12 ms·
DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage
- limejuicedrop 1y ago[flagged]
- Aurornis 1y agoSo one of their servers had a /heapdump endpoint that publicly served a heap dump of the server? This whole saga is out of control. This group didn’t really “publish” anything, though. They’re offering access to journalists through a request form. They’re also not saying how much actual message content they have because the 410GB of heap dumps makes for a bigger headline number.
- barbazoo 1y agoAren’t those Israeli software companies all supposed to be top notch, ex Mossad, yadda yadda? Doesn’t sound like it. I hope the message dump is juicy.
- treebeard901 1y agoAfter all the concern over China and TikTok, why is the USG using a foreign chat program at all?
- coolcase 1y agoSuperPAC and other corruption
- Calwestjobs 1y ago[flagged]
- basilgohar 1y agoThis article doesn't mention Mossad, though. Do you have any other sources?
- MPSFounder 1y ago[flagged]
- Calwestjobs 1y agoyes, Shin Bet : https://en.wikipedia.org/wiki/Yigal_Amir https://en.wikipedia.org/wiki/Yigal_Amir
- viraptor 1y agoThat's not a great generalisation for the whole country. How many ex Mossad people interested in doing actual implementation in tech companies do you think there are? It's like "aren't those US software companies all supposed to be top notch, ex NSA yadda yadda?"
- conradev 1y agoThey do start a lot of tech companies specifically: https://en.wikipedia.org/wiki/Unit_8200#Companies_founded_by_alumni https://en.wikipedia.org/wiki/Unit_8200#Companies_founded_by... The US only has voluntary military service, so the dynamics are different
- lysp 1y agoThe CEO/Founder of TeleMessage Guy Levit was the head of the Planning and Development Department of an elite technical unit in the Intelligence Corps of the IDF according to bio.
- aorloff 1y agoI guess we could say that in many ways, he never left
- gruez 1y agoI thought Israel has mandatory military service, so ex-mossad or ex-military signals intelligence doesn't really say much? Presumably they're directing people based on their skill set, so you'd expect most hackers to end up in mossad for their mandatory service.
- kennywinker 1y ago> Presumably they're directing people based on their skill set Big presumption. If I were israeli, there’s no way in hell anybody with half a brain would want me near their spy agency. When a gov is committing a genocide, their decisions are based on control and fear, not getting the best out of people. Edit: downvote all you want. Israel is still committing a genocide. No hospitals left standing. Killing aid workers, journalists, and doctors. A million people on the brink of starvation. Literally salting the earth to prevent crops from being grown. That is war crimes, ghettoization, and genocide.
- oceanplexian 1y agoOne problem that smart people tend to make is in thinking that being really smart in one area is generalizable to all others. Just because they're good at AppSec doesn't mean they're good at networking or operating a webserver.
- ripley12 1y agoI agree with this. It's surprising how often I encounter people with that belief, because I was disabused of it very early on in my career; this industry is chockablock with people who are brilliant in 1 area and deficient in others.
- coolcase 1y agoThat's why you need teams. Red team for example! Security team. App developers. Code reviews. You need all the process too. Security that relies on one genius is fragile.
- karn97 1y agoThat sounds more like a stupid person than smart lol
- stefs 1y agoyou can be smart in one area and stupid in others. the "not knowing you're stupid in others" is part of the "stupid in others".
- czl 1y agoAka "halo effect"
- msy 1y agoAnd SBF of FTX fame was ex-Jane St so obviously was a serious finance professional. This is why using past employers as a shorthand for capability is unwise.
- sillystu04 1y agoIn fairness, FTX had a profitable bankruptcy [1]. So it's still better to be scammed by Jane Street alumni than to be scammed by the usual alumni of Goldman Sachs, JP Morgan etc [1] https://www.bloomberg.com/news/articles/2024-05-15/ftx-bankruptcy-will-pay-customers-over-100-but-they-missed-crypto-rally https://www.bloomberg.com/news/articles/2024-05-15/ftx-bankr...
- coolcase 1y agoHow is that fair? It was luck from the AI investment. Pure luck.
- arresin 1y agoIt wasn’t the only smart investment
- fredoliveira 1y agoRegardless of how you feel about SBF and FTX, claiming an early investment into Anthropic is "luck" rather than being ahead of the curve feels off the mark.
