Hacking With Discord Just Got Harder

Поделиться
HTML-код
  • Опубликовано: 28 сен 2024

Комментарии • 173

  • @Seytonic
    @Seytonic  10 месяцев назад +14

    Go to ground.news/seytonic to stay fully informed. Subscribe for less than $1/month or get 40% off unlimited access to take advantage of their biggest sale of the year. Sale ends November 30 :)

    • @MexieMex
      @MexieMex 10 месяцев назад

      Ground News? Seriously? It's fucking terrible! It totally biased and not at all trust worthy! Just taking them as a sponsor really puts doubt in your due diligence. I didn't unsubscribe, but I came very close.

  • @PepsiMan42069
    @PepsiMan42069 10 месяцев назад +628

    I get why discord are doing this, but I’m gonna miss having an empty discord server as my cloud provider 😅

    • @Aphex51
      @Aphex51 10 месяцев назад +128

      And I'm sad that I'm too dumb to realise this potential and I've now totally missed the party.

    • @aegis2907
      @aegis2907 10 месяцев назад +47

      I mean it sounds like it'll still be possible to do that, just that the links will expire but the file should still be there

    • @SuperElephant
      @SuperElephant 10 месяцев назад +41

      Files hosted on discord are probably still persistent, just the download link expires. So no more long term direct links but you kinda still be able to use as a file host I guess..

    • @varsityathlete9927
      @varsityathlete9927 10 месяцев назад +53

      My 85 TB rare pepe server ....

    • @KARMA.XD.
      @KARMA.XD. 10 месяцев назад +16

      ehh I used to do this but I got banned and lost access to like 100+ accounts and emails

  • @Debianz
    @Debianz 10 месяцев назад +15

    SQL injection in 2023 is absolutely ridiculous. This problem has been completely solved on the developers end using ORM or Query Builders.

  • @queerzard
    @queerzard 10 месяцев назад +17

    Imagine having a website prone to SQL Injection in 2023

  • @zephyfoxy
    @zephyfoxy 10 месяцев назад +8

    I don't know how much I buy that this change to Discord is about malware so much as it is about Discord wanting to save on bandwidth by not being treated like a file server.

  • @SlimeeosGames
    @SlimeeosGames 10 месяцев назад +19

    Actually, when someone deleted the message that contain a file or media, it disables the link after some time (a few hours or a die).
    It don't store permanent if the original message was deleted.

  • @170insane
    @170insane 10 месяцев назад +12

    I live in Maine and can verify that the state is DUMB AF regarding this ordeal.
    Their excuse for not disclosing the breach is so they could contact individuals.
    They need you to contact a hotline to find out if you're affected.
    WHY DO I NEED TO CALL IN, IF YOU HAVE MY INFO ALREADY!!!!
    Hold times are bad but it's a third party doing the customer service 🙄🙄🙄🙄🙄
    Overall, I'm not surprised having worked with the state's IT team previously.

    • @garydeluce464
      @garydeluce464 10 месяцев назад +8

      Not to mention MOVEit was patched in FUCKING JUNE

  • @Rerbun
    @Rerbun 10 месяцев назад +73

    Loved all these topics! The air tag one way communication over Bluetooth story is insane. Potentially better communication method for spies than number radios?

    • @iWhacko
      @iWhacko 10 месяцев назад +6

      as long as there are Apple devices around, it's a great way to send encrypted information yes.

    • @lowwastehighmelanin
      @lowwastehighmelanin 10 месяцев назад +9

      Yeah the mesh network is massive. Brilliant idea honestly.

    • @BillAnt
      @BillAnt 9 месяцев назад +2

      It's really stealthy since there's no cellular communication going on. It would work best in densely populated ares like large cities with lots of nearly iPhones.

  • @kaloyan.doychinov
    @kaloyan.doychinov 10 месяцев назад +44

    Sadly, what happened with discord is just another case of bad actors making the user experience worse.
    Btw, another amazing video

    • @StopTh3Idiots
      @StopTh3Idiots 10 месяцев назад

      It's not about that, Discord loves black supremacists, anti-white racist servers, where they radicalize a lot of kids, they also love hosting pedo content, they just cracked down on hackers because of the war in Insrael.

  • @trueriver1950
    @trueriver1950 10 месяцев назад +2

    Love the sign in the photo "Welcome to Maine - the way life should be".
    Perhaps not in this case...😅

  • @Damariobros
    @Damariobros 10 месяцев назад +4

    I think you should also mention that the new Discord link system doesn't affect emojis! So, non-Nitro users can be rest assured that their media links they use to insert big emojis will never expire!

  • @itsawill9268
    @itsawill9268 10 месяцев назад +7

    Using discord is like negative opsec if you are a hacker tho

    • @WindowsDaily
      @WindowsDaily 10 месяцев назад +1

      Realistically, just sign up with a vpn and throwaway email. You're only making a server with one channel anyway.

  • @cpuuk
    @cpuuk 10 месяцев назад +1

    Maine Local Gov: Oopsy, were we still using MoveIT.

