Уровень 0 · материалов: 2
В кластер входят документы об обнаружении уязвимостей в мессенджере Telegram и не входят документы об уязвимостях в банковских платежных системах.
Общие признаки: поиск уязвимостей, этический хакинг, выплата вознаграждений, взаимодействие с вендорами
Группа выше: Bug bounty и раскрытие уязвимостей
Смысл: The text describes the process of an ethical hacker discovering and exploiting several vulnerabilities on a Telegram server used for crash reports, eventually leading to a successful bug bounty reward through a SQL injection attack.
A security researcher discovers a SQL injection vulnerability on a Telegram crash-report server via Apache misconfigurations and earns a $2,500 bounty.
Смысл: The text describes a security researcher's experience finding a flaw in Telegram's auto-delete feature on Android, where images were not actually deleted from the device cache. It highlights the frustration of the researcher dealing with Telegram's support and their attempt to enforce a strict NDA in exchange for a bounty, eventually leading to the public disclosure of the CVE.
A researcher exposed a Telegram Android bug where 'auto-deleted' images remained in the device cache and detailed the company's attempt to silence them with a restrictive NDA.