Telegram Remote Code Execution Zero-Day Vulnerability
11–17 of 17 posts
Re: Telegram Remote Code Execution Zero-Day Vulnerability
#12Calling it "remote code execution" is veeeery clickbait-y. By this logic, any website with download links uses "remote code execution". Even the source article says just "zero-day". Also, tldr: Using Unicode Right-To-Left, you can make Telegram show file name "gpj.js" as "sj.jpg". That's all.
Re: Telegram Remote Code Execution Zero-Day Vulnerability
#13I didn't quite understand the "Remote control" scenario; is the victim becoming a telegram bot, where the attacker sends commands to the bot and the bot executes stuff on the victim system?
Re: Telegram Remote Code Execution Zero-Day Vulnerability
#14Calling it "remote code execution" is veeeery clickbait-y. By this logic, any website with download links uses "remote code execution". Even the source article says just "zero-day". Also, tldr: Using Unicode Right-To-Left, you can make Telegram show file name "gpj.js" as "sj.jpg". That's all.
The aricle says it was discovered in October 2017, and that they "informed the Telegram developers of the problem, and the vulnerability no longer occurs in Telegram’s products".
Re: Telegram Remote Code Execution Zero-Day Vulnerability
#15Calling it "remote code execution" is veeeery clickbait-y. By this logic, any website with download links uses "remote code execution". Even the source article says just "zero-day". Also, tldr: Using Unicode Right-To-Left, you can make Telegram show file name "gpj.js" as "sj.jpg". That's all.
It's a knotty problem. Also exploits in software bad.
Re: Telegram Remote Code Execution Zero-Day Vulnerability
#16"Hello! I'm russian remote code execution vulnerability, please run me and ignore system security warning. Also, you may want to delete your Documents and Settings folder, just press Del button and then Continue"
As a security researcher who tends to focus a bit on user interaction and phishing vectors you are 100% correct, but also representing part of the problem. Too often we discount vulnerabilities which users have to click-through to execute. Unfortunately users do ignore system security warnings. Unfortunately when given a dialog where they can choose security over doing their job, they'll do their job. I've actually p…
Re: Telegram Remote Code Execution Zero-Day Vulnerability
#17"Hello! I'm russian remote code execution vulnerability, please run me and ignore system security warning. Also, you may want to delete your Documents and Settings folder, just press Del button and then Continue"
As a security researcher who tends to focus a bit on user interaction and phishing vectors you are 100% correct, but also representing part of the problem. Too often we discount vulnerabilities which users have to click-through to execute. Unfortunately users do ignore system security warnings. Unfortunately when given a dialog where they can choose security over doing their job, they'll do their job. I've actually p…
Maybe give it an actual name. Something like Vibkac: Vulnerability is between keyboard and chair.