- coolcase 1y agoThat is dodging the point. The guy ripped people off. By luck they got the fiat value of their investment at some past date back. Yes if a single investment pays off well enough to negate fraud losses on that scale over a short time scale. It's fucking luck.
- stackskipton 1y agoIt's not profitable. They are getting their money back from value of the assets in 2022 when they went bankrupt but most of crypto assets have gone up significantly in value so it's 2.5 years of lost profit.
- underdeserver 1y ago"All supposed to be". This is a country of 10 million people, a rather heterogeneous one at that. There are going to be better and worse companies.
- H8crilA 1y agoThey are top notch - at working for profit and for the interests of their country.
- rsynnott 1y agoI'm not sure why you'd expect intelligence agency types to be particularly good at engineering, tbh.
- rainworld 1y agoSpooks in general like to project a veneer of competence, downright invincibility. Entertainment media, journalists, experts play a big role in this. And by and large it works. It’s especially true for spooks of a certain entity. Also, it’s easy to confuse brazenness, being protected from consequences, and usually downplayed or secret Western complicity with competence.
- rsynnott 1y agoI mean, I'm sure they're competent in some stuff, but being competent in one field doesn't generally mean being magically competent in _all_ fields.
- keeda 1y agoI'm not sure about this case, but maybe the assumption here is that these are people from a technical branch of Mossad, such as Unit 8200, which does SIGINT. I've interviewed 3 of them for your typical Big Tech SWE position, and to a candidate, they were very strong engineers. I never got to work with them, however, because they always got better counteroffers...
- ExoticPearTree 1y ago> Aren’t those Israeli software companies all supposed to be top notch, ex Mossad, yadda yadda? Working with a few companies like these, I can tell you that the marketing is top-notch, and very aggressive. The products not so. Most get better with time.
- coolcase 1y agoYeah the /leakitbaby endpoint was meant for just them, not the world! Doh!
- elzbardico 1y agoIt only takes one guy doing one stupid thing to have a security incident. Yeah, processes should be in place, but no process is perfect.
- mingus88 1y agoCan you imagine co-opting a trusted and secure (and free) bit of software and just making it worse at seemingly every turn? And charging for it?! I’m not sure what is more embarrassing: to be the company or to be a user.
- hypeatei 1y agoWhy would the company be embarrassed? The users (i.e. high level U.S. officials) did no due diligence. Of course a private company is going to take the easiest and cheapest route. If it goes bad, just shut down and spin up a new entity. Some speculate this was intentional intelligence gathering by the Israelis which is plausible too.
- dylan604 1y ago>Some speculate this was intentional intelligence gathering by the Israelis which is plausible too. Which does not bode well for the customers' counter intelligence abilities
- n2d4 1y ago> Some speculate this was intentional intelligence gathering by the Israelis which is plausible too. How does this make sense? If they were gathering data, why would they add a public download? Surely the Israeli officials would not want foreign powers to access this? Per Hanlon's razor, I don't think this is attributable to anything other than incompetence.
- g-b-r 1y agoI mean, it could theoretically have been to provide plausible deniability, but it seems extremely more likely to have been incompetence and carelessness (and if they were also sending everything to Israel, it was probably through some unencrypted ftp upload).
- barbazoo 1y agoTwo things can be true at once. Them using their access to unencrypted messages for nefarious purposes and them being incompetent at the same time leaving that endpoint open.
- jfim 1y agoSounds like someone had a Java app and mistakenly exposed all of the JMX endpoints over HTTP. It's not the default configuration, and likely done out of carelessness.
- 0xbadcafebee 1y agoOr intentionally. There could be an APM agent which just lets you run heap dumps any time you want, or they enabled heap-dump-on-crash, or had a heap dump shutdown hook, etc. There's a lot of ways to trigger dumps. If we're talking about a full dump, and the apps were using most of the memory allocated to their container/VM/etc, 410GB is actually not that many dumps (we're probably talking uncompressed). At 4GB/dump, that's around 100, over possibly several years. I just wonder where they were storing them all? At one place I worked, we jiggered up an auto shutdown dump that then automatically copied the compressed dump to an S3 bucket (it was an ephemeral container with no persistent storage). Wonder if they got in through excessive cloud storage policies and this was just the easiest way to exfiltrate data without full access to a DB.
- pigbearpig 1y agoFrom the Wired article, it may not have even been a mistake, depending on the version of Spring Boot. "Spring Boot Actuator. “Up until version 1.5 (released in 2017), the /heapdump endpoint was configured as publicly exposed and accessible without authentication by default."
