.eval module, there's a serious vulnerability using which anyone can gain access to your account without having to do much. Nuke the userbot altogether if you don't know what I'm talking about.
How it works?
TL;DR or for the inexperienced:
An attacker may make your account do functions underhand to gain complete access to your account and lock you out, thanks to how telegram inline bots function.
Technical explanation:
Telegram inline bots can be programmed to make the user's account send anything they want, this makes the functioning of userbot vulnerable since it runs on commands inputted by the user.
The attacker can make a custom inline bot designed for the target that's predefined to run an eval code to obtain MemorySession details when the target uses it, then the attacker can use the credentials to make a session in telethon after which the attacker will have full access to the account and the victim will be locked out.
Thanks to @Hackintosh5 for discovering the vulnerability.
Make your userbot ignore messages sent via inline bots
Обсуждают сегодня