How this team accidentally found a SSRF in Slack exposing AWS credentials! A $4000 bug bounty

Complex libraries lead to hidden attack vectors

Roberto
InfoSec Write-ups
Published in
5 min readJul 29, 2022

--

This is an inspiring story for all bug bounty hunters of how a SSRF vulnerability was discovered in Slack, along with potentially many other web applications, by Brett Buerhaus, Cody Brocious, Sam Erb, and Olivier Beg’s. I will be detailing a more user-friendly version of their detailed “A Tale of Exploitation in Spreadsheet File Conversions,” and all the material I’m presenting is sourced from…

--

--

Stanford alum, Software Engineer with a passion for CyberSec, Biotech, and Sustainability. Work with me at https://www.tidallabs.io/.