hieuhtr / Blog

Don’t be lazy. Don’t make excuses. No one cares. Work fucking harder.
Other
6 stars 2 forks source link

Leak slack token #54

Open hieuhtr opened 7 years ago

hieuhtr commented 7 years ago

Information:

  1. https://arstechnica.com/security/2016/04/hacking-slack-accounts-as-easy-as-searching-github/
  2. https://labs.detectify.com/2016/04/28/slack-bot-token-leakage-exposing-business-critical-information/

Slack: We are monitoring for publicly posted tokens, and when we find any, we revoke the tokens and notify both the users who created them, as well as the owners of affected teams.

Lesson learned:

"double check" all files that you want to push to the internet