Hacking Slack using postMessage and WebSocket-reconnect to steal your token
labs.detectify.com
labs.detectify.com
I think what really makes this writeup worth the read is the insight it shows into the thought process of identifying an interesting bug and weaponizing it. Thanks Frans!
if (!TS.utility.calls.verifyOriginUrl(evt.origin)) {
return
}
...
verifyOriginUrl: function(originHref) {
var a = document.createElement("a");
a.href = originHref;
return a.hostname == window.location.hostname
},
Is there a JS API for getting the host name from an origin, or is creating DOM elements the way to do this?https://support.microsoft.com/en-us/help/834489/internet-exp...
That doesn't mean that it's pretty. But neither is the DOM API.
A tag elements expose this with the href attribute and it's very lightweight since it's not inserted into the DOM. Create one reusable global element and make a wrapper function around it if you want to be even more efficient.
Your post makes it look so easy, but it would surely take weeks for me to figure out all these things.
addMessageListener("https://*.slack.com", function(data){})
Wonder if their support team is proportionately larger than most startups, or if "10x Support Agents" are a thing?