Postlar filtri


Tech & Leaks Zone dan repost
BREAKING: Nekogram is secretly transmitting your telegram account phone number to the developer

According to SOTA,
"The backdoor is hidden in the http://Extra.java file, which differs from the template uploaded to the repository. The obfuscated code sends data as an inline request to the @nekonotificationbot, leaving no trace. The same file implements account 'doxing' via several bots; it is possible that the leaked data is used to populate their databases."

Additionally, the creator of the Nekogram client, (presumably a Chinese national) was previously known for conducting DDoS attacks and unethical online behavior (including death threats against acquaintances).

Apparently, in the early versions of the client, de-anonymization was applied only to Chinese phone numbers, which could have been used for political surveillance;. However, it is now applied to all users.

Follow @TechLeaksZone


I’m not going to endorse any telegram clients. Make sure you follow the opsex guides. 🐝🐝


Stop using Nekogram.




What to Do When Your OPSEC Fails


You can't control things that are beyond your control.🥲

Doxing attempts are on the rise on Telegram due to recent leaks (https://t.me/durov/441).


What if someone obtains your name, number, or other personal information and threatens to leak it on Telegram?


If it happens, it happens. The most you can do is block the number or stop receiving calls and messages from unknown contacts. As always, never click on unknown links. Even if someone expects ransom, don't give a sh*t about those morons😏.


If you want to take legal action against them?

Yes, it’s possible. Telegram provides suspect information when you file a complaint with the police. (Telegram complies with most countries' legal requests.)


P.S. No one can hack your bank account just by knowing your mobile number or bank account number. I know it’s a general statement, but it applies here. YOU ARE NOT SPECIAL, Millions of user data is getting stolen and leaked every month and you are just a drop in it😂


Reason: almost more than 30-40% of the people numbers on telegram are leaked (specifically old telegram accounts and in some cases new accounts too). If possible try to using a different number to create the account as Im unsure the extent.


Friendly update, everyone who's using telegram from more than 1 year, delete that account and recreate. Don't forget to clear all the chats history from all the groups, exit and clear the DMs too.

I'll mention the reasons later, for now, this is the update.


This data was not leaked due to cyberattacks on the mentioned websites, but rather through info stealer malware, phishing campaigns, credential stuffing, and other methods.

Should you be worried?

If you regularly rotate passwords for sensitive websites it's good and avoid using the same password across multiple sites, and enable two-factor authentication (2FA) on sensitive accounts like telegram, email and financial services.


Use a password manager to store your passwords securely ( only if it allows you to set up your own encryption.)

Also, ensure your passwords are at least 8 characters long and include uppercase and lowercase letters, numbers, and special characters.

A password shouldn’t be something easy to remember... it should be something you must remember.



❌ Weak Password = Not secure

✔️ Weak Password + 2FA = Safer, unless there are vulnerabilities that can bypass 2FA

✔️ Strong Password = Secure if there's no option to enable 2FA

✔️ Strong Password + 2FA = Most secure, as long as there are no other vulnerabilities compromising the account




Stop using Nice gram..

Not open source and we don't know what they going to inject into it.


Okay, Nagram looks good. It supports PGP signing, encryption, decryption, and includes a duress feature. It uses OpenKeyChain, so Nagram won't store your private keys.
Project link: https://github.com/NextAlone/Nagram


Don't click on links or usernames without verifying their legitimacy.

Example 1 - Links:
1. fragment.com
2. fragment.com

Example 2 - Usernames:
1. @rose
2. @rose

Safety steps:
1. Long-press any link before clicking to reveal the actual hyperlink destination.

Important character distinctions to verify:
- 'l' (lowercase L)
- 'I' (uppercase i)
- '1' (number one)
- '0' (zero) vs 'O' (uppercase o)

Example 3:
1. @hello
2. @heIIo

Username verification:
- Always check the actual username field, not just the display name or bio
- Impersonators may attempt to deceive by putting legitimate usernames in their bio instead of having the actual username
- Example:
* Legitimate account: Username field: @hello
* Impersonator: Username field: (different or none), Bio: "@hello"


Note: This guide intended only for the ones who’s more towards having privacy(Maybe AnoNyMity on telegram)
1) Don’t use your real number, use any burner numbers. Don’t use telegram based anonymous numbers[ Maybe good for you if you are interested in investment and get less limitations. This is 100 times better than using own number but burner number is best, cheap and also easy to rotate ].
2) Never use real IP.
3) Make sure you change these privacy settings:
- Disable peer to peer calling even for the ones in the contact list
- Hide your number from everyone
- Disable searching you through your number
- Disable generating link previews in secret chats
- Forwarded messages to nobody
4) If you intended to use a username, make sure it’s completely unique and never used. Avoid leaking your DoB year or mobile number ending digits in the username or using the same number sequence else where to your other social media account
5) Better to clear the chats in all the groups whenever you feel to.
6) Don’t use keyboard suggestions. Try to write the words from scratch.
7) Never talk about your alt ids anywhere.
8) Don’t join the same groups you join with your normal account
9) Never use bots like whisper for sensitive conversations . Use a custom one if possible or else stick to PM
10) Use limited words if you want to talk In a public group.
11) Using Once View or Secret Chats or Self Destruct doesn't mean others can't save those conversations.

Differentiation must be there between private and normal account

PS: If you are really a paranoid, don’t talk anything sensitive on telegram cloud chats except in the secret chats or else stick to Simplex[Duress Feature available which will let you put two passwords, one is for login and another one to self destruct chats😉]

13 ta oxirgi post ko‘rsatilgan.

84

obunachilar
Kanal statistikasi