Live data from Hacker News

Remote Code Execution in Slack desktop apps

hackerone.com

1–10 of 201 posts

Re: Remote Code Execution in Slack desktop apps

#2
$1750 for that?! Security researchers need to organize!

I have no idea what I’m talking about but my guess would be that the security economics of finding an RCE make it very valuable. The disclosure would be worth considerably more to Slack than this bounty. Something in the order of months’ worth of skilled labour, not hours.

I suppose the economics also mean Slack only have to outpay the bad guys, so this is really showing us poorly compensated black hat labor is?

Re: Remote Code Execution in Slack desktop apps

#3
One click RCE, not zero. $1,750 still seems a little low by H1 standards, but probably not by an order of magnitude.

Cool to see how they used the html injection gadget.

Seems like slack messed up with the blog post but made a sincere attempt to make amends.

I've noticed slack is pretty good about allowing disclosure of H1 bugs. It's a really hard sell in a lot of companies, so I think they should be applauded for that.

Re: Remote Code Execution in Slack desktop apps

#4
They didn’t disclose for months, and when they did, they failed to credit the researcher who found the bug, and started their blog post by saying “This is a fancy way of saying we’ve dialed up the security of the app. It wasn’t unsafe before, but it’s double safe now.” That sucks.

Re: Remote Code Execution in Slack desktop apps

#6
Great report on a critical RCE vulnerability in Slack. However, I will bite.

$1,750 for a detailed report on a critical RCE is like rewarding sniffer-dogs with breadcrumbs. One could sell this exploit at least for 5 figures on the black market.

In all cases, since Electron brings XSS to the desktop, it is a hackers paradise.

Re: Remote Code Execution in Slack desktop apps

#7
post #6

Great report on a critical RCE vulnerability in Slack. However, I will bite. $1,750 for a detailed report on a critical RCE is like rewarding sniffer-dogs with breadcrumbs. One could sell this exploit at least for 5 figures on the black market. In all cases, since Electron brings XSS to the desktop, it is a hackers paradise.

Can you support that statement about the black market with evidence?

Re: Remote Code Execution in Slack desktop apps

#8
post #7
post #6

Great report on a critical RCE vulnerability in Slack. However, I will bite. $1,750 for a detailed report on a critical RCE is like rewarding sniffer-dogs with breadcrumbs. One could sell this exploit at least for 5 figures on the black market. In all cases, since Electron brings XSS to the desktop, it is a hackers paradise.

Can you support that statement about the black market with evidence?

agreed on 5 figures. evidence? there’s even clearnet websites where you can buy vulns. most known would be: https://0day.today

Re: Remote Code Execution in Slack desktop apps

#9
post #7
post #6

Great report on a critical RCE vulnerability in Slack. However, I will bite. $1,750 for a detailed report on a critical RCE is like rewarding sniffer-dogs with breadcrumbs. One could sell this exploit at least for 5 figures on the black market. In all cases, since Electron brings XSS to the desktop, it is a hackers paradise.

Can you support that statement about the black market with evidence?

https://en.m.wikipedia.org/wiki/Market_for_zero-day_exploits

https://en.m.wikipedia.org/wiki/Zerodium

Re: Remote Code Execution in Slack desktop apps

#10
post #7
post #6

Great report on a critical RCE vulnerability in Slack. However, I will bite. $1,750 for a detailed report on a critical RCE is like rewarding sniffer-dogs with breadcrumbs. One could sell this exploit at least for 5 figures on the black market. In all cases, since Electron brings XSS to the desktop, it is a hackers paradise.

Can you support that statement about the black market with evidence?

[deleted]
Post reply on HN