Here is how you can disclose your IP Address with Whatsapp Link Preview feature , a short demo using Grabify.

Anish M
2 min readMay 2, 2021

--

Note: This content is strictly for educational use only , misusing this knowledge can land you in trouble.

I recently came across an article on medium by Rahul Kankrale about Whatsapp user’s IP disclosure from Whatsapp’s Link Preview feature . The article was quite interesting , it meant that if a Whatsapp user copy pasted a website URL on his/her message box and Whatsapp generated a preview of the URL , it would expose Whatsapp user’s IP address to the website even without the user clicking the URL.

That article was quite technical and demonstrating it to non technical student community was a pain, I also wanted to test if it works in 2021 without complex technical setup. So after lots of trial and error I selected Grabify service for this purpose and got interesting results such as Whatsapp version , Location , ISP and IP Address by simply copy pasting the tracking URL in my Whatsapp Android App and waiting for it to generate a link preview.

I have used a VPN to hide my IP Address and geolocation . In the above dashboard i had to hide few columns for privacy reasons .

So here i am going to explain how i did it so that people can verify it for themselves.

STEP 1: visit https://grabify.link/

STEP 2: Enter any website url in grabify and create a grabify URL. This URL is capable of tracking users.

STEP 3: Simply copy paste the grabify URL in Whatsapp message box and wait till a preview is generated.

STEP 4: In grabify Dashboard you will find Whatsapp IP address , Version , Country and ISP used by the Whatsapp User who pasted the grabify URL in his Whatsapp messagebox.

Currently there is no way to disable link previews in Whatsapp So avoid copy pasting unknown links in Whatsapp chatbox . Share this article to spread awareness and stay safe!

Originally published at https://outflaw.blogspot.com on October 18, 2020

--

--