Web Hack List

Collected research

Experimental Security Analysis of the App Model in Business Collaboration Platforms

An analysis of the third-party app model in Slack and Microsoft Teams finding that its access control violates least privilege and complete mediation. A malicious app can eavesdrop on messages it has no permission to read, place fake video calls, and merge code into connected repositories without user approval.

Record

Researcher
Yunang Chen, Yue Gao, Nick Ceccio, Rahul Chatterjee, Kassem Fawaz and Earlence Fernandes
Published by
usenix.org
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Yunang Chen, Yue Gao, Nick Ceccio, Rahul Chatterjee, Kassem Fawaz and Earlence Fernandes, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .