Тёмный

Discord Screwed Up… Badly 

No Text To Speech
Подписаться 810 тыс.
Просмотров 485 тыс.
50% 1

What happens when you forget to follow the most fundamental thing about building a website? Well you get creative NFT and crypto scammers abusing Discord's incompetence to create the ultimate way to get your Discord account stolen. If you visit a specific page on Discord's website, you instantly get your account stolen. No clicking on phishy (pun intended) links or downloading an exe file. You visit the discord page and it's already over.
What a completely laughable and preventable event that occurred. Thanks Discord 👎
LINKS
-----------------------------------------------------------------------------
Server Forge Overview
/ 1603515845195472902
JustCC's ELI5 + upsetness
/ 1603337868428152834
Vice banger article
www.vice.com/en/article/wnjwb...
SOCIALS
-----------------------------------------------------------------------------
Discord Server
/ discord
TIMESTAMPS
-----------------------------------------------------------------------------
00:00 - The scam
01:24 - Explanation
06:04 - Why this is unforgivable

Наука

Опубликовано:

 

15 июн 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 946   
@Doctorgeo7
@Doctorgeo7 Год назад
Wow... This is a school grade level exploit. Anyone who paid attention to basic website security knows how to prevent this attack. And yet Discord's dev team is so incompetent that it couldn't even prevent something this basic.
@0.r0
@0.r0 Год назад
discords dev team is 12 year olds what want the badge
@pseudoscientist8010
@pseudoscientist8010 Год назад
So why it this action not considered as in purpose? If so much money is being stolen, then a kickback is obvious.
@DawaBvv
@DawaBvv Год назад
@@0.r0 who wants
@bitrare7
@bitrare7 Год назад
@@0.r0 You seem like you're 12 with that spelling. Discord devs work at discord for money not a badge? And you have to be over 18 to actaully work at discord.
@bitrare7
@bitrare7 Год назад
Bros the developer police 😭 the devs have hundreds of things to do they aren't able to check every little thing
@jackdavenport5011
@jackdavenport5011 Год назад
The crazy thing is that React (which Discord is built with) literally has XSS protection built into it, meaning the developers had to deliberately go out of their way to make this exploit possible.
@Choroalp
@Choroalp Год назад
Discord is made with electron
@hovac.
@hovac. Год назад
@@Choroalp youre dumb
@Choroalp
@Choroalp Год назад
@@hovac. yes i am(and how do fuck you managed to find me)( some people saying itami might be backdoored)
@rice8864
@rice8864 Год назад
@@Choroalp electron is the desktop framework, react is the frontend framework which discord is built with
@tabiasgeehuman
@tabiasgeehuman Год назад
@@Choroalp electron is just repackaged chrome and nodejs. You can use any framework with it, including react, which is what discord does
@lior_haddad
@lior_haddad Год назад
They use React and still got an XSS issue?! That's honestly unforgivable.
@jojo989GD
@jojo989GD Год назад
lmaao
@jackdavenport5011
@jackdavenport5011 Год назад
Lmao someone just likes using dangerouslySetInnerHTML
@rednexie
@rednexie Год назад
@@jackdavenport5011 lmao they should just change it to innertext and its gone
@adrianozuna875
@adrianozuna875 Год назад
Do they even code review at this point
@adrianozuna875
@adrianozuna875 Год назад
@x41ih10a You're right lmaoo
@rvs570
@rvs570 Год назад
Why don't we create a script that generates tokens and sends them to all known token saving sites? Fill up their databases and have them be less effective
@rvs570
@rvs570 Год назад
Actually, I found my goal for today xD
@polaris2707
@polaris2707 Год назад
Safer to send junk and not actual tokens. Provided they don't have checking it'll still work and doesn't carry the risk of accidentally sending a legit token.
@jsh722
@jsh722 Год назад
well there is a chance you can generate a legit token
@rvs570
@rvs570 Год назад
@@polaris2707 Yea, would probably make sure to add or remove some random part to it to be safe
@rick-sanchez
@rick-sanchez Год назад
Exactly my thought. You just need to put it trough a service that sends it from different IP addresses first or they can filter it easily.
@GamerShyUncut
@GamerShyUncut Год назад
Fun fact. Changing your password doesn't always work. I actually once got hacked on Discord, and instantly changed my password the moment I knew what had happened. Before the scammer even had a chance to do it themselves. They still got control of my account. Next level tomfoolery indeed.
