktop apps

#87
post #50

Earlier quoted context omitted.

I agree with you. It's super low, but I and others will just ignore it in the future and ultimately they lose. However, bug bounties are not a job. Nobody is forced or obligated to do anything. I'm giving them 'a pass' in the future :) It's great people are discussing this and surely it will improve things for future researchers. I consider bug bounties like competitions. The 'prize money' is defined beforehand. You…

> However, bug bounties are not a job. Nobody is forced or obligated to do anything. I'm giving them 'a pass' in the future :) It's great people are discussing this and surely it will improve things for future researchers. Shouldn't people like you be able to do this for a living if you want to? It's valuable work. It has real market value. It seems like you're doing this for fun and genuine interest and I do admire…

Yes they should and I think I could. This exploit was more of a fun challenge.

I support and agree to everything you are saying. I love the community response. I too loathe the bug bounty asymmetry in power between corporations and reporters, but it exists.. by design. How do you imagine a researcher can 'demand' more money in this situation? They can choose the amounts arbitrarily and there is nothing legal or ethical you can do about it.

I haven't seen any proposals for real solutions - how would you ask this? How do you decide the amount for each company? Solutions, which do not bypass ethics or laws. I hope that 'the market' will solve this eventually and I think I at least raised awareness.

Re: Remote Code Execution in Slack desktop apps

#88
post #79

Earlier quoted context omitted.

> If you haven't had food for a few days everything is indeed about money I doubt anybody capable of finding an exploit like this is in that situation

Most software is made entirely free with no source of income. The job market for software is terrible, and those people work entirely seperate jobs from it. Many program on a very minimum life expenditure.

https://levels.fyi disagrees. I can confirm the offers on there are real

Re: Remote Code Execution in Slack desktop apps

#89
post #83
post #79

Earlier quoted context omitted.

> If you haven't had food for a few days everything is indeed about money I doubt anybody capable of finding an exploit like this is in that situation

They can be when they try to live off of bug bounties alone. There are a lot of young folks that try to make this their full time job after some success, then get into a dry spell. The panic robs them of the lateral thinking that brought them to the dance to begin with, and they get into spirals of ravenously hunting simple bugs that end up as dupes and out of scope.

> They can be when they try to live off of bug bounties alone.

I think that's the problem. You shouldn't be entirely dependent on bounty money, because sooner or later you will find a bug that is worth 10x or 1000x on the black market.

I have seen white hat bounty hunters go rouge in such situations and entirely blame it on the cheap ass companies that won't offer the "right" amount.

Nobody owns you anything, you are doing this mostly for fun. The bounty is just a bonus.

Re: Remote Code Execution in Slack desktop apps

#90
post #14
post #11

Earlier quoted context omitted.

>$1750 for that?! Security researchers need to organize! https://hackerone.com/slack?type=team It says right on the tin what the payout is going to be. If you don't like the terms of the program, don't participate. It's not really that difficult a concept.

Had the researchers (unethically) published it as a zero-day vulnerability in e.g. a blog post stating "the slack payout wasn't enough for us to care" - what would've been their legal risks? I assume that would be _one_ way to get companies to care more about rewarding people who spend substantial amounts of time researching their security

Finding and disclosing vulnerabilities predates bug bounties by a long stretch. Bug bounties are simply an incentive for people to follow a scope and disclosure policy through a legal safe harbor and small financial incentive, but they aren't always effective at that. Folks that operate outside of the bounty program don't have that safe harbor and are likely exposed to the full force of whatever domestic 'hacking' laws exist on the books. In the US this has resulted in jail time and fines.

If someone doesn't like the terms of a particular bug bounty program, I would ask why they are doing research against that company to begin with. That's like someone really wanting kids dating a person that doesn't want kids and hoping they will change their mind after they see how awesome it will be. Almost without exception, if you read the comments from the individuals reporting the bugs, they will actually defend the status quo (as is the case here if you dig around). It's mostly just loud people in the vicinity of this trying to drive up the market.

Of course in my example I could try to incentivize said partner to have children by all sorts of unethical means, and there are certainly ways for researchers to try to incentivize corporations to increase bounty scope or payout by unethical means. This is generally considered 'extortion'.

Lastly I think it's also important to point out that legality has nothing to do with ethics, and I certainly believe there are cases where disclosure is warranted outside of any established paradigm of 'responsible disclosure' or bounty program.

Post reply on HN