#今天又看了啥 #telegram #security #CVE #XSS
Telegram Web app XSS/Session Hijacking 1-click [CVE-2024–33905]
Attack surface: Telegram Mini Apps
“Telegram Mini Apps are essentially web applications that you can run directly within the Telegram messenger interface. Mini Apps support seamless authorization, integrated crypto and fiat payments (via Google Pay and Apple Pay), tailored push notifications, and more.”
This attack surface also affects web3 users because it handles crypto payments through the TON Blockchain.
Telegram fixed the flaw on March 11th, 2024.
Vulnerable version: Telegram WebK 2.0.0 (486) and below
Fixed version: Telegram WebK 2.0.0 (488)
https://medium.com/@pedbap/telegram-web-app-xss-session-hijacking-1-click-95acccdc8d90
Telegram Web app XSS/Session Hijacking 1-click [CVE-2024–33905]
Attack surface: Telegram Mini Apps
“Telegram Mini Apps are essentially web applications that you can run directly within the Telegram messenger interface. Mini Apps support seamless authorization, integrated crypto and fiat payments (via Google Pay and Apple Pay), tailored push notifications, and more.”
This attack surface also affects web3 users because it handles crypto payments through the TON Blockchain.
Telegram fixed the flaw on March 11th, 2024.
Vulnerable version: Telegram WebK 2.0.0 (486) and below
Fixed version: Telegram WebK 2.0.0 (488)
https://medium.com/@pedbap/telegram-web-app-xss-session-hijacking-1-click-95acccdc8d90
https://csgo.5eplay.com/article/2404308vw1rc
省流:CS 赛事 EPL S19 可能国内播映翻车
省流:CS 赛事 EPL S19 可能国内播映翻车
微软放出 36 年前的 MS-DOS 4.0 版系统源代码
https://www.ithome.com/0/764/343.htm
https://github.com/microsoft/MS-DOS
https://www.ithome.com/0/764/343.htm
https://github.com/microsoft/MS-DOS
https://doc2x.noedgeai.com?inviteCode=HIJZXM
目前新上了图像畸形矫正和API(需申请)功能,团队承诺对个人用户单日免费500页,整体来看还是比较不错的
他们自己准备的软文: https://mp.weixin.qq.com/s/IxNls2pU_IzV--hsxBBFdg
广而告之:Telegram 移动端 客户端内自助编辑 Sticker 功能现已实装.
https://telegram.org/blog/sticker-maker
https://telegram.org/blog/sticker-maker
#security
完全无法想象
省流:Facebook收了一个VPN公司,然后给用户装CA来解密竞争对手的App流量以用作分析。
https://techcrunch.com/2024/03/26/facebook-secret-project-snooped-snapchat-user-traffic/
完全无法想象
省流:Facebook收了一个VPN公司,然后给用户装CA来解密竞争对手的App流量以用作分析。
https://techcrunch.com/2024/03/26/facebook-secret-project-snooped-snapchat-user-traffic/
【信息学竞赛 (OI) 究竟发生了什么?-哔哩哔哩】 https://b23.tv/eFNjTfw