@NotAFanMan88
@NotAFanMan88 Год назад
In token stealing exploits, you may have to explicitly invalidate all your login sessions, which discord does allow you to do. Changing passwords doesn't necessary invalidate all existing login session tokens, though if discord had any sense they should.
@theseangle
@theseangle Год назад
They probably just send an automatic POST request to change the password to the discord server upon receiving the token immediately. Most likely that's why you don't have time to change your password in time
@Brabbs
@Brabbs Год назад
God, the absolute leveling that this guy does is addicting. This guy feels like one of those parents that would go: "Yeah, school sucks, heres why it sucks-"
@migs388
@migs388 Год назад
Facts
@hellokittyiesss
@hellokittyiesss Год назад
Nah it's true tho
@satgurs
@satgurs Год назад
is is
@MaahirMomtaz12
@MaahirMomtaz12 Год назад
This seems to be a monthly thing now. Just don't click links. Simple
@rebane2001
@rebane2001 Год назад
XSS vulnerabilities like this one are very rare.
@stryrok4216
@stryrok4216 Год назад
I dont know if I should say this but I literally saw/knew a guy who said he can just token grab people by just giving a invite link and that was over a year ago ,just how many people have known about it before this vid almost scary
@AANyt
@AANyt Год назад
i mean, this link is looking safe. So the only possibility is, to not use the internet at all or don't use services like discord (what ever this means)
@SurmenianSoldier
@SurmenianSoldier Год назад
@@AANyt or just don't be dumb and have like 3000 layers of protection ezez
@tzarg
@tzarg Год назад
@@SurmenianSoldier or don't be dumb and click on whatever unsuspecting tinyurl links you see pop up
@tairitsu5560
@tairitsu5560 Год назад
I've heard Twitter had a self-retwitting script that works just like this, but that was several years ago. Can't believe this still happens
@Coder_Tavi
@Coder_Tavi Год назад
ru-vid.com/video/%D0%B2%D0%B8%D0%B4%D0%B5%D0%BE-zv0kZKC6GAM.html
@Knaeckebrotsaege
@Knaeckebrotsaege Год назад
@@Coder_Tavi links get censored by YT (only the poster can see it, nobody else), which might explain why it's showing "2 replies" yet only one shows up
@Archimedes.5000
@Archimedes.5000 Год назад
It was TweetDeck not Twitter as far as I know
@sluuuudge
@sluuuudge Год назад
I’m honestly astounded that in 2022, Discord of all companies managed to accidentally create an XSS exploit.
@DMack6464
@DMack6464 Год назад
Well Google had one, so why stop the incompetence there?
@testuser1235
@testuser1235 Год назад
Bro u clearly know nothing. 1. They didnt create an XSS Exploit, a person which found the vulnerability created the exploit 2. Even in Google, Nvidia, Apple etc. are xss, and even more dangerous vulnerabilities (like ssrf, or with that RCE) found (daily), so pls dont just talk shit about discord, when u clearly know nothing about this topic. Look at for example Hackerone and see how many reports are daily submitted and resolved.
@sluuuudge
@sluuuudge Год назад
@@testuser1235 I ain't your "bro", either way you're still incorrect. Discord developed the application therefore they created the exploitable surface. Perhaps I didn't make that part of my comment clear. I'm not sure why you're white knighting Discord as if they're gonna give you a job for defending them...
@testuser1235
@testuser1235 Год назад
@@sluuuudge nah, im Not defending them, but I just can‘t stand people who think, Discord is the only Company who has vulnerabilities like that.
@un1que730
@un1que730 Год назад
@@testuser1235 discord is the one company getting fame astoundingly fast ,with mass comes critics
@Sluip69
@Sluip69 Год назад
NTTS is a youtuber I actually like to watch nowadays, even tho its about subjects I don't even know much about or affects me
@ItzStardustYT
@ItzStardustYT Год назад
@@stavratum 💀
@izzyxvibes
@izzyxvibes Год назад
@@stavratum if u don’t care then why’d you respond
@Sluip69
@Sluip69 Год назад
@@izzyxvibes cause he is a fan
@KhAnTlol
@KhAnTlol Год назад
@@stavratum we don't care that you don't care
@inspektor66
@inspektor66 Год назад
@@stavratum you seem like an angsty teenager with a "p" addiction.
