welcome
Wired

Wired

Technology

Technology

Here’s how a hacker hacked TeleMessage’s secure.telemessage.com

Wired
Summary
Nutrition label

58% Informative

An anonymous hacker says they hacked TeleMessage , a clone of encrypted messaging app, recently acquired by Smarsh .

The exploit that the hacker used was incredibly simple.

TeleMessage has temporarily suspended all services, which is now why WIRED can share exactly how this hack took place without risking anyone’s private data.

TeleMessage ’s archive server was running an eight-year-old version of Spring Boot , or someone had manually configured it to expose the heap dump endpoint to the public internet.

In the case of TeleMessage 's archive server, the heap dumps contained usernames, passwords, unencrypted chat logs, encryption keys, and other sensitive information.

Despite this critical vulnerability and other security issues with TeleMessage , someone in the Trump administration deployed it to Mike Waltz's phone.