Telegram still leaks your real IP address to contacts

Carding 4 Carders

Professional
Messages
2,729
Reaction score
1,521
Points
113
Experts say that the popular Telegram messenger continues to merge users IP addresses. To exploit this loophole, a conditional attacker just needs to add to the victim's contacts and force them to accept an incoming call.

Denis Simonov, a cybersecurity researcher also known by the online pseudonym n0a, spoke about the possible IP address leak.

Moreover, Simonov even wrote a special tool that demonstrates the exploitation of a gap in Telegram. The publication TechCrunch was able to confirm the existence of the problem: journalists added Simonov to the contact list of the new account and accepted an incoming call from him.

As a result, n0a provided TechCrunch employees with their real IP address immediately after the call. It is strange that the developers of the messenger, given its user base, did not eliminate this flaw, because earlier experts have already raised the issue of security of Telegram users.

The reason for "draining" the IP address is in the default settings of the messenger: it opens a P2P connection between the interlocutors "for better communication quality".

To protect yourself from this, you can find the item "Calls" in the privacy and security settings and put "Never" in the "Peer-to-Peer" section.

92a20b6251.jpeg
 
Top