- formerly_proven 1y agoThis was also part of the exploit chain in the "Volksdaten" incident.
- davedx 1y agoThis sounds utterly insane. Is Actuator a standard part of Spring Boot or is it an optional package of some kind?
- teekert 1y agoImaging putting up a firewall to mitigate this, then docker compose helpfully opening the ports for you. Security comes in layers.
- kbouck 1y agoif a heap dump is a copy of all the bytes in memory, then wouldn't "thousands of heap dumps" likely be larger than 410GB? napkin math: 410GB/1000 dumps = 410MB per dump? 410GB/2000 dumps = 205MB per dump
- diggan 1y agoMight be filtered somewhat, like extracted all ASCII text then compile that into the dump, rather than just the raw dump files. Edit: reading the description on the dump again, seems exactly what they did: > Some of the archived data includes plaintext messages while other portions only include metadata, including sender and recipient information, timestamps, and group names. To facilitate research, Distributed Denial of Secrets has extracted the text from the original heap dumps. https://ddosecrets.com/article/telemessage https://ddosecrets.com/article/telemessage
- coolcase 1y agoKubernetes pods?
- trebligdivad 1y agoIs this a heapdump of servers or of clients? I can imagine that might have been intended as a place for crashing clients to log
- BearOso 1y ago> They’re also not saying how much actual message content they have because the 410GB of heap dumps makes for a bigger headline number. That's very important to say. I went through one of these massive data dumps recently and it was literally all cached operating system package updates and routine logs. Nothing at all of interest. It's easy to cut the size on a heap dump. When it's not done it seems sketchy. But it could be a 512GB dump and already pruned, so I could be wrong.
- harrall 1y agoMost of the the heap dump will be filled with stuff like java.util.String!blahjava.util.ArrayList! Though the heap dump would have messages in flight at the time. It's obviously not as useful if you are just trying to grab messages for a specific person. Frankly the most useful part might be any in-memory secret keys, which could be useful for breaking deeper into the system.
- deleted 1y ago[deleted]
- aorloff 1y agoPlenty of info from a live heap dump if you know what you are doing. But these guys are only interested in "journalists" not people who spent decades digging into ad server heap dumps
- kleton 1y agoTeleMessage is most likely an intelligence asset, and a burned one now that Trump's people stopped using it. A fake hack is the safest way for the agency responsible to leak the messages collected.
- aorloff 1y agoand provide a plausible reason for the shutdown
- CyberMacGyver 1y ago[flagged]
- greyface- 1y agoI don't disagree generally, but it should be noted that the TeleMessage federal contracts predate this administration. > According to Padgett and government records reviewed by NBC News, government contracts (some of which are still current) involving TeleMessage go back years, predating the current Trump administration. One current contract that mentions TeleMessage allocated $2.1 million from the Department of Homeland Security and FEMA for “TELEMESSAGE MOBILE ELECTRONIC MESSAGE ARCHIVING,” beginning in February 2023, with an August 2025 end date. https://www.nbcnews.com/tech/security/photo-appears-shows-mike-waltz-using-signal-app-can-archive-messages-rcna204434 https://www.nbcnews.com/tech/security/photo-appears-shows-mi... https://www.usaspending.gov/award/CONT_AWD_70FA3123F00000028_7022_70RTAC21D00000006_7001 https://www.usaspending.gov/award/CONT_AWD_70FA3123F00000028...
- tw04 1y agoSure, but was it being used to send secure military messages in the past? Or was it being used as a slightly more secure text messaging replacement by agencies that weren’t subject to the same security requirements as the Secretary of Defense?
- timewizard 1y ago> but was it being used to send secure military messages in the past? We have no information on that one way or the other. > a slightly more secure text messaging replacement Yea but it wasn't secure at all. For any purpose. > that weren’t subject to the same security requirements as the Secretary of Defense? Regardless of who is using it and for what purpose I'd like the server to actually be secure. This isn't a left vs. right issue. This is an overall government incompetence issue.
- mikem170 1y agoIt is my understanding that the normal procedures mandate that government supplied locked down devices be used for classified communications, not personal phones running Israeli cloud-connected messaging apps. This is comparable to everyone using Hillary's email server for classified messaging, except also controlled in a foreign country, and oops very insecure. Even office drones working at a bank aren't allowed to do such things. This is not normal.
