Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Partyhack 3.0 - Telegram bugbounty writeup

Bo0oM
April 12, 2019
3.8k

Partyhack 3.0 - Telegram bugbounty writeup

Bo0oM

April 12, 2019
Tweet

Transcript

  1. Вступление

    View Slide

  2. View Slide

  3. View Slide

  4. View Slide

  5. КАК-ТО МНЕ
    НУЖНО БЫЛО
    ПРИДУМАТЬ
    ТЕМУ ДЛЯ
    ДОКЛАДА
    Как я
    телеграм
    ломал

    View Slide

  6. View Slide

  7. View Slide

  8. https://github.com/Bo0oM/fuzz.txt

    View Slide

  9. https://github.com/Bo0oM/server-status-monitor

    View Slide

  10. View Slide

  11. View Slide

  12. View Slide

  13. https://github.com/telegramdesktop/tdesktop/blob/cc2c13d0182c62dd5a89784a49ec375306
    449797/Telegram/SourceFiles/core/crash_report_window.cpp#L506

    View Slide

  14. View Slide

  15. View Slide

  16. View Slide

  17. View Slide

  18. View Slide

  19. Database: tdesktopdbase
    Table: users
    [4 columns]
    +----------+
    | Column |
    +----------+
    | id | int(11) |
    | login |
    | logincrc |
    | pwdhash |
    +----------+
    Database: tdesktopdbase
    Table: keyvalue
    [3 columns]
    +--------+
    | Column |
    +--------+
    | key |
    | value |
    | id |
    +--------+
    Database: tdesktopdbase
    Table: crashes
    [6 columns]
    +----------+
    | Column |
    +----------+
    | date |
    | version |
    | dump |
    | id | int(11) |
    | platform |
    | viewed |
    +----------+

    View Slide

  20. View Slide

  21. View Slide

  22. View Slide

  23. https://t.me/WebPwn
    https://twitter.com/i_bo0om

    View Slide