breaking-telegram
Simple PoC script that allows you to exploit telegram's "send with timer" feature by saving any media sent with this functionality.
Status
Working
PoC
How to
Step 0
git clone https://github.com/matteounitn/breaking-telegram.git
Step 1
- Go to https://my.telegram.org/auth?to=apps;
- Create an app(doesn't matter how do you call it);
- Get API ID and API KEYS;
- Replace them in
config.ini.example
and save it asconfig.ini
Step 2
cd breaking-telegram
python3 -m venv venv && source venv/bin/activate
pip3 install -r requirements.txt
python3 broke.py
Now insert your number and your code.
Eventually you will be asked for a password, if you have one set in your account.
Step 3
Receive an image with timer (could also be a video or gif). Check your saved messages.
Take Home
Use secret chats. They're not bulletproof, but they're definitely safer.