5 ms·
how does slack have permanent root access to my system again?
by johnmarcus 7y ago
how does slack have permanent root access to my system again?
- CameronNemo 7y agoThe repo can theoretically hijack a package like util-linux, unless you creatively set up apt pinning.
- MayeulC 7y agoThat, plus I guess the package could easily contain suid binaries.
- codedokode 7y agoIf you download and unpack Slack's .deb package [1] , you'll find a script "/etc/cron.daily/slack" (contained within "data.tar.xz") that is a bash script run by cron daily under root account. This cron script adds a line "deb https://packagecloud.io/slacktechnologies/slack/debian/ https://packagecloud.io/slacktechnologies/slack/debian/ jessie main" into apt sources list. Also it adds Slack Inc. public key into list of trusted keys. This allows Slack Inc. to replace any package on your system including bash, firefox, libreoffice or sshd by publishing a package with the same name but higher version number. Note that they can provide malicious updates only to specific users, identifying them by country or IP address, so that other users won't see anything suspicious. For example, law enforcement agencies can ask them to backdoor a suspect's computer to gather evidence or important data for intelligence. This is the problem with apt and with Linux package managers in general: they assume you only add package sources you completely trust and do not support installing third-party packags without this trust (unlike Windows that supports portable applications or Android that doesn't give root privileges to installed packages). Linux package managers are not suited for installing untrusted third-party applications. [1] https://downloads.slack-edge.com/linux_releases/slack-desktop-4.0.1-amd64.deb https://downloads.slack-edge.com/linux_releases/slack-deskto...