Live data from Hacker News

Telegram Remote Code Execution Zero-Day Vulnerability

securelist.com

11–17 of 17 posts

Re: Telegram Remote Code Execution Zero-Day Vulnerability

#12
post #3

Calling it "remote code execution" is veeeery clickbait-y. By this logic, any website with download links uses "remote code execution". Even the source article says just "zero-day". Also, tldr: Using Unicode Right-To-Left, you can make Telegram show file name "gpj.js" as "sj.jpg". That's all.

and it seems to be limited to windows only, imho not a detail to leave out

Re: Telegram Remote Code Execution Zero-Day Vulnerability

#13
post #10

I didn't quite understand the "Remote control" scenario; is the victim becoming a telegram bot, where the attacker sends commands to the bot and the bot executes stuff on the victim system?

I think its basically that the malware uses telegram bot API as a CGI. Probably not a smart attack and sounds like something someone naive but familiar with writing messenger bots might try.

Re: Telegram Remote Code Execution Zero-Day Vulnerability

#14
post #3

Calling it "remote code execution" is veeeery clickbait-y. By this logic, any website with download links uses "remote code execution". Even the source article says just "zero-day". Also, tldr: Using Unicode Right-To-Left, you can make Telegram show file name "gpj.js" as "sj.jpg". That's all.

But it's not "zero-day" either.

The aricle says it was discovered in October 2017, and that they "informed the Telegram developers of the problem, and the vulnerability no longer occurs in Telegram’s products".

Re: Telegram Remote Code Execution Zero-Day Vulnerability

#15
post #3

Calling it "remote code execution" is veeeery clickbait-y. By this logic, any website with download links uses "remote code execution". Even the source article says just "zero-day". Also, tldr: Using Unicode Right-To-Left, you can make Telegram show file name "gpj.js" as "sj.jpg". That's all.

This is mildly off topic but regarding clickbait titles, does anyone have any good idea how we can stop them? Because everybody hates them, but everybody clicks on them. Seriously, I hate the way BBC News has turned into a clickbait nightmare; but I still clicked on the "my husband turned into an otter, then became a security professional" link, or whatever it was.

It's a knotty problem. Also exploits in software bad.

Re: Telegram Remote Code Execution Zero-Day Vulnerability

#16
post #2

"Hello! I'm russian remote code execution vulnerability, please run me and ignore system security warning. Also, you may want to delete your Documents and Settings folder, just press Del button and then Continue"

As a security researcher who tends to focus a bit on user interaction and phishing vectors you are 100% correct, but also representing part of the problem. Too often we discount vulnerabilities which users have to click-through to execute. Unfortunately users do ignore system security warnings. Unfortunately when given a dialog where they can choose security over doing their job, they'll do their job. I've actually p…

I agree, but this is not an RCE

Re: Telegram Remote Code Execution Zero-Day Vulnerability

#17
post #2

"Hello! I'm russian remote code execution vulnerability, please run me and ignore system security warning. Also, you may want to delete your Documents and Settings folder, just press Del button and then Continue"

As a security researcher who tends to focus a bit on user interaction and phishing vectors you are 100% correct, but also representing part of the problem. Too often we discount vulnerabilities which users have to click-through to execute. Unfortunately users do ignore system security warnings. Unfortunately when given a dialog where they can choose security over doing their job, they'll do their job. I've actually p…

> As an industry we've got to stop discounting vulnerabilities as not serious because they require user interaction which involves clicking through security warnings.

Maybe give it an actual name. Something like Vibkac: Vulnerability is between keyboard and chair.

Post reply on HN