Pull to refresh

All streams

Show first
Rating limit
Level of difficulty

Analysis of Telegram Accounts

Reading time4 min
Reach and readers492

Welcome back, dear readers! We are continuing our 'SHKH' series of articles, and today our main course is Telegram. In earlier articles, we looked at ways to find a target user's accounts by their nickname, after which we conducted reconnaissance on their account on the VKontakte social network. At this stage, our important goal is to find out the user's phone number, as the number can be a good starting point for reconnaissance and can reveal even more details about its owner. In the last article we tried to find out the number using a VKontakte page, and in this one, as you might have guessed from the title, we will try to find out as much information as possible about a Telegram account. This material has been edited and republished due to the blocking of the previous material by the RKN (Roskomnadzor) in the Russian Federation.

Disclaimer: All data provided in this article is taken from open sources. It does not call for action and is published solely for familiarization and study of the mechanisms of the technologies used.

Read more

Notes on Spammers – 2023: Non-binarity in the service of "solid" business

Level of difficultyEasy
Reading time9 min
Reach and readers382

Fig. 1: Part of the spammers' gender identity spectrum.

I rejoice when I receive spam, because it gives me an opportunity to replenish the budget of my beloved country (where the money for pensions, hospitals, schools, duck houses, and now even Counter-Strike comes from, if you know what I mean). I carefully forward every message I receive from spammers to the FAS, giving it the opportunity to replenish the budget not with a paltry 2-500 thousand rubles fine, but up to 1 million, and then I enjoy the materials of the "investigations" that shed light on the dirty underbelly of "solid business" and its non-binary accomplices. Lies, document forgery, and so on and so forth—just like last year, and before… and something else about the prosthetic paws of regulatory authorities.
Read more →

Roskomnadzor tries to block EVERYTHING, plus a red alert level at OpenAI

Reading time9 min
Reach and readers675

The most interesting finance and tech news from Russia and the world for the week: RKN blocked FaceTime, Snapchat, and Roblox, visa-free travel with China and Saudi Arabia, Russia was added to the EU's money laundering blacklist, home surveillance cameras were hacked in South Korea, Musk's Twitter was fined in Europe, and rumors of a 'garlic' model from OpenAI.

Read more

How Crazy Grannies Can Sue You for Your Apartment: The Most Complete Breakdown from a Lawyer

Level of difficultyEasy
Reading time27 min
Reach and readers351

For the past couple of months, the real estate market has been in an uproar: everyone is afraid of demonic granny-owners who seize apartments through the courts from unsuspecting buyers. In this comprehensive guide, we will break down all aspects of this problem with a professional litigation lawyer: from chilling court stories to the most reliable ways to protect yourself from such risks. In short, it's going to be fun!

Read more

A brief overview of XHTTP for VLESS: what, why, and how

Level of difficultyMedium
Reading time6 min
Reach and readers7.4K

We were asked to talk about the protocol technology XHTTP in the context of XRay, VLESS, and others. You asked for it, so here it is!

First, a bit of history. The classic use of VLESS and similar proxy protocols (including with XTLS-Reality) involves the client connecting directly to a proxy server running on some VPS. However, in many countries (including Russia), entire subnets of popular hosting providers have started to be blocked (or throttled), and in other countries, censors have begun to monitor connections to 'single' addresses with high traffic volumes. Therefore, for a long time, ideas of connecting to proxy servers through CDNs (Content Delivery Networks) have been considered and tested. Most often, the websocket transport was used for this, but this option has two major drawbacks: it has one characteristic feature (I won't specify it here to not make the RKN's job easier), and secondly, the number of CDNs that support websocket proxying is not that large, and it would be desirable to be able to proxy through those that do not.

Therefore, first in the well-known Tor project for bridges, the meek transport was invented, which allowed data to be transmitted using numerous HTTP request-response pairs, thus allowing connections to bridges (proxies) through any CDN. A little later, the same transport was implemented in the briefly resurrected V2Ray. But meek has two very significant drawbacks that stem from its operating principle: the speed is very low (in fact, we have half-duplex transmission and huge overhead from constant requests-responses), and due to the huge number of GET/POST requests every second, free CDNs can quickly kick us out, and paid ones can present a hefty bill.

Read more

A guide to bypassing 'whitelists' and setting up a chain: working options and why your VPN might not be working

Reading time4 min
Reach and readers6.6K

Hello everyone, in this article I will explain how many people manage to bypass whitelists, and what the root of the problem is. If you are a 'newbie' and don't want to bother with all the setup, at the <a href="#services"> end of the article</a> I've listed services that are mentioned in discussions.

Direct connect VLESS + Reality to Europe (Amsterdam, Germany, Finland) is being shaped for almost everyone. TSPU has mastered a new tactic: they don't terminate the session via RST, but simply 'freeze' it. As soon as the data volume in a single TCP session exceeds 15-20 KB, packets stop arriving. The connection hangs until the client times out.

Read more

Best free VPNs for PC and smartphone 2025 (that work)

Level of difficultyEasy
Reading time6 min
Reach and readers1.1K


Free VPNs.

In recent years, internet traffic filtering using TSPU has intensified in the Russian Federation. Hundreds of websites and internet services have been blacklisted and blocked. They can only be accessed via a VPN. However, the most popular VPNs have also been blocked.

The restrictions can be bypassed through a channel on your own foreign server by buying the cheapest hosting there for a couple of dollars or a ready-made VPS with a VPN installed (such ads can be found on Avito). If you don't have your own server, the only option is to use third-party VPN services that are not yet blocked. The best free VPNs among those that have survived are listed below.

