This isn't a leak, but...
BREAKING: Nekogram is secretly sending your phone numbers to the developer
The backdoor is hidden in the http://Extra.java
file, which differs from the template uploaded to the repository. The obfuscated code sends data as an inline request to the @nekonotificationbot, leaving no trace.
More info about the backdoor: https://github.com/Nekogram/Nekogram/issues/336 (locked by Nekogram devs)
To validate this, we made a PoC: an LSPosed module that replaces the bot ID and username to ours so all requests are going to it. That way, we confirmed that the phone numbers are being collected. Every. Login.
The PoC is available here: https://github.com/RomashkaTea/nekogram-proof-of-logging
BREAKING: Nekogram is secretly sending your phone numbers to the developer
The backdoor is hidden in the http://Extra.java
file, which differs from the template uploaded to the repository. The obfuscated code sends data as an inline request to the @nekonotificationbot, leaving no trace.
More info about the backdoor: https://github.com/Nekogram/Nekogram/issues/336 (locked by Nekogram devs)
To validate this, we made a PoC: an LSPosed module that replaces the bot ID and username to ours so all requests are going to it. That way, we confirmed that the phone numbers are being collected. Every. Login.
The PoC is available here: https://github.com/RomashkaTea/nekogram-proof-of-logging
❤1👏1
There are also allegations around Cherrygram having the same backdoor as well. But the developer has made out his response, denying the usage of that "function" in release builds and the code itself existed by accident after base syncing: https://t.me/cherrygram/1138
Telegram
Cherrygram 🍒
This kind of function has never been used and will never be used. It ended up in the codebase purely by accident during a merge from the development repository into the main branch.
Anyone who’s interested can simply download the source code and verify that…
Anyone who’s interested can simply download the source code and verify that…
Btw, If anyone it's interested, don't use Firefox on Linux, via a cookie hijacking attack with less than 50 lines of code I stole all my accounts I had on the browser, so pls be careful and don't execute code you don't trust
Every chromium based it's vulnerable too, bur the attack it's a little more difficult, but it's still possible
I won't release the code (for obvious reasons) for now until I make sure the vulnerability it's patched
Firefox say they won't fix it too, well, here's the files for Linux if anyone wants it
Here is the explanation, files and how to use the scripts, but pls use it responsibly
Microsoft Edge keeps every saved password as plain readable text in its memory as soon as you open the browser. This includes passwords for websites you have not even visited yet.
Google Chrome only unlocks passwords when you actually need them.
A security researcher created a tool that shows how admins can easily copy passwords from other users’ Edge browsers on shared computers or work setups.
Microsoft says this is “by design.” But the browser still asks you to log in again, even while it holds all the passwords unprotected in memory. This creates real risks on shared devices.
Google Chrome only unlocks passwords when you actually need them.
A security researcher created a tool that shows how admins can easily copy passwords from other users’ Edge browsers on shared computers or work setups.
Microsoft says this is “by design.” But the browser still asks you to log in again, even while it holds all the passwords unprotected in memory. This creates real risks on shared devices.