@zephyrprime8
@zephyrprime8 Год назад
Discord try not to create a security vulnerability with every new feature challenge (impossible)
@debargha0_0
@debargha0_0 Год назад
Looks like $800K wasn't that much for Discord, they should be again fined
@ItzStardustYT
@ItzStardustYT Год назад
Discord messed up??!?! No way! Impossible!
@Prouf1
@Prouf1 Год назад
-_-
@ezioboiz-ieatchildren-
@ezioboiz-ieatchildren- Год назад
Who could have guessed???
@joelhoon1707
@joelhoon1707 Год назад
This is the first time this has happened in so long, I forgot Discord ever messed up!!!!!
@k.silverpoint
@k.silverpoint Год назад
This is as good as a reminder to everyone to SANITIZE YOUR INPUTS.
@QUASAR098
@QUASAR098 Год назад
xkcd reference
@JaivianDean
@JaivianDean Год назад
@Jimmeh make inputs(what they user types in a text box) basically only work for the purpose you give them, no funky business, lol
@mousepotatoliteratureclub
@mousepotatoliteratureclub Год назад
@@QUASAR098 Happy holidays to Bobby Tables
@williamdrum9899
@williamdrum9899 Год назад
@@jimmydabear Design your website so that if the user types in computer code instead of a password their code doesn't get run.
@maskettaman1488
@maskettaman1488 Год назад
This has nothing to do with input sanitation lmao
@Willie-2024
@Willie-2024 Год назад
Someone, please make this man a Discord Mod. He does figure out more than discord itself.. Hats off man. Love from India
@clouderino
@clouderino Год назад
NO OH GOD PLEASE DONT MAKE HIM A DISCORD MOD I DONT WANT TO BE HIS KITTEN
@neanni
@neanni Год назад
​@@clouderinospooky
@itsarian.
@itsarian. Год назад
WHY ARE INDIAN PEOPLE EVERYWHERE LITERALLY EVERY COMMENT I SEE IT SAYS "LOVE FROM INDIA" AT THE END
@justaweeb14688
@justaweeb14688 Год назад
@@itsarian. because they had too many kids
@justaweeb14688
@justaweeb14688 Год назад
Why tf you insulting him for? Why do you want him to be a discord mod?
@nclsDesign
@nclsDesign Год назад
The only vulnerability that's more unforgivable than XSS is SQL injections... That this happened to a big company like Discord is even worse...
@cenniebeanie
@cenniebeanie Год назад
there should be (again) in the title 😂
@TomJ211
@TomJ211 Год назад
Lol
@uhKilz
@uhKilz Год назад
I appreciate you making these videos. I love waiting to get into a MW2 match and watching discords biggest mistakes.
@jn567
@jn567 Год назад
MW2?
@Likemea
@Likemea Год назад
@@jn567 Modern Warfare 2
@uhKilz
@uhKilz Год назад
@@jn567 jc isn’t really a gamer if he doesn’t know what modern warfare 2 is
@ezioboiz-ieatchildren-
@ezioboiz-ieatchildren- Год назад
@@uhKilz facts, he's probably 9 years old and plays Minecraft.
@MrFilgueiras.
@MrFilgueiras. Год назад
Following this logic, the next exploit is gonna be "someone accidentaly typed 'DROP DATABASE discord' oops"
@williamdrum9899
@williamdrum9899 Год назад
Or used "gets(password)"
@SamuelLing
@SamuelLing Год назад
IIRC they use nosql database, it would be impossible for that to happen, but xss, yea, those are different
@SupaMC_Gaming
@SupaMC_Gaming Год назад
Thank you for bringing this to light. You’re one of my favorite RU-vidrs
@SavageMudkip
@SavageMudkip Год назад
damn bro thats crazy, they only did a minor felony this time?
@shidosensei.
@shidosensei. Год назад
Thanks for letting us know man, I hope you stay safe out there
@trollify2851
@trollify2851 Год назад
Thank you for sharing this important information about the Discord NFT scam link. Your video is helping to educate and protect the community. Keep up the good work in raising awareness about these types of threats
@iFurore
@iFurore Год назад
I'm happy that I never fell for this scam because I got a lot of these DMs but I just ignored them.
@tristanrhodes2789
@tristanrhodes2789 Год назад
i accidentally fell for one before like a month ago XD now im worried
@IllagerCaptain
@IllagerCaptain Год назад
@@tristanrhodes2789 change your password if you haven't already.
@tristanrhodes2789
@tristanrhodes2789 Год назад
@@IllagerCaptain Yeah i did but that isnt the issue they have my account token not my password XD
@Trigger4589
@Trigger4589 Год назад
NTTS, you covered this so well! * I don't feel sorry for the idiots that have a lot of money I guess.
