Web Hack List

Collected research

Hacking Slack using postMessage and WebSocket-reconnect to steal your precious token

Slack's web client handled window postMessage events without checking the sender's origin. An attacker page could open slack.com/call/me, send a reconnect_url event repointing the client's WebSocket at the attacker's server and a goodbye event to force the reconnect, then read the xoxs session token out of the handshake and take over the account.

Record

Researcher
Frans Rosén
Published by
labs.detectify.com
Topic
HTTP

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Frans Rosén, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .