The company behind the Signal clone used by at least one Trump administration official was breached earlier this month. The hacker says they got in thanks to a basic misconfiguration.
How the Signal Knockoff App TeleMessage Got Hacked in 20 Minutes
https://www.wired.com/story/how-the-signal-knock-off-app-telemessage-got-hacked-in-20-minutes/
4 Comments
krogoth@infosec.pub · 7 pts · 1y
«When they loaded this URL, the server responded with a Java heap dump, which is a roughly 150-MB file containing a snapshot of the server’s memory at the moment the URL was loaded.»
Comedy gold, the whole article…
raltoid@lemmy.world · 1 pts · 1y
Client side md5 password hashing, JSP, having public facing links to dump the heap due to default configuration..
Either this was made by someone who took a programming course twenty years ago and haven't touched it since. Or it was intentionally made to be insecure.
LadyMeow@lemmy.blahaj.zone · 1 pts · 1y
What the….? Why use a knockoff? Signal is free…
Chronographs@lemmy.zip · 5 pts · 1y
Because they want to archive their messages assumedly, and because they’re clownishly incompetent of course