@ShadowOcto
@ShadowOcto Год назад
They’re NFT bros, don’t 💀
@Testing123-Ore7
@Testing123-Ore7 Год назад
What the guy above me said
@apyr1055
@apyr1055 Год назад
What the guy above the guy above me said
@MemezuiiSangkanskje
@MemezuiiSangkanskje Год назад
What the guy above the guy above the guy above me said
@DaniZeAlmighty
@DaniZeAlmighty Год назад
What the guy above the guy above the guy above the guy above me said
@Awesome_Aasim
@Awesome_Aasim Год назад
A few years ago a security researcher found an XSS vulnerability in TweetDeck and used it to make the only self retweeting tweet.
@wolfypro
@wolfypro Год назад
Your videos are getting better & better! I follow you since you had 50k subs. Great job!!
@timedeos4320
@timedeos4320 Год назад
I found someone that’s been doing this to get people’s tokens and selling their tokens since the QR code scam, I’ve always thought this was possible but never had a sample to work with like you did, good job man!
@ciach0_
@ciach0_ Год назад
Thank you NTTS for a birthday gift that is this video
@Bockanator
@Bockanator Год назад
my face when discord's website is vulnerable to the simplest Cross site scripting imaginable.
@frostdesigns555
@frostdesigns555 Год назад
As someone that is still learning web development, this stuff kinda scares me. My knowledge on network security as well as vulnerability detection is not that much yet.
@RyanTheTechMan
@RyanTheTechMan Год назад
Hey, I have been watching for a long while, and I only now just realized that I was never subscribed! Your videos have always been recommended to me :)
@Respectable_Username
@Respectable_Username Год назад
This is why you gotta set your CSP headers. Even if somebody messed up the actual code itself, a good CSP will stop it from actually doing any harm!
@Naleksuh
@Naleksuh Год назад
I'm pretty sure the reason they were embedding the script off RU-vid was because of the CSP. So no, CSP would not have stopped it
@_kzr
@_kzr Год назад
i’m genuinely surprised this was overlooked, literally no validation checks or encoding on the html to make sure that scrips aren’t being executed.. it’s unsurprising coming from discord though
@_kzr
@_kzr Год назад
@@zydn it’s discord 😂 they always find a way to make something worse
@NicoPlyley
@NicoPlyley Год назад
@@zydn Yes that’s true when using JSX. But this exploit was done through the state management software. When someone loads the page it get exploited before the page even renders out html. If it was in the JSX it would have been sanitized
@hi-kt3qr
@hi-kt3qr Год назад
@@zydn React takes some steps to protect against simple xss attacks and html input vector rendering. displaying script tags, for instance, or other things. The exploit in this case is trickier than you might expect because it only guards against DOM-based XSS assaults, although XSS comes in a variety of forms. Having said that, data sanitization might have easily avoided this.
@yuvalne
@yuvalne Год назад
man, the last time I saw such a major and easy xss vulnerability was xss in tweetdeck 8 years ago. and that was just a self-retweeting tweet. such incompetence.
@NiftRex
@NiftRex Год назад
This happened to me. I got offered to be paid to "test" a service or something similar and be invited to a server. I just simply ignored those DMs. They were persistent and would try one or two more times, I still never clicked on them.
@Leep226
@Leep226 Год назад
Fantastic video to inform us all about it but to be honest if you just stick to the rule of never clicking on any links before asking around or anything is the safest way to go Do not let your curiosity or greed get the better of you as those are usually how you fall for any scams Always ask yourself what could happen or simply why do I have to click on something someone sent me in dm which I have never spoken to before. Always have a certain level of distrust as come on this is the internet unless you know them personally irl you should always that certain level of awareness as anything could happen such as even your best friend on internet for years could turn on you for personal benefits
@0xNe
@0xNe Год назад
Im gonna sleep very well tonight knowing that NFT are losing money again
@user-ku9vx6uj4o
@user-ku9vx6uj4o Год назад
And probably you are using NFTs in products without even knowing. But yeah, be stupid. And no, NFTs aren't JPG's.
