Urgent.News

What's breaking now, across thousands of outlets.

Tech

Telegram Desktop vulnerability allowed any user's file to be stolen

Article URL: https://beaksec.github.io/posts/telegram-desktop-one-click-account-takeover/ Comments URL: https://news.ycombinator.com/item?id=50029123 Points: 229 # Comments: 116

A vulnerability in Telegram Desktop allowed any user's files to be stolen. When someone added a user to a Telegram group and sent a link in the chat, clicking the link gave the attacker access to the user's account. Telegram Desktop forwarded the clicked links to its own instance over a local socket, where they were never separated by a unique character.

This allowed an injection attack, where a crafted link could read and send any file to a chat without checking the requester or requiring confirmation. The operating system registers URI schemes, so when Telegram Desktop registered tg., the system knew that tg:// links belonged to Telegram and launched them with the URL as a command-line argument.

If Telegram was already running, the system launched a new process, which made it vulnerable to the same attack. The second defect was that the injected command reached an internal URI scheme, interpret:, which read a file named in an instruction file and sent it to a chat without a confirmation. An attacker could place an instruction file on the victim's disk and exfiltrate any file from their machine with a clicked link, exploiting the missing authorization check.

Written by urgent.news from Hacker News Best's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at beaksec.github.io →

More in Tech

48-Hour Field Notes: I Would Fingerprint the Locale Before I Blame the Fixture

Have you ever watched a text fixture pass on your laptop and then fail on a clean remote job? I keep meeting that surprise when the file looks identical and the decoder still disagrees with it.

  • Record locale before diagnosing text fixture failures.
  • Consider codec as first suspect for UnicodeDecodeError.
  • Compare free model and free server environments.

When Cloudflare WAF detections fail, choose a rule response for each route

A security detection can fail before it decides whether a request is safe. That is a different event from a detection matching an attack.

  • The field is an array of strings, indicating failures reported by various detectors.
  • Use len(cf.appsec.request.faileddetections) gt 0 to match any reported failure in rule expressions.

SafeLine WAF vs Imperva: Self-Hosted WAF vs Enterprise Cloud Protection

SafeLine WAF vs Imperva: Self-Hosted WAF vs Enterprise Cloud Protection When people compare SafeLine to Imperva, they're usually comparing two very different things: a lightweight self-hosted WAF and…

  • SafeLine is a self-hosted WAF from Chaitin, runs as reverse proxy, blocks SQL injection, XSS, bots.
  • Imperva is an enterprise cloud WAF with CDN, DDoS protection, bot management at network edge.

More from Saturday 10 October →