{"id":163512,"date":"2016-04-29T13:30:57","date_gmt":"2016-04-29T11:30:57","guid":{"rendered":"http:\/\/mybroadband.co.za\/news\/?p=163512"},"modified":"2016-04-29T13:32:20","modified_gmt":"2016-04-29T11:32:20","slug":"how-to-hack-slack-accounts-search-github","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/163512-how-to-hack-slack-accounts-search-github.html","title":{"rendered":"How to hack Slack accounts: search Github"},"content":{"rendered":"<p>Developers are leaking access tokens for Slack on GitHub in public repositories, support tickets, and public gists, security researchers from <strong><a href=\"https:\/\/labs.detectify.com\/2016\/04\/28\/slack-bot-token-leakage-exposing-business-critical-information\/\" target=\"_blank\">Detectify<\/a><\/strong> have found.<\/p>\n<p>\u201cThey are extremely easy to find due to their structure,\u201d Detectify warned, adding that it is clear that the knowledge about what these tokens can be used with malicious intent is not on top of people\u2019s minds yet.<\/p>\n<p>Using the tokens, it is possible to eavesdrop on a company, the researchers said.<\/p>\n<p>Outsiders can easily gain access to internal chat conversations, shared files, direct messages and even passwords to other services if these have been shared on Slack.<\/p>\n<p>Detecitfy said that it was able to identify over 1,500 strings that match the pattern of a Slack token that are publicly available on GitHub.<\/p>\n<p>These tokens belong to different users and companies, among them Forbes 500 companies, payment providers, Internet service providers, and health care providers.<\/p>\n<p>With the tokens it identified, Detectify said it was able to find database credentials, login to continuous integration platforms and internal services, see private messages to the token owner, and files with passwords.<\/p>\n<p>\u201cWe also concluded from the internal communication inside Slack teams, that people tend to be really sloppy with passing credentials in general,\u201d the researchers said.<\/p>\n<p>Following the disclosure of the security problem, Slack said that it has revoked the tokens Detectify reported, notified affected users and team owners directly, and promised that they would be doing that proactively from now on.<\/p>\n<h3 id=\"related\">More security news<\/h3>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/163330-hawks-arrest-tollgate-official-for-card-skimming.html\"><strong>Hawks arrest tollgate official for card skimming<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/163240-over-300-hacking-attempts-on-gauteng-school-application-system.html\"><strong>Over 300 hacking attempts on Gauteng school application system<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/162390-the-biggest-security-mistakes-you-make-when-shopping-online.html\"><strong>The biggest security mistakes you make when shopping online<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/software\/162726-unlimited-free-vpn-built-into-the-opera-browser.html\"><strong>Unlimited free VPN built into the Opera browser<\/strong><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Developers are being careless with their Slack login credentials, security researchers have found.<\/p>\n","protected":false},"author":23,"featured_media":163514,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_facebook_post_id":"","_sma_instagram_post_id":"","_sma_threads_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[27],"tags":[36,36924,11253,36922],"class_list":["post-163512","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-active","tag-detectify","tag-github","tag-slack"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/163512"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/23"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=163512"}],"version-history":[{"count":1,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/163512\/revisions"}],"predecessor-version":[{"id":163516,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/163512\/revisions\/163516"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/163514"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=163512"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=163512"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=163512"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}