@0xNe
@0xNe Год назад
@@user-ku9vx6uj4o AHAHAHAHAHAHAHAHAHAH
@user-ku9vx6uj4o
@user-ku9vx6uj4o Год назад
@@0xNe NFTs are used in cars from Alfa Romeo for example. NFTs are for metadata storage, and yeah, a lot of people (mostly scammers) use it to store a link to a image to sell it. But NFTs aren't images or something. This metadata can be anything and can be used for a lot of things (car maintenance info, keys to your car, event tickets, subscriptions, in-game characters or items, login info etc).
@0xNe
@0xNe Год назад
@@user-ku9vx6uj4o no shit, wheres ur prev comment? and where did i ask what are nfts? i know what they are, and I, in fact, know that people who bought into nfts are dumbest people in existence and most of them lost money, so every time they lose again, its a good news
@0xNe
@0xNe Год назад
@@user-ku9vx6uj4o ye i dont see yours too i only see the one from 1hour ago, others are only on notifs, we will argue some other day since theres no point if we cant see comments, have a nice day sir
@PinkManGuy
@PinkManGuy Год назад
A friend of mine lost his account to this. Luckily we were able to recover it, but it was scary for a while there.
@ms.awesome
@ms.awesome Год назад
i remember when tweetdeck had a xss self retweeting tweet a long time ago. How so many people don't see this issue with their websites is crazy to me
@comet.x
@comet.x Год назад
i didn't even know what this was called but as soon as i saw the html i knew exactly what was going on. like no way did they let you just write html in a text description like that
@williamdrum9899
@williamdrum9899 Год назад
That's like a fox guarding the henhouse
@darthvader8744
@darthvader8744 Год назад
The moment I hear "This was against NFT groups" I immediately agree with the exploiters
@Dude29
@Dude29 Год назад
Spectacular analysis. Thank you!
@BeastGamingHD
@BeastGamingHD Год назад
I think what's crazy is that people are just now figuring out about this exploit which has actually been around for nearly 2 years now. Also most of the people hijacking accounts are focusing on people with og or "leets" for username and account age so that they can keep it and or sell it. A "leet" would be a username like root#0001 for example.
@Knaeckebrotsaege
@Knaeckebrotsaege Год назад
brainfart: could people theoretically spam the blueh and/or hawkemedia links with fake/random tokens via scripts to throw some sand in their gearbox? obviously not all from the same IP so it's not as easy for them to filter out. they'd have to figure out if the tokens they collected are actually valid, and i guess would be kinda pissed if 99% aren't lol 🤔
@twilighttales-
@twilighttales- Год назад
That cherry server really went through a lot of pain mainly thier owner🤣🤣🤣
@twilighttales-
@twilighttales- Год назад
Abee 👁 👁 😂 👄
@jalkarna
@jalkarna Год назад
@@twilighttales-kya bol raha hai bhai
@nanopi
@nanopi Год назад
I've been using that new string type quite a bit lately. It's very useful.
@NoMerCyNL
@NoMerCyNL Год назад
Thanks for the information, Shared in my discord server
@Vlame
@Vlame Год назад
To be honest, I'm not even suprised anymore that Discord has another exploit. If they fix one, someone will find another one 😅
@Dyanosis
@Dyanosis Год назад
This shows how little testing they have. If they'd had more testing, especially for such a simple webpage, this would have never made it to live. Xss is very simple to prevent and, as many people have posted many times before, is very simple to escape a user's input. Apparently Discord doesn't know/follow the "never trust user input" rule. Also, with Discord being as big as it is, you'd think they'd do vulnerability testing that would have told them about this problem long before it got out of dev.
@williamdrum9899
@williamdrum9899 Год назад
"Surprise penetration testing"
@TS_Mind_Swept
@TS_Mind_Swept Год назад
This is why you don't click links. Even if it's from someone you think you know, try to engage them in a conversation (esp if you haven't heard from them in a minute); if they talk different than normal, you know
@xyhasanamazingalt9583
@xyhasanamazingalt9583 Год назад
it’s insane discord never patched this, i literally used it in 5th grade to mess with my friends on websites they made
@Sopitive
@Sopitive Год назад
It is possible to do a lot of input sanitization, CORS policy changes and CSP changes to circumvent a lot of XSS, but in the end you probably won't get everything. Hackers will reverse a site and try to find a bypass to the filter you set in place. It isn't necessarily Discord's fault because it took hackers this long to discover it. It just goes to show that nothing you do as a security researcher and engineer will truly patch a vulnerability fully, but instead just makes it harder for a hacker to exploit it. Discord does have a bug bounty, but if crypto scams will yield more money than the reward money from the bug bounty, it makes more sense for hackers to exploit it rather than responsibly disclosing it.
