dgongut/docker-controller-bot

Ban @GroupAnonymousBot from TELEGRAM_ADMIN

Closed this issue · 1 comments

image

If spoken to from a group via an "invisible" administrator, the userID of the speaking user is not that of the REAL administrator. It is actually that of @GroupAnonymousBot. It can lead to confusion and someone can put the userid 1087968824 as TELEGRAM_ADMIN which is incredibly dangerous.

This would open the door for anyone to add your bot to a group and control your server.

TLDR: DON'T PUT 1087968824 AS TELEGRAM_ADMIN

Solved in v2.3.3