  • @NorthernChimp
    @NorthernChimp 10 месяцев назад +2

    In which circumstance can a kid get access to their teacher's keyboard, unattended long enough and with a tool to neatly open and close back it's casing?!

    • @v4n1ty92
      @v4n1ty92 10 месяцев назад

      lol you can plug a keylogger into a usb port and then plug the keyboard into the keylogger. would maybe take 5 seconds, and wouldnt require opening up the keyboard at all

  • @BriannaTheGod
    @BriannaTheGod 10 месяцев назад +7

    Another banger of a video! Thanks for sharing & keeping us in the loop Seytonic!

  • @HunterHogan
    @HunterHogan 10 месяцев назад +2

    I feel like your writing and video production skills progressed from Good to Polished.

  • @InSight0r
    @InSight0r 10 месяцев назад +3

    While on topic of malicious links, recently I saw malicious link masked in a youtube redirect.
    - m-Link pasted in the description
    - video posted as private
    - copy the middle stage of the redirect between youtube and m-Site
    - redirect is still with youtube header - no detection
    Stay safe out there.

  • @lowwastehighmelanin
    @lowwastehighmelanin 10 месяцев назад +1

    My data was compromised at my doctor's because of MOVEit and so was 844999 other northern Californian's. Exhausting.

  • @AnesuC
    @AnesuC 10 месяцев назад +2

    Maybe the use of them seem rare because its soo good that barely anyone has found out. I am mostly joking but this could actually be true. Other usual methods can result in someone noticing weird behaviour on the system or network and thus catching it. But this method is outside the device and the network making it much harder to find out

  • @unitazer
    @unitazer 9 месяцев назад

    Now you can store a message link, that contains a replaceme link, that contains the malware link, you will just have to update 3 links within a day (if changing message actually does that) so discord malware will break within a day without wifi.

  • @psapple5858
    @psapple5858 10 месяцев назад +1

    cant you create a link that when clicks generates a new discord link then redirects you to that , then boom you dont have to worry about the time limit.

  • @stage6fan475
    @stage6fan475 10 месяцев назад

    The 'Hitman for hire' parody site made my morning.

  • @LumiLumiLumiLumiLumiLumiLumiL
    @LumiLumiLumiLumiLumiLumiLumiL 10 месяцев назад +10

    *Correction: Files are NOT permanently hosted.*
    They remain for a set of hours before they turn invalid
    Just like with messages, if you delete files or attachments they will be deleted from discord aswell, to preserve storage capacity.

    • @AliveOP
      @AliveOP 10 месяцев назад +1

      False... Try it out yourself

    • @nigmane
      @nigmane 10 месяцев назад

      Correct

    • @y7o4ka
      @y7o4ka 9 месяцев назад +1

      ​@@AliveOPfiles are being deleted from media servers instantly once the origin message is deleted. CDNs though can take up to a few days to remove the file from the cache

  • @abcdefxyz1239
    @abcdefxyz1239 10 месяцев назад +1

    that sucks ngl

  • @SASTSimon
    @SASTSimon 10 месяцев назад +6

    I wish discord didnt do this. I loved the infinite storage

    • @tardistrailers
      @tardistrailers 10 месяцев назад +2

      And people abusing Discord as infinite storage space is probably way more of a reason for them to introduce these restrictions than malware distribution. Storage and traffic cost them money after all and they aren't a charity.

  • @ScienceLifeChronicles
    @ScienceLifeChronicles 10 месяцев назад +1

    wow that's amazing.

  • @ΖΖΖΖΖΖΖ
    @ΖΖΖΖΖΖΖ 10 месяцев назад

    This is crazy, wtf.

  • @swift_rxz8403
    @swift_rxz8403 10 месяцев назад

    So are my mp3 files I have in discord going to disappear after the new action takes affect? Or Am I not just going to be able to download them again once sent.

  • @theraves
    @theraves 10 месяцев назад

    I assure you it won't hinder them that much...I have a bogus discord account that I purchased nitro for once or twice so if it gets stolen I have a payment trail I can use to get it back with....a few of the servers that its in have already discussed this and have ways around this discord as a company is shady and shitty in general their only doing this to try and save their pathetic asses but its not going to help it might slow things down a bit but after what I have seen others discussing this wont be nothing to them.

  • @redlexapher
    @redlexapher 10 месяцев назад

    Holy hell I only just heard about the Maine hack, note, I live in Maine

  • @OhFruits
    @OhFruits 10 месяцев назад

    discord do this mostly to cut cost from people that are hot hosting files on their database

  • @LoyaltyIsEverything91
    @LoyaltyIsEverything91 10 месяцев назад

    How about the state's NOT TRUST 3rd party proprietary software!! Closed source code is saying you trust the diligence of that company to do the work of security that open source allows billions of humans to join and help do for free.

  • @n0tzuck
    @n0tzuck 10 месяцев назад +1

    You can actually bypass it using a method (discords cdn thingy)

    • @neey3832
      @neey3832 10 месяцев назад

      could you be more specific?

    • @n0tzuck
      @n0tzuck 10 месяцев назад

      @@neey3832 Basically, Discord's API could be used to retrieve a file's attachment link. Someone could then write a script that fetches the document URL every day and updates their scam website with the URL.

