Telegram's MacOS flaw allows it to recover deleted messages - ICSS

Introduction

Trustwave Spider Labs Lead Threat Architect -Reegun Richard Jayapaul, identified the issue in Telegram MacOS's Self-Destruct feature, which is part of the messaging app's Secret-Chats feature that uses end-to-end encryption.

Jayapaul reported a bug in macOS Telegram version 7.5 that causes any shared location, music, video, or documents transferred via the app to be preserved in the Telegram cache under the path:“/Users/Admin/Library/GroupContainers/XXXXXXX.ru.keepcoder.Telegram/appstore/account-1271742300XXXXXX/postbox/media”.

Telegram

The Secret-Chat is saved in this directory with the prefix "secret-file-xxxxxx." “Any media files submitted to Telegram, except attachments, are downloaded by default to the aforesaid cache folder,” he explained in the article. Locations that have been shared are saved in the form of an image.

Jayapaul described two situations in which the issue might be exploited: one in which both the sender and the recipient of the messages or locations' privacy is violated, and the other in which only the sender's privacy is violated

Someone sends a voice recording, video message, or photograph, or exposes his or her location in the first scenario, and then turns on the "self-destruct" option. According to how the feature works, once the receiver reads the message, it is removed. “However, the files are still available for retrieval locally inside the cache folder,” Jayapaul stated.

The second option relies on the message recipient going into the cache folder to retrieve the self-destructing file, or deleting the messages without reading them in the Telegram app. According to the post, the sender will never know if the message was read, and the recipient will keep a permanent copy of the material.

Why Choose Indian Cyber Security Solutions (ICSS) ?

Indian cyber security Solutions is one of best institute of India among other institute in India. ICSS offer as CEHv11 Courses in India as well as kali Linux. ICSS has won as many award for giving the online training as well as offline training. Its way of giving the training is unique which is easily adapted by the student as well as the professional. Due to way how ICSS trained the student it has got as many award some of award are Tech Brand of 2020,Ten most trusting cyber security certification provider 2021 and many more.

Among the many Ethical Hacking course in India, Indian Cyber Security Solutions would be the right for you to join. We have the right set of practical lab classes set up for students to learn as well as industry grade trainers who would conduct the classes and impart the right set of Cyber Security Knowledge to students. Our efforts have been acknowledged by various reputed administrative institutes, such as "Top Ten Training Institutes in India in 2020 by Silicon India; as well as Ten Most Trusted Training & Cyber Security Certifications Provider, 2021 by The Knowledge Review.

As an Education Institute, we are also cyber security service provider to corporate organization. Services like VAPT, Web Penetration Testing, Network Penetration Testing, Mobile Application Penetration Testing to corporate organization like IRCTC, HDFC, Cambridge Technologies, and many more. With this, Indian Cyber Security Solutions have been acknowledged as the 20 Tech Brands of 2021. by Business Connect India.

Our Cyber Security Services

Cyber Security is extremely important for every organisation and that we understand that data theft avoided is better than data theft done. Thus we also provide cyber security services to various MNCs across India. Our team is professional in providing Web Application Penetration Testing, Network Penetration Testing, Mobile Application Penetration Testing to clients.

We this, we have been acknowledged as the top 20 most Cyber Security Trusted Brands for 2021 by The Global Hues. We stand by to our commitment in providing the right cyber security training to students. We have provided services to clients like Madhya Pradesh Gramin Bank, Odisha State Pollution Control Board, HDFC Life Insurance Corporation, Qatar Development Bank and many more.


CERTIFIED COMPANY


MEMBER OF



OUR ADDRESS

KOLKATA

Globsyn Crystals Building,5th Floor, Unit-4, Webel MoreKolkata – 700091

BANGALORE

Chirush Mansion, 3478J HAL 2nd Stage,13th A Main Road Indiranagar Bangalore – 560008 Land Mark: Behind New Horizon School

CANADA141E34

Indian Cyber Security Solutions Cyber Security Research & Analytics Center Vine Avenue Moncton NB,Canada, PO E1E 1J9

AUSTRALIA

Indian Cyber Security Solutions Australia (Research and Development Center)11 Darling Street, Hughesdale Melbourne VIC. 3166

© 2021 Indian Cyber Security Solutions | Green Fellow IT Security Pvt. Ltd.