@JaivianDean
@JaivianDean Год назад
this is a new feature that just came out with discord that got XSS'ed
@Sopitive
@Sopitive Год назад
@@JaivianDean Even then, reflected XSS is one of the least serious types of XSS. If it were to have been stored XSS, we would have had a huge problem (worse than this one). This still required a little social engineering and user interaction to pull off. Though that kinda makes sense, they should have probably checked for something like that before they pushed an update.
@blenderbachcgi
@blenderbachcgi Год назад
Like I said, the only way to stop this, is to deal with the hackers one on one. Trying to patch up a broken wall, to hide from them, is only delaying the inevitable, because they will ALWAYS find you. Sadly, everyone chooses to literally allow them to do these things.
@SamuelLing
@SamuelLing Год назад
@@Sopitive or just be smart, don’t click on those links, if you want do it in a incognito mode or a vm (though, this is not really practical)
@Jazztache
@Jazztache Год назад
This is why it's a good idea to use Element instead, Discord just keeps on getting these weird instabilities.
@C00L3R
@C00L3R Год назад
that's for companies... just use guilded if you really dislike discord (i don't use guilded it sux)
@Jazztache
@Jazztache Год назад
@@C00L3R Not really. It's like saying Slack is *just* for companies. The only companies on Element in my vicinity is the company of the lads. Also, with Guilded... Roblox Corporation. Enough said. Plus, it's free (libre) and open source, which should be the norm for communications/chat apps.
@ImDuck42
@ImDuck42 Год назад
That with the worm is talked about with interview on darknet diarys
@AdianAntilles
@AdianAntilles Год назад
What one could do in case of these dead ends mentioned in the video, it is always possible to look where the servers are hosted and what they are doing with them. ping, traceroute and nmap are your friends.
@Madison1676
@Madison1676 Год назад
Keep slaying no text to speech
@andistive
@andistive Год назад
SLAY QUEEN 💅💅💅💅💅💅💅💅💅💅
@corn738
@corn738 Год назад
I really hope you get to be a discord mod. You do more than the discord staff at this point. PLEASE LET ME BE YOUR KITTEN 😳😳😳
@vilact0
@vilact0 Год назад
what the hell
@williamdrum9899
@williamdrum9899 Год назад
Took me a minute to get that reference
@1ch0r41
@1ch0r41 Год назад
I was around the hacking space when this vulnerability was found. My friend tested it on me and we thought it was a cool little gimmick but nothing worth using against anyone except enemies. That was 6 years ago I believe, if it’s really been this long and they haven’t patched it, that’s extremely sad. Honestly a low level exploit as well.
@natec1
@natec1 Год назад
That’s really really bad. The fact that this is even a possibility in this day and age is insane
@blenderbachcgi
@blenderbachcgi Год назад
It wouldn't have been a thing in this day and age if we'd gotten rid of the hackers a long time ago. But we don't. We just keep gluing a cracked wall together with raisins and mud hoping that someone can't just bust it down and get to you.
@fractal6929
@fractal6929 Год назад
these security exploits are really making guilded look like a feasible option
@luviana_
@luviana_ Год назад
Guilded is owned by Roblox. Don't move to an equally trash platform. Pick something open source, like Element or Signal
@rtzgf67games7
@rtzgf67games7 Год назад
I can't believe that discord forgot about it! It's legit on the OWASP top 10 web app vulnerabilities. A lot of these big companies forget about web app security 101 and it's sad.
@maskettaman1488
@maskettaman1488 Год назад
They outsource things like frontend to their diversity-hire tokens or to overseas workers entirely. Many major companies do it. It's why websites like RU-vid and Discord are getting progressively worse and worse from an interface perspective
@d1g1t4l_bl00d
@d1g1t4l_bl00d Год назад
really cool video! can you tell me what explorer do you use? or what theme do you use to make it look that way? i been trying to find a cool browser and yours is really cool.
@StolenJoker84
@StolenJoker84 Год назад
I actually had my Discord account stolen a while ago - after signing into what I thought was a Discord page. They changed my password (which is how I learned that the account was hijacked). They deleted everything, logged my account into a bunch of random servers, then game my account back. When I contacted Discord, they told me that it was impossible for my account to have been stolen. After I got my account back (no help from Discord on this front, since they insisted that it wasn’t even possible), I asked them if they could tell me where my account was accessed from. I never got a reply back from them. I found out on my own, using Discords own tools, what countries (yes, more than one) my account had been accessed from between the time it was stolen and the time it was “returned”.
