電報錯誤ACL。



博客:https://www.inputzero.io/2019/09/telegram-privacy-fails-again.html
簡介:電報消息應用程序關注隱私,在Playstore中有超過10,00,00,000個下載。在這種情況下,我們將濫用眾所周知的刪除郵件功能,該功能允許用戶刪除錯誤或真實發送給任何收件人的郵件。已經觀察到,一旦消息(圖像)被發送給接收者,它仍然保留在用戶的內部存儲器中,該用戶位於「 / Telegram / Telegram Images /」路徑中。 。

2 comments
  1. Wtf? It's a bag? You earn 2500€ from Telegram for it?!?!?? is this a bug ?! I did this many times when I needed to see deleted images and didn』t even think that this was a vulnerability, because it is a regular image cache.Dude, you fucking lucky bastard, I hate you, I don』t have enough money for food in the Russian Federation, and here you get 2500 € for some kind of garbage in the form of a bug

Comments are closed.