journalctl -u micro
103 subscribers
2.39K photos
234 videos
293 files
1.62K links
Esperienze e consigli di uno sviluppatore tech−unenthusiast

creation — 2021-04-29
owner — @Microeinstein

networks
@sigma_hub Σ
@ageiroumena
Download Telegram
Wind sembra bloccare i siti certificati con Let's Encrypt / serviti da IP residenziale (?) con una funzione attivata a tutti arbitrariamente senza chiedere alcun consenso.

https://connect.gt/topic/248058/wind-tre-servizio-di-sicurezza-che-blocca-siti-con-let-s-encrypt
Forwarded from CSIRT Italia
‼️ #Telegram: rilevata vulnerabilità #0Click che potrebbe permettere #RCE tramite l’invio di sticker animati

Rischio: 🟠

Tipologia:
🔸 Remote Code Execution

🔗 https://www.acn.gov.it/portale/w/telegram-rilevata-vulnerabilita-0-click

👉 Analisi e mitigazioni disponibili
Sorry what
Forwarded from News and Tips
This vulnerability does not exist. The researcher falsely claims that a corrupted Telegram sticker can be used as an attack vector, while completely ignoring the fact that all stickers uploaded to Telegram are checked on servers before they can be played in Telegram applications.

📰 Telegram press service responded to the critical zero-day vulnerability.
Please open Telegram to view this post
VIEW IN TELEGRAM
Prima volta che avvio l'installer di Arch tramite net boot PXE e FUNZIONA.
Grazie dnsmasq
🔥5
Forwarded from 🌱 Activacy
5🔥2
Forwarded from govd
source - @govd_bot
Anthropic accidentally leaked the source code for Claude Code via a public npm source map, exposing ~500K lines across ~1,900 files.

It doesn’t include the model itself no weights or training data but reveals how Anthropic builds its tools and agent workflows.

GitHub link: https://github.com/instructkr/claude-code
🔥3
Forwarded from Tech & Leaks Zone
BREAKING: Nekogram is secretly transmitting your telegram account phone number to the developer

According to SOTA,
"The backdoor is hidden in the http://Extra.java file, which differs from the template uploaded to the repository. The obfuscated code sends data as an inline request to the @nekonotificationbot, leaving no trace. The same file implements account 'doxing' via several bots; it is possible that the leaked data is used to populate their databases."

Additionally, the creator of the Nekogram client, (presumably a Chinese national) was previously known for conducting DDoS attacks and unethical online behavior (including death threats against acquaintances).

Apparently, in the early versions of the client, de-anonymization was applied only to Chinese phone numbers, which could have been used for political surveillance;. However, it is now applied to all users.

Follow @TechLeaksZone
Forwarded from Tech & Leaks Zone
EXPOSED: Source Code Evidence of Nekogram Phone Number Harvesting

1. Exfiltration Logic: The function uo5.g() (reconstructed as logNumberPhones) silently collects the UserID and Phone Number of every account logged into the app (up to 8 accounts).

2. Transmission: Data is sent via Inline Queries to the bot @nekonotificationbot. This is done programmatically, so no message appears in your "Sent" history.

3. Target Bots: Three bots embedded in the client's obfuscated code:
@nekonotificationbot: Receives the automated phone number uploads.
@tgdb_search_bot and @usinfobot: : An OSINT bot mentioned in the obfuscated classes.

4. Security Token: The app uses a hardcoded secret key 741ad28818eab17668bc2c70bd419fc25ff56481758a4ac87e7ca164fb6ae1b1 as a prefix for the stolen data, likely to authenticate with the bot's backend.

5. The image shows that Nekogram always wants to get the "reg date".

Unfortunately the Google Play Store version is also affected!!!

Follow
@TechLeaksZone
😭1
2🔥1