How the Signal Knockoff App TeleMessage Got Hacked in 20 Minutes

https://www.wired.com/story/how-the-signal-knock-off-app-telemessage-got-hacked-in-20-minutes/

The company behind the Signal clone used by at least one Trump administration official was breached earlier this month. The hacker says they got in thanks to a basic misconfiguration.

28 points · 4 comments · view on lemmy.world

4 Comments

krogoth@infosec.pub · 7 pts · 1y (1 reply)

«When they loaded this URL, the server responded with a Java heap dump, which is a roughly 150-MB file containing a snapshot of the server’s memory at the moment the URL was loaded.»

Comedy gold, the whole article…

raltoid@lemmy.world · 1 pts · 1y

Client side md5 password hashing, JSP, having public facing links to dump the heap due to default configuration..

Either this was made by someone who took a programming course twenty years ago and haven't touched it since. Or it was intentionally made to be insecure.

LadyMeow@lemmy.blahaj.zone · 1 pts · 1y (1 reply)

What the….? Why use a knockoff? Signal is free…

Chronographs@lemmy.zip · 5 pts · 1y

Because they want to archive their messages assumedly, and because they’re clownishly incompetent of course