    • @n0tzuck
      @n0tzuck 10 месяцев назад

      It's technically not a bypass but rather a work around

    • @mycelia_ow
      @mycelia_ow 10 месяцев назад

      @@n0tzuck How is it done?

  • @Ric3cir121
    @Ric3cir121 10 месяцев назад

    Telegram allows you to upload up to 2gb files...
    But it comes with the exception of non existing direct download links

  • @D.von.N
    @D.von.N 10 месяцев назад +2

    Must have been living under a rock, never used that platform. Neither Tiktok. And proud of it! LOL

    • @ryshellso526
      @ryshellso526 10 месяцев назад +1

      Yup, always got the feeling discord was just a place for pedophiles to trade photos.

  • @Atmatan
    @Atmatan 10 месяцев назад

    The rentahitman site is seriously old news, like decades old.
    Did you only just learn about it?

  • @antifalls
    @antifalls 10 месяцев назад

    wow nice video bro.

  • @whtiequillBj
    @whtiequillBj 10 месяцев назад

    Are the parameters extended attributes or Alternate Data Streams or forks (Linux, Windows, MacOS respectively)?

    • @byharix2542
      @byharix2542 10 месяцев назад

      it's just parameters on the url, some POST request data

    • @tardistrailers
      @tardistrailers 10 месяцев назад

      Assuming you're talking about the Discord links, it's just an HMAC with an expiration timestamp. It's also still a GET and not a POST request.

  • @zoenagy9458
    @zoenagy9458 10 месяцев назад

    so which one is a real hitman website?

  • @gamerr6638
    @gamerr6638 9 месяцев назад

    nope 0% security on discord

  • @sujanthapa1506
    @sujanthapa1506 9 месяцев назад

    informative video

  • @abhi_iam
    @abhi_iam 10 месяцев назад

    Explain about dark side of whatsapp

  • @arafatmarius331
    @arafatmarius331 10 месяцев назад

    Nice ...I wanna be like them

  • @vannyvanngogg
    @vannyvanngogg 10 месяцев назад

    in case you didn't know: "CL0P" -- sounds identical to russian word for a Bed Bug ("клоп")... just saying 🤷‍♂

  • @TechnoL33T
    @TechnoL33T 10 месяцев назад

    Can they not just use a script to keep the link updated?

    • @WindowsDaily
      @WindowsDaily 10 месяцев назад

      Probably, yes. The links themselves would expire, but every time you scroll up to the link it would have a different expiration date.

    • @tardistrailers
      @tardistrailers 10 месяцев назад +1

      They can, when the link is on a website, but not in an e-mail.

  • @lordsussyindustries2021
    @lordsussyindustries2021 10 месяцев назад

    ....

  • @Catinkss
    @Catinkss 10 месяцев назад +3

    Apple is wild, genuinely pro-privacy in one case, claiming 8GB of RAM > 16GB in another, i cant tell if they are competent or not

    • @v4n1ty92
      @v4n1ty92 10 месяцев назад +2

      Let's not get it twisted, apple is absolutely not pro-privacy and is harvesting and selling user data just like every other major tech company. You don't become a trillion dollar company just selling hardware. They sure do love having that outward appearance of being "privacy focused" though

    • @v4n1ty92
      @v4n1ty92 10 месяцев назад

      They don't block third party tracking out of the kindness of their hearts, they do it so they can have a monopoly on the data you generate on their hardware. Apple is not privacy focused and you've been duped if you think they are 🤷‍♂

  • @CrittingOut
    @CrittingOut 10 месяцев назад

    These goofy mfs still out here trying to buy hitmen

  • @MexieMex
    @MexieMex 10 месяцев назад

    Ground News? Seriously? It's fucking terrible! It totally biased and not at all trust worthy! Just taking them as a sponsor really puts doubt in your due diligence. I didn't unsubscribe, but I came very close.

  • @immameme
    @immameme 10 месяцев назад

    HackNewsAndImma1st

  • @nekrosis4431
    @nekrosis4431 10 месяцев назад +84

    Imagine you create a goofy parody site, but you overestimated the intelligence of murderers and now you are on first name basis with the local FBI agents.
    Comedy Gold.

    • @BillAnt
      @BillAnt 9 месяцев назад +1

      Wonder how the site owner didn't get arrested to begin with. Even though it's a parody, the 3-letter-boys don't have a good sense of humor. lol

    • @kuva
      @kuva 5 месяцев назад

      @@BillAnt its not entrapment if its a private citizen doing it! they'd be dumb to arrest the site owner.

  • @jayaif
    @jayaif 10 месяцев назад +43

    Making an encrypted messaging app that uses Apple's find my network would be a much more interesting use case

    • @emireri2387
      @emireri2387 9 месяцев назад

      this would be actually kinda similar to hacknet in a way

  • @jmr
    @jmr 10 месяцев назад +9

    Every time Hire a hitman catches someone I think "surely this is the last one". We know these people have Google. 😂

  • @peconi47
    @peconi47 10 месяцев назад +7