Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Code Project
  1. Home
  2. Other Discussions
  3. The Insider News
  4. GIFShell attack creates reverse shell using Microsoft Teams GIFs

GIFShell attack creates reverse shell using Microsoft Teams GIFs

Scheduled Pinned Locked Moved The Insider News
htmlsharepointcomlinuxsecurity
2 Posts 2 Posters 0 Views 1 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • K Offline
    K Offline
    Kent Sharkey
    wrote on last edited by
    #1

    Bleeping Computer[^]:

    A new attack technique called ‘GIFShell’ allows threat actors to abuse Microsoft Teams for novel phishing attacks and covertly executing commands to steal data using ... GIFs.

    Beware of hackers bearing GIFs

    "Microsoft supports sending HTML base64 encoded GIFs, but does not scan the byte content of those GIFs." <- because of course "no one" would ever do anything bad with those.

    O 1 Reply Last reply
    0
    • K Kent Sharkey

      Bleeping Computer[^]:

      A new attack technique called ‘GIFShell’ allows threat actors to abuse Microsoft Teams for novel phishing attacks and covertly executing commands to steal data using ... GIFs.

      Beware of hackers bearing GIFs

      "Microsoft supports sending HTML base64 encoded GIFs, but does not scan the byte content of those GIFs." <- because of course "no one" would ever do anything bad with those.

      O Offline
      O Offline
      obermd
      wrote on last edited by
      #2

      The new attack scenario, shared exclusively with BleepingComputer, illustrates how attackers can string together numerous Microsoft Teams vulnerabilities and flaws

      This is why even low priority security vulnerabilities need to be patched.

      1 Reply Last reply
      0
      Reply
      • Reply as topic
      Log in to reply
      • Oldest to Newest
      • Newest to Oldest
      • Most Votes


      • Login

      • Don't have an account? Register

      • Login or register to search.
      • First post
        Last post
      0
      • Categories
      • Recent
      • Tags
      • Popular
      • World
      • Users
      • Groups