Collected research
Hacking Slack using postMessage and WebSocket-reconnect to steal your precious token
Slack's web client handled window postMessage events without checking the sender's origin. An attacker page could open slack.com/call/me, send a reconnect_url event repointing the client's WebSocket at the attacker's server and a goodbye event to force the reconnect, then read the xoxs session token out of the handshake and take over the account.
Record
- Researcher
- Frans Rosén
- Published by
- labs.detectify.com
- Topic
- HTTP
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Frans Rosén, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .