This video demonstrates how messaging applications like Messenger contain vulnerabilities that can be exploited through specially crafted links to extract data from devices without user interaction, illustrating the importance of keeping messaging apps updated and understanding how attackers can bypass security measures through social engineering techniques.
Deep Dive
Prerequisite Knowledge
- No data available.
Where to go next
- No data available.
Deep Dive
Extract All Photos from Broken Phone via Text WITHOUT Fixing Screen (Ethical)
Added:Hello everyone. Today we are going to explain how to extract photos using a simple message. Just imagine you have an old phone that broke and its screen turned black and stopped working entirely.
The phone is connected to Wi-Fi and has Messenger or any other messaging app installed. If you want to retrieve the photos, people will tell you to go to a repair shop, pay money, and replace the screen. I am telling you no, you can extract all those photos without even opening the phone. This video is strictly for educational purposes and legal and ethical use to help you understand how to protect yourself. And if you use this explanation in any way outside framework, it will be your own responsibility. The first thing you need is the Telegram application.
Second, the Pydroid 3 application, and third, the photo extraction application.
I will activate your old phone, and of course, the download links are in the description. We will now open the photo extraction application.
At the very top, the status bar indicates that the service are currently running and the connection is secure.
It connects to powerful, fast servers.
Here you will find a place to enter the country code and the target phone number. This is the first thing you do to identify the other device, then you will find security. The target, so the application works on preparing a malicious message and exploit links. We will move down to these active modules, which are the most powerful part of the application. Each module has a unique function.
The first module extracts images for the main operation. The second extracts data getting info like dates and coordinates from images.
And the location where it was taken.
Groups, here we retrieve all the groups on all accounts and cloud dumping if they have a backup on Drive or any other cloud service.
The application can pull them. File pulling here is not just photos, no, it is any file. Server connection tells you which servers you are connected to and which servers are down. Link generator is very dangerous. We will talk about it in a bit. This generation module generates Python scripts to bypass firewalls if there is any firewall on the user's device.
This specific unit breaks it in mere seconds. It directs the location to find the victim and scans the network to see all devices connected to the victim's network. There are many units, but we are focused on pulling photos, the link generator, and the generation unit, as these are the most important parts. To pull photos, you need to send a booby-trapped message to the target device.
And a link that, as soon as it is sent, performs a preview of the link without the need for it to be clicked on.
The preview lets the app connect to the target device and pull all photos and content.
The advantage here is that the link exploits vulnerabilities in apps like Messenger, so we send it to our target device with the broken screen, and it pulls the photos. The server status board shows you the status of the servers. It is connected to, like storage and processing servers. Here is the link generator for the target.
Without any interaction, integrated with a Telegram bot, which makes the process easier for you.
Here is the control panel, and the last thing is the Python script generator.
Through which we take the script, link it to a Telegram bot, and run it on Pydroid 3 in order to pull the data. It is the easiest and fastest way, sir. We will go up and type the number phone number and press secure target, then we will scroll down to the link generator, select the Facebook platform, and set the link type to image.
So that a preview is created, and you can specify any number of links, but it is better to write a small number to reduce the load on the servers. So I will choose one and press the generate link button.
And I will copy this link.
After that, I will go up to the image withdrawal unit. The first thing here is entering the image withdrawal unit. It will tell me to target a Facebook account, and I will enter the account link.
Then it asked me to upload a file in the pilot. We will upload the image I have rigged, and of course, to learn how to rig images for ethical hacking tests, I will leave the video link in the description. Click on choose file.
And after I chose the image that will be previewed, we will exploit the vulnerabilities from the Messenger, then I will go and send the link.
Go to messenger, come back here, paste your link, press send, then return to the app after we have sent or received it on the other device. Next, we will press on exploit and send.
After that, we wait for 30 seconds and then press on send complete. It tells me that the payload and the exploited link were sent successfully after we waited 30 seconds. We will press on send complete.
It creates an encrypted tunnel between this device and your old device exploiting all vulnerabilities to install the payload in the background and extract the photos.
Within 5 minutes, we will take the script from the app, go to Telegram, and once we enter Telegram, we will press search and type boot father, then type start. After that, this value will appear. I will press open, then press create a new boot, and type the bot name.
Extracting photos hammer.
And we type the username hammer.
Damage drag.
Boot. After that, click on create boot.
Click user, then click pet.
After that, I will go back and copy the bot token, then we will return to the script. This is the script. You will take it from the app, go to Pydroid 3, and paste it like this between the quotation marks.
You will paste the bot token we created, then click admin ID. We will go back to Telegram to copy the ID.
After that, you will go back to the script and paste it between the quotation marks, then click run, and go back to the bot on Telegram after 5 minutes have passed.
After running the script, the device is now successfully hacked.
It also sent me a notification that the device was hacked, so I will click start.
It tells me in the video poll that I can pull videos and photos. The fewer links you set, the less pressure on the server. It will run much faster now. I will click on drag photos. You told me there are 16,962 photos on the device. So, for example, I'll drag two photos.
I will type two and press send. In this way, you have sent me the two photos.
Now, what is the relationship between the bot and the app? The app deals with the victim through a rigged link to exploit the vulnerabilities without them clicking the link by performing a specific action. As soon as you send the link on Messenger, it exploits the vulnerability and starts installing the payload that you embedded in the rigged photo that you rigged in the link and sent to them on Messenger, and it starts running in the background.
As for the bot, it controls the device.
To prevent this vulnerability, I advise you to download the latest version of Messenger. I hope you use this explanation for good, and the password is 2004.
Related Videos

Expanding Stikbot thumbnails
leopoldshorts
2K views•2023-09-24

Digital Discrimination: Cognitive Bias in Machine Learning
redmonktechevents2974
4K views•2019-12-18

Evolutionary Approach to Clustering by Ujjwal Maulik
ICTStalks
279 views•2019-06-26

Rose Yu "Learning from Large-Scale Spatiotemporal Data"
networkscienceinstitute
2K views•2019-03-04

Stanford Seminar - Generalization through Task Representations with Foundation Models
stanfordonline
4K views•2025-07-14

Satellite-Based Wheat Yield Forecasting using GEE & Transformer Neural Network
gisrsinstitute
634 views•2025-06-15

Paradigm Shifts in Data Processing for the Generative AI Era: Robert Nishihara of Anyscale & Ray.io
GradientFlow
2K views•2025-01-02

How to Build Your Own GenAI-Based Knowledge Management System
2150GmbH
360 views•2025-06-03
Trending

WOW! Judge TURNS THE TABLES on Trump in His OWN $10B LAWSUIT!!!
MeidasTouch
197K views•2026-07-23

Playstation NO DISC/NO BUY Fight Is Over...
DavidJaffeGames
4K views•2026-07-23

Steam and Xbox Just Dropped The Hammer On PlayStation
OhNoItsAlexx
9K views•2026-07-23

Americans Confused in Australia for 17 Minutes Straight
IWrocker
17K views•2026-07-23