- 0xbadcafebee 1y ago> Because the data is sensitive and full of PII, DDoSecrets is only sharing it with journalists and researchers. Yeah I'm normally a big proponent of responsible disclosure, but in this case, I think the more painful, damaging leak is required. Firstly, autocrats, fascists & oligarchs don't care that much if you hack them. They will just keep using these tools (or another one just like it) ignoring the correct procedure their government already wants them to use. The citizens of affected nations need to be made angry by their leaders' failure to do their jobs correctly, and that's only gonna happen when there are consequences for their actions. Their incompetence put their nations at risk, and now it's clear they have failed to keep their intel safe. They have failed hard, let them fail hard. Second, journalists and researchers have almost completely lost their power. In a non-democratic world (we're nearly there, just give them a little more time), when a journalist exposes corruption or incompetency, that journalist/researcher is simply silenced by the government. Silence the journalists and nobody knows what's going on so oppression can continue unchecked. Every person who gets silenced has a greater chilling effect on the whole society; nobody wants to be next. This is how authoritarians gain power. Oppression with no resistance or consequence legitimizes the oppression. If we were just talking about typical corporate incompetence re: security, and the only thing at stake is a single stock or individuals' data, I would say disclose responsibly. But when it comes to stopping autocracy, the gloves have to come off. They sure as shit aren't gonna play by any rules, so neither should we.
- CobrastanJorji 1y ago> The citizens of affected nations need to be made angry by their leaders' failure to do their jobs correctly, and that's only gonna happen when there are consequences for their actions. This is a really dangerous line of thinking. It's the line of thought that slides forwards to "I love America so much, but to save America I have to get Americans to really feel the pain, and to do that I need to <horrible violence> to them to wake them up and make them see how things are bad." Hurting people in order to make them see how they are being hurt is almost never the right call.
- scheeseman486 1y ago
- yieldcrv 1y agobeautiful, any prediction markets tied to this? I need to stop betting on those things, I’m so bad at it
- goalieca 1y agoSecurity standards need to start banning heap dumps.
- GuinansEyebrows 1y agoSomething tells me that wouldn’t make a huge difference in some of these companies opsec.
- sneak 1y agoI’m pretty sure they already do, especially endpoints open to the whole internet that are unauthenticated.
- lionkor 1y agoIf only there was a rule saying "don't do that, this would not have happened
- deleted 1y ago[deleted]
- guluarte 1y agocannot the pentagon with their billions in funding make a secure app?
- hn_throwaway_99 1y agoYes, and they do. The fact that the leaders of our present kakistocracy don't use it should not be an indictment of the civil and military workers in the US military.
- sneak 1y agoNo, the fact that they still work for the US government given “our present kakistocracy” is a sufficient indictment.
- pigbearpig 1y agoNot when "off the shelf" is the motto. They'd still have to outsource the development and at that point would be questioned why spending that much money when Telemessage sells the product. Unfortunately, the financial structure doesn't really make it easy for custom DoD software.
- loeg 1y ago[flagged]
- greyface- 1y agoIt's been weeks since the initial TeleMessage revelation... has the Signal Foundation responded in any way to the news? They condemn open source third-party clients and threaten trademark litigation when people use the "Signal" name in interop projects. Meanwhile, total silence when a defense contractor does the same thing.
- th0ma5 1y agoYou're making me wonder if Signal is the customer of the third party and not the government.
- ethersteeds 1y agoThe charitable answer is that organizations across US society are currently all trying to be very still and quiet and not do anything to provoke a vindictive assault by this administration. The less charitable one is that Moxie was the opinionated and uncompromising core of the Signal Foundation and has been removed from the board and completely vanished from the public eye. What it stands for now is a touch less clear.
- Ey7NFZ3P0nzAe 1y agoMeredith Whittaker seems kinda fearless though
- h4ck_th3_pl4n3t 1y agoRemember Signal FOSS fork that got cease and desisted? How is Molly doing these days? Is there an alternative server you could selfhost?
- decimalenough 1y agoSignal has done nothing wrong here. There's nothing they could meaningfully say that would do anything except draw heat from people looking for a scapegoat. This mess is entirely the fault of Telemessage and the people who chose to use it for top-secret comms.
- asdffdasy 1y ago
- bob_theslob646 1y agoIsn't it against the law in the United States to use outside channels for government communications? Wasn't this the whole scandal about Clinton? Please correct me if I am wrong.
