Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Speaker Deck
PRO
Sign in
Sign up for free
Partyhack 3.0 - Telegram bugbounty writeup
Bo0oM
April 12, 2019
0
3.7k
Partyhack 3.0 - Telegram bugbounty writeup
Bo0oM
April 12, 2019
Tweet
Share
More Decks by Bo0oM
See All by Bo0oM
31337
bo0om
0
15
Your back is white
bo0om
0
72
FTP2RCE
bo0om
0
4.2k
Interpret it!
bo0om
0
830
At Home Among Strangers
bo0om
1
2.8k
2000day in Safari
bo0om
2
1.8k
Defcon Russia | Bo0om vs Шурыгина
bo0om
0
1.5k
Featured
See All Featured
Making Projects Easy
brettharned
98
4.3k
ReactJS: Keep Simple. Everything can be a component!
pedronauck
655
120k
Building Better People: How to give real-time feedback that sticks.
wjessup
344
17k
Pencils Down: Stop Designing & Start Developing
hursman
112
9.8k
Optimizing for Happiness
mojombo
365
63k
The Success of Rails: Ensuring Growth for the Next 100 Years
eileencodes
10
3.4k
How To Stay Up To Date on Web Technology
chriscoyier
780
250k
JavaScript: Past, Present, and Future - NDC Porto 2020
reverentgeek
37
3.3k
The Language of Interfaces
destraynor
148
20k
Automating Front-end Workflow
addyosmani
1351
200k
The Invisible Customer
myddelton
110
11k
Raft: Consensus for Rubyists
vanstee
126
5.4k
Transcript
Вступление
None
None
None
КАК-ТО МНЕ НУЖНО БЫЛО ПРИДУМАТЬ ТЕМУ ДЛЯ ДОКЛАДА Как я
телеграм ломал
None
None
https://github.com/Bo0oM/fuzz.txt
https://github.com/Bo0oM/server-status-monitor
None
None
None
https://github.com/telegramdesktop/tdesktop/blob/cc2c13d0182c62dd5a89784a49ec375306 449797/Telegram/SourceFiles/core/crash_report_window.cpp#L506
None
None
None
None
None
Database: tdesktopdbase Table: users [4 columns] +----------+ | Column |
+----------+ | id | int(11) | | login | | logincrc | | pwdhash | +----------+ Database: tdesktopdbase Table: keyvalue [3 columns] +--------+ | Column | +--------+ | key | | value | | id | +--------+ Database: tdesktopdbase Table: crashes [6 columns] +----------+ | Column | +----------+ | date | | version | | dump | | id | int(11) | | platform | | viewed | +----------+
None
None
None
https://t.me/WebPwn https://twitter.com/i_bo0om