

Francesco Poldi
4.9K posts

@noneprivacy
🔍👀 Senior Open Source Intelligence Developer and Researcher. 🔑👤 Privacy is a Human Right.



ONE-CLICK TELEGRAM IP ADDRESS LEAK! In this issue, the secret key is irrelevant. Just like NTLM hash leaks on Windows, Telegram automatically attempts to test the proxy. Here, the secret key does not matter and the IP address is exposed. Example of a link hidden behind a username: [@nickname](t.me/proxy?server=1…)





‼️Telegram has a vulnerability that allows proxy bypass by sending a link disguised as a username When the victim clicks the mentioned username, they connect to the specified proxy, exposing their IP address.







📢 Workshop Announcement 📢 "Better open-source investigations with Ubikron" -6 December - 13:00-18:00- @RoelofTemmingh Learn how to conduct open-source intelligence investigations and research using the new Ubikron system. Buy workshop tickets now: ow.ly/mWHy50TPEzM