- afavour 1y agoAmazingly the app is on the governments list of approved apps. The scandal is what they’re discussing on there: highly sensitive information you normally go to very secure channels to talk about.
- rtpg 1y agoMy understanding is that it was added fairly recently at that, and already this has happened. This must be a record time in "change of policy leading to the most embarassing result". Only a couple of months!
- ensignavenger 1y agoAccording to the article: "TeleMessage has been used by the federal government since at least February 2023" I don't know if that use was authorized or not.
- ok123456 1y agoThis is a pitfall of having an approved software list (whitelist). Malfeasance or misfeasance could include flat-out spyware versions of software, often made available in internal "software stores," instead of legitimate software distributed from the developer or through official channels.
- deleted 1y ago[deleted]
- floam 1y agoThe app exists to comply with the regulations, was my understanding.
- 1y ago
- willmarquis 1y agoExposing unauthenticated /heapdump endpoints in production is a rookie mistake-especially for a service handling sensitive government comms. The presence of MD5 hashes and legacy tech like JSP just adds to the picture of poor security hygiene. This breach is a textbook case of why defense-in-depth and regular audits are non-negotiable.
- Traubenfuchs 1y agoDon't hate on JSP. Java Server Pages is now Jakarta Server Pages, part of Java EE (Jakarta EE) and it's latest version 11 was released just a year ago. Spring Framework 7 will be released by the end of 2025 and be based on it. Tomcat 11 is already based on it as well. And all of this is based on the thriving Java ecosystem. Version 12 is under development. If they kept their stuff updated, nothing about this is legacy. It just declined in popularity. You can build insecure trash and expose unprotected endpoints with next.js, or whatever is currently considered state of the art, as well.
- deleted 1y ago[deleted]
- WatchDog 1y agoGreat example to use whenever legislators want to ban or add backdoors to e2e encryption.
- runlevel1 1y ago"clean on OPSEC" - Pete Hegseth That line simultaneously becomes funnier and more depressing.
- TechDebtDevin 1y agoYeah no thanks, not donating to gate keepers who want to maintain the status quo. I'll give my coin to wiki leaks and groups with balls.
- zombiwoof 1y agoIf no one will persecute criminals they will keep breaking all laws
- jfritsch1984 1y agoWe‘re doing something way less critical at my job. But we have two pentests per year by external companies. How on earth is this level of incompetence even legal.
- treebeard901 1y ago"We are currently clean on OPSEC"
- pawanjswal 1y agoWow, this whole TeleMessage leak feels like a spy thriller.
- asdffdasy 1y agoif you get your spy thrillers from Mexican day time tv soap opera script writers, yes.
- halfmatthalfcat 1y agoTelenovella about spy’s? Sign me up.
- gregorvand 1y agoTeleMessage CEO LinkedIn bio - reads like a terrible AI hatchet job: "At the helm of TeleMessage, my leadership is defined by strategic innovation and a steadfast commitment to advancing telecommunications solutions. With a focus on SaaS products, our team has successfully navigated the industry's evolution, ensuring that we remain at the forefront of technological advancements. My role encompasses not only the oversight of our direction but also the cultivation of a culture that values ethical standards and collaborative success. Our achievements are anchored in a proven track record of delivering results and solving complex problems with efficiency. Spearheading business development and marketing initiatives, we have established a reputation for excellence within the telecom sector. The acquisition of TeleMessage by Smarsh in 2024 stands as a testament to our team's dedication and my leadership in driving growth and fostering a united vision."
- notpushkin 1y agoThis just reads like a terrible LinkedIn-speak to me.
- walrus01 1y agoSufficiently advanced human written linkedin-speak is indistinguishable from a barely coherent chatgpt 3.5 that's been instructed to speak in business buzzwords.
- teekert 1y agoHahaha, I was thinking the exact same thing! I can imagine myself reading this 10 years ago and think: Wow this guy is on top of his CV game, how concise and elegant. But now, everybody has this ultra condensed LinkedIn speak, it has become so cringe, so meaningless.
- CGMthrowaway 1y agoOverly polished language, abstract phrasing, and a focus on generalities over specifics.