@MightyDantheman
@MightyDantheman Год назад
This is why I stay logged out in my browsers
@beyem6377
@beyem6377 Год назад
So glad I've been sick the last few days
@Dolphin002
@Dolphin002 Год назад
Even I, someone who makes tiny Github websites with no actual security risks, patch XSS. How did Discord forget?
@fcantil
@fcantil Год назад
that's crazy. well on the slightly bright side, at least it's fixed now...
@qbcd
@qbcd Год назад
You can use burp suite to check what it is doing in detail
@mu11668B
@mu11668B Год назад
Whoa! Some classic XSS just became a 0-day on Discord. How unexpected! 😂
@sumoddball
@sumoddball Год назад
Where's my "I love you bye bye!" 😭best part of your videos.
@Wirby.
@Wirby. Год назад
Funny how I got a discord ad at the start
@lorics7322
@lorics7322 Год назад
Wich Browser are you using? It Looks so cool with the rounded edges
@gentoolinuxuser4387
@gentoolinuxuser4387 Год назад
You should really look into being a security researcher, great work!
@Naleksuh
@Naleksuh Год назад
No Text To Speech should or the person who found it should? All they did was read the work of others so I don't see why a parrot should be a security researcher
@mat_name_whatever
@mat_name_whatever Год назад
It's stupid that Discord did that, but it is also astounding that redux put the vulnerable code on their website, with only a comment in the snippet saying "hey check this link for security issues", instead of including the two function calls that make it safe. And then I wonder why Discord server side renders/ templates it in there in the first place, js can access the query param itself... Truthfully as a developer I have to say that unfortunately I have had many less than competent colleagues, and combined with pressure and negligence from management that has lead to very similar and worse issues a number of times. These issues don't come out of nowhere.
@spazmcat3853
@spazmcat3853 Год назад
When i saw the video title i thought: yeah do they actual do good things instead of hurting its users and platform like i have never seen that discord does something good
@siomek101
@siomek101 Год назад
"Discord messed up server discovery" - i already thought about xss
@masterdementer
@masterdementer Год назад
Your discord token will automatically change within 6-8 hours I think or maybe 12. It doesn't stay the same forever. They can send automated requests using that. But they can't change your password or access the full discord account. Unless they know the Server ID, Channel ID in which they want to send the message in. So they would have that info probably of only one server in which you were with the guy that sent you the link.
@ulize.
@ulize. Год назад
Two wrongs in this message. Firstly, the Discord token does not expire until you change your password or change two-factor authentication settings. Secondly, you are able to access the full account, it's very simple to log into an account using the token. Don't spread false security tips, it helps no one
@rufust33333333333333
@rufust33333333333333 Год назад
I’m amazed this could happen
@Kitalula
@Kitalula Год назад
I'm wondering if that's what happened to me yesterday or something new, cuz someone else was on my account for a bit, but instead of sending links they went into a vc as me and yelled slurs.
@SWinxyTheCat
@SWinxyTheCat Год назад
Does Discord not have a blue team? It sounds like they don't from the presence of these scams and exploits.
@bruisedbug
@bruisedbug Год назад
im not a security engineer or anything, but didnt this exact same thing happen with Flash? Like this is one of the most simplest things to avoid.
@alex59292
@alex59292 Год назад
Yes xss is literally thought in schools, that's how basic it is to do
@JaMaMaa1
@JaMaMaa1 Год назад
What did you do to your firefox to make it look like that? the coloration of boxes and lines around the tabs to be specific.
@SpidermanArda
@SpidermanArda Год назад
He explained that a few videos earlier. İ don't remember which video was it
@thelegendaryorb5745
@thelegendaryorb5745 Год назад
You can group tabs together
@JaMaMaa1
@JaMaMaa1 Год назад
@@thelegendaryorb5745 Maybe in 2016... because they absolutely do not do that.
@MikeyD594
@MikeyD594 Год назад
There was a similar /script exploit on twitter a few years back, it wasn't malicious but it easily could have been All it did was as soon as a tweet was loaded, it would automatically make you retweet the heart emoji and anyone who loaded that tweet would also do it
@NeuralSensei
@NeuralSensei Год назад
I was planning to use discord login built into opera gx to use alt account from the main program, but this seems like such a big security flaw now
@rickytheraccoon6102
@rickytheraccoon6102 Год назад
Sucks that it happened, but at least it was a bunch of crypto nerds and not actual human beings
@williamdrum9899
@williamdrum9899 Год назад
That's a bit harsh. I don't even do crypto
@Noob-gx6yf
@Noob-gx6yf Год назад
Another day, another scammer heist. On Discord ofcourse!
