3 ms·
Slack authentication works like many other web applications and once you've successfully authenticated you get a cookie which can be used to read/send messages
by InitialBP 5y ago
Slack authentication works like many other web applications and once you've successfully authenticated you get a cookie which can be used to read/send messages on your behalf.
If someone managed to get some malware running on a machine where you have logged into slack it's fairly trivial for someone to get your cookie. Something like https://github.com/djhohnstein/SharpChromium https://github.com/djhohnstein/SharpChromium is an example of a tool used to pull browser cookies off a compromised host.
I don't know the explicit details of this particular instance, but I imagine the user in question had some kind of malware installed on their phone or computer. ( I keep seeing mention of a browser extension in the comments, and I have seen some working examples of malicious chrome extensions recently that would let you steal cookies once installed.)