- 1y ago
- nlitsme 1y agoI think this is abuse of the word 'publish'
- udev4096 1y agoThe title is outright wrong and should be criticized for spreading false information. They have NOT published anything, it's only for "researchers", which is a way of saying "we will write false title of this article just so we can get a lot of attention"
- ayrtondesozzla 1y agohttps://nitter.net/ProjPM/status/1915527064070881379#m https://nitter.net/ProjPM/status/1915527064070881379#m Is this group not very seriously discredited, with ties to FBI, convicted child porn criminals, etc? Or am I getting something mixed up? This could still be a legitimate leak, of course. I'm just wondering if this info is publically known, or if I'm conflating things
- namdnay 1y agoHowever bad their Signal fork was, at least it was legal. What's crazy is that this very company was also selling a cracked WhatsApp, which is a whole different kettle of fish... and people were buying it! real corporations and governments were buying this crap - it's insane https://smarsh.my.salesforce.com/sfc/p/#30000001FgxH/a/Pb000000r00H/0aFJJ3tCViox8quTxN05CvEu53Cz22.IvHqz4o4EoIc https://smarsh.my.salesforce.com/sfc/p/#30000001FgxH/a/Pb000...
- pid-1 1y ago> and people were buying it! real corporations and governments were buying this crap - it's insane Anedote: in Wall Street, Global Relay and TeleMessage are the major players when it comes to achieving communication for compliance.
- asdffdasy 1y agobefore that wallstreet ran on yahoo messenger! they only stopped because new yahoo brand owners didn't understood the value of this and shut it down because there weren't enough teens signing up.
- n2d4 1y agoWhy would that be illegal? In the Beeper case, the DOJ has not been sympathetic to companies attempting to ban third-party messaging clients of proprietary protocols [0] — is WhatsApp different? The WhatsApp archiver, from what I can tell, seems to install a patch on the user's WhatsApp installation. Probably a security nightmare, sure, but I don't think it would be illegal. https://techcrunch.com/2024/03/21/doj-calls-out-apple-for-breaking-imessage-on-android-solution-beeper/ https://techcrunch.com/2024/03/21/doj-calls-out-apple-for-br...
- namdnay 1y agoThey are actually distributing a rebuilt client binary, complete with the Meta branding. That’s a clear breach of both the licensing of the software (I’m pretty sure it’s not open source) as well as the trademarks of Meta It’s not the same thing as providing a compatible app with their own branding
- Yizahi 1y agoI love when politicians, lobbying for the backdooring all communication software are getting pwned in the same way. Too bad they lack either brain cells or basic human empathy to make a connection between these events.
- diggan 1y ago> Too bad they lack either brain cells or basic human empathy to make a connection between these events. I think that's giving them too much benefits. They know what they're doing, it's clear they want "security for me, but not for you", and claiming they're too dumb to know exactly what they're doing is playing it exactly like how they want it.
- Yizahi 1y agoYeah, that the "lacking empathy part". Most of them are sociopaths and psychopaths, in the medical sense. They only want power for themselves at any cost to others.
- halfmatthalfcat 1y agoI don’t think it’s that extreme. They probably view themselves as the arbiters of society and are inherently granted more privilege than a normal citizen. Paternalistic more than sociopathic. Issue is our parents, while have the benefit of experience, don’t know shit about shit really. Especially when it comes to tech.
- labadal 1y agoI'm someone who is building a messaging app, and I make sure we subscribe to the "nothing to hide, nothing to fear" philosophy. But in our case it's collect nothing so there's no data to steal even if we get hacked.
- lubesGordi 1y ago'Heapdump' is a term I learned from debugging android applications 15 years ago. Its just a snapshot of the java processes memory. Its going to contain plaintext. Now why those heaps are available at an open http endpoint is another matter, and is the interesting point. I'm guessing the client code had that endpoint hardcoded somewhere or they saw a request to it. I'm not seeing how they could know anything about the back end or how the messages are stored from this. Did I miss something?
- trallnag 1y agoThe observability endpoints have defaults in Sprint Boot and are usually not customized. So if you know the path to the API, you also know the path to the heap dump endpoint
- JohnMakin 1y agoIt's just /actuator/heapdump and usually isn't hard to find. It's off by default in more modern versions but used to be default enabled.
- throw7 1y agoDoes TM's SGNL still work on Signal's servers? Has Signal said that they do allow Telemessage's custom signal client use on their servers?
- ianhawes 1y ago> Because the data is sensitive and full of PII, DDoSecrets is only sharing it with journalists and researchers. Sorry, but no, journalists and researchers have implicit bias.