Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Slack Vulnerability Allowed Hackers to Hijack Accounts

A researcher earned $6,500 from Slack last year after finding a critical vulnerability that could have been exploited to hijack Slack accounts.

Researcher Evan Custodio discovered in November 2019 that the enterprise collaboration platform’s slackb.com domain was vulnerable to HTTP request smuggling attacks.

A researcher earned $6,500 from Slack last year after finding a critical vulnerability that could have been exploited to hijack Slack accounts.

Researcher Evan Custodio discovered in November 2019 that the enterprise collaboration platform’s slackb.com domain was vulnerable to HTTP request smuggling attacks.

HTTP request smuggling allows an attacker to interfere with the way websites process HTTP request sequences. If a website is vulnerable to these types of attacks, a hacker could use specially crafted requests to bypass security controls, access sensitive data, and compromise the accounts of other users.

In the case of Slack, Custodio discovered that an attacker could steal a user’s session cookie, which would give them access to the victim’s account. The attack could have been automated, allowing the hacker to harvest many users’ session cookies.

“With this attack it would be trivial for a bad actor to create bots that consistently issue this attack, jump onto the victim session and steal all possible data within reach,” the researcher explained.

The vulnerability was reported to Slack in mid-November via the company’s bug bounty program on HackerOne and it was patched within 24 hours, which is not uncommon for Slack when it comes to account hijacking issues. The details of the flaw were made public by Slack last week.

The vendor provided the following description for the vulnerability: This researcher exploited an HTTP Request Smuggling bug on a Slack asset to perform a CL.TE-based hijack onto neighboring customer requests. This hijack forced the victim into an open-redirect that forwarded the victim onto the researcher’s collaborator client with slack domain cookies. The posted cookies in the customer request on the collaborator client contained the customer’s secret session cookie. With this attack the researcher was able to prove session takeover against arbitrary Slack customers.

Slack typically offers $1,500 for critical vulnerabilities found in its products. However, Custodio reported this security hole during a period when the company was offering higher rewards for serious flaws. The company has paid out a total of over $560,000 for vulnerabilities reported through HackerOne.

Advertisement. Scroll to continue reading.

Related: Slack Flaw Allows Hackers to Steal, Manipulate Downloads

Related: Slack Lists Cybersecurity Risks Ahead of Going Public

Related: Slack, GitHub Abused by New SLUB Backdoor in Targeted Attacks

Related: Slack Unveils New Enterprise Security Tools

Written By

Eduard Kovacs (@EduardKovacs) is a managing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

Expert Insights

Related Content

Vulnerabilities

Less than a week after announcing that it would suspended service indefinitely due to a conflict with an (at the time) unnamed security researcher...

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...

IoT Security

A group of seven security researchers have discovered numerous vulnerabilities in vehicles from 16 car makers, including bugs that allowed them to control car...

Vulnerabilities

A researcher at IOActive discovered that home security systems from SimpliSafe are plagued by a vulnerability that allows tech savvy burglars to remotely disable...

Risk Management

The supply chain threat is directly linked to attack surface management, but the supply chain must be known and understood before it can be...

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

Vulnerabilities

Patch Tuesday: Microsoft warns vulnerability (CVE-2023-23397) could lead to exploitation before an email is viewed in the Preview Pane.

Vulnerabilities

The latest Chrome update brings patches for eight vulnerabilities, including seven reported by external researchers.