Note. Habr will likely block this article for users from the Russian Federation in compliance with Roskomnadzor's ban on information about circumventing blocks, so it's best to save it immediately after publication or subscribe for updates on Telegram.
Read more →

TOP 10 Sexting Services of 2025: The Best Bots and Platforms for Intimate Chatting

Level of difficultyHard
Reading time6 min
Reach and readers2.4K

In 2025, sexting has become a real trend thanks to sexting neural networks and convenient platforms that make online intimate messaging safe and exciting. With the development of artificial intelligence, online sexting has turned into an art where everyone can enjoy virtual flirting without risk. I tested dozens of services and selected the TOP 10 bots and apps for sexting in Russian, evaluating them based on convenience, anonymity, and the quality of sexual correspondence. These sexting services offer everything: from anonymous sexting to virtual sex chat with self-destructing photos. Let's figure out which sexting chatbots and platforms are worthy of your attention and how they work.

Read more

4 ways to fix goodbyeDPI, how to restore access to YouTube

Level of difficultyMedium
Reading time3 min
Reach and readers1.4K

Lately, there has been a flood of comments that goodbyedpi is not working again, so I decided to make instructions for you on 4 working ways to restore goodbyedpi's functionality. It works differently for everyone, so test them out to see which one suits you. Write in the comments what helped you, maybe some of your own values!

Read more

How to download, install Office 2024 LTSC from the Microsoft website and activate it permanently?

Level of difficultyMedium
Reading time8 min
Reach and readers2.8K

Ten years ago, I wrote a couple of articles - How to download the latest Office from the Microsoft website without any App-V / Habr (habr.com) and How to download Microsoft Office 16 from the Microsoft website / Habr (habr.com), using the then little-known Office Deployment Tool.

Time flies. After Office 2016 came Office 2019, Office 2021, and now it's time for Office 2024. Well, let's see what has changed in terms of downloading, installing, and activating the product over the past ten years.

First, let's talk about the versions and editions of Microsoft Office. To avoid being too meticulous in the description, I'll briefly state the most important thing: over the years, the Office lineup has evolved. There are different subscriptions and update plans, new features appear in new versions, and bug fixes and patches for found vulnerabilities are released for older versions.

Microsoft has long since switched to a system of distributing Office family products through various so-called "channels," depending on how often you want to receive new features and updates.

The key difference in the current download and installation of Office from what was relevant in the days of Office 2016 is that you must determine which distribution channel you are going to use - that is, from which channel you are going to install the product itself. For those who would like to study the different distribution channels in detail, I suggest reading the original source - Office updates - Office release notes | Microsoft Learn. For the rest, I'll summarize briefly - Microsoft now prefers to sell everyone a subscription to Microsoft 365 (what was previously called Office 365), with regularly updated features under the so-called Modern Lifecycle Policy. The consumer (boxed, retail) versions of Office 2021 are also distributed under this modern policy. Office 2021, for example, is only supported until October 13, 2026. And older versions follow the so-called Fixed Lifecycle Policy, under which Office 2016 and Office 2019 are only supported until October 14, 2025. In general, they will not stop working after that date, but they will stop receiving updates. And for those of you who use email services based on Microsoft Outlook.com or Office365, and possibly Microsoft Exchange users, with updates released after October 14, 2025, it's time to think about upgrading.

Read more about installing Office 2024

Reconnaissance using Telegram bots — OSINT in Telegram

Level of difficultyEasy
Reading time4 min
Reach and readers1.3K

Greetings, dear readers! Continuing the SH article series, in this article we decided to focus in more detail on bots in Telegram, as in many cases they are no worse and more effective than common OSINT tools. The bots discussed in this article will mainly concern reconnaissance on Telegram users.

Disclaimer: All data provided in this article is taken from open sources. It does not call for action and is provided for informational purposes only, and for studying the mechanisms of the technologies used.

Read more

Reality in Whitelists

Level of difficultyMedium
Reading time8 min
Reach and readers727

In a changing network infrastructure, mobile internet users face questions: what resources remain available, and what does this look like on a technical level? This material is the result of a practical study using standard network analysis tools.

No speculation—only measurements, numbers, and technical facts.

Read more

MAX permissions for Android. Comparing with Telegram and WhatsApp*

Level of difficultyEasy
Reading time10 min
Reach and readers848

Hello everyone!

I, at my own risk, decided to install MAX and see what happens after installation. My research will result in at least 2 articles.

This is the first article. In it, I will compare the permissions requested by the MAX app for Android with the permissions requested by Telegram and WhatsApp.

Read more

Installing and Configuring Hysteria

Level of difficultyEasy
Reading time10 min
Reach and readers7.4K

This year, like many Habr visitors, I read with great interest the articles by the respected MiraclePtr, learned to apply his ideas and recommendations, and got practical experience with protocols, clients, and graphical panels. For many protocols, there are detailed installation and configuration instructions available to even the most inexperienced users who are just starting to explore the world of Linux.

I finally got around to the protocol briefly described in the article "Modern Anti-Censorship Technologies: V2Ray, XRay, XTLS, Hysteria, Cloak, and Everything Else" — the Hysteria protocol, which has already reached its second version. And I couldn't find a comprehensive Russian-language guide for it, which prompted me to gather all the information in one place once I figured out the main issues of installing and configuring the server and clients for using this protocol to bypass blocking.

Read more

Top 25 useful bots in Telegram, from planners to search engines

Reading time8 min
Reach and readers3.9K

Telegram is a messenger with a powerful API that allows you to create the most complex bots. Here you can find an assistant for any purpose: to recommend a movie, write a to-do list for the day, and even chat in English. But the problem is that there is no search for bots in TG, so even the coolest tools often go unnoticed.

My team and I have tested dozens of services and selected the most useful bots in Telegram that make life easier. At the time of this article's publication, they are all functional, and almost all of them are free.

Read more