@sctjkc01
@sctjkc01 Год назад
Stealing a Discord token is incredibly bad. If you lose the token and the recipient has any sort of scripting set up, you can expect to have the entire account stolen inside of 30 seconds. I'd fallen for a phish where I was asked to test a game distributed over Itch. It stole my Discord token from my Discord desktop client, logged me out, and closed the client. And despite having 2FA on my account, I was unable to log back in again, as the token thief managed to strip 2FA AND change the password AND change the email address on it. Without any sort of request for 2FA tokens from my phone or passwords. I'd asked Discord support over Twitter for assistance, and they'd reverted the email address back to mine... but presumably the token never got reset or the token stealer was still running on my machine, because it was stolen and yanked away from me yet again. And yes, I was a paying Nitro user with saved payment information. Thankfully, because I paid via PayPal, I was able to tell PayPal to never send any money toward Discord and saved myself ~US$150 of fraudulent purchases.
@thecwd8919
@thecwd8919 Год назад
I like how they're just using a default nginx forbiden page like "damn this is so easy we dont even need to make it look like its not a scam!"
@decayedargon6765
@decayedargon6765 Год назад
Sometimes, it's the implementation of XSS prevention which is vulnerable. There was evidence of existing XSS prevention in the audit that was made. Don't flame them too hard.
@Aquilz.
@Aquilz. Год назад
the light mod thumbnail BRUHHH
@SomeKittyCat
@SomeKittyCat Год назад
are those coloured tab groups a chrome plugin on is that a build in feature of chrome?
@Mikasks
@Mikasks Год назад
The junior developer who wrote that: oops.. 👀
@mikeberger6035
@mikeberger6035 Год назад
This is why sensitive information is better saved in cookies instead of in session. This info isn't accessible by scripts if you are using HTTP-only cookies
@PatrykLastowski
@PatrykLastowski Год назад
I'm sorry but I really like the "I spy a scam" etc. buttons where your tabs are, is it like a chrome extension or something?
@pieflower6419
@pieflower6419 Год назад
That's chrome tab groups, a new feature in chrome. You can start them up at any time by right clicking on tabs, making groups and dragging other tabs into groups.
@user-tr2dh4xx6u
@user-tr2dh4xx6u Год назад
Wow I was wondering all the warnings saying not to click links lmao
@mstieferman
@mstieferman Год назад
Why does the outro always catch me off guard?
@sephstar-offical
@sephstar-offical Год назад
the thing is, how are you supposed to know theirs a volubility in something intill it gets found?
@jadelily18
@jadelily18 Год назад
i feel so bad for the people who had their accounts stolen but holy fuck is that funny lmao. It's such an easy thing to fix and I don't know how it's ever a thing in 2022
@spythere
@spythere Год назад
Wait, they hold the session token in the local storage? Did they made this with some random ass tutorial on the internet?
Далее
This is NOT going Well… Linux Gaming Challenge Pt.2
14:45
Investigating the Discord Exploit that Leaks Your IP!
18:32
Best ASMR 😳
00:26
Просмотров 16 тыс.
13 Карт - Клоны в супе | 3 серия
11:12
Top.gg Won't Like This...
10:53
Просмотров 299 тыс.
A Discord Moderator's Worst Nightmare...
8:27
Просмотров 421 тыс.
Steam Scammers on Discord are Insane!
14:35
Просмотров 765 тыс.
Genshin Impact Forced Discord To DOXX Someone!
8:53
Просмотров 305 тыс.
Scambaiting Fake Discord Support!
9:35
Просмотров 419 тыс.
This Discord Message is Not what you think it is.
8:49
Nerdy Privacy-Focused Discord Alternatives!
24:01
Просмотров 326 тыс.
Why You Shouldn't Nest Your Code
8:30
Просмотров 2,6 млн
Please Don't Download This... (Wubuntu)
20:58
Просмотров 608 тыс.
ПОКУПКА ТЕЛЕФОНА С АВИТО?🤭
1:00
Holographic transparent flexible LED panel.
0:20
Просмотров 3,3 млн
✅ЛУЧШИЕ фишки iOS 18🔥
0:51
Просмотров 105 тыс.