4 ms·
Calling it "remote code execution" is veeeery clickbait-y. By this logic, any website with download links uses "remote code execution". Even the source article
by wizzard0 9y ago
Calling it "remote code execution" is veeeery clickbait-y. By this logic, any website with download links uses "remote code execution".
Even the source article says just "zero-day".
Also, tldr: Using Unicode Right-To-Left, you can make Telegram show file name "gpj.js" as "sj.jpg". That's all.
- kbart 9y agoYeah, I was disappointed as well. This "zero day remote code execution" actually is not much more than good, old "important_document.pdf.exe" just slightly more obscure.
- Tenobrus 9y agoThe "exploit" doesn't even have anything to do with Telegram specifically (except presumably that there's some known real world use on that platform). I'm surprised at this kind of article coming from Kaspersky.
- thinkMOAR 9y agoand it seems to be limited to windows only, imho not a detail to leave out
- jwilk 9y agoBut it's not "zero-day" either. The aricle says it was discovered in October 2017, and that they "informed the Telegram developers of the problem, and the vulnerability no longer occurs in Telegram’s products".
- escapologybb 9y agoThis is mildly off topic but regarding clickbait titles, does anyone have any good idea how we can stop them? Because everybody hates them, but everybody clicks on them. Seriously, I hate the way BBC News has turned into a clickbait nightmare; but I still clicked on the "my husband turned into an otter, then became a security professional" link, or whatever it was. It's a knotty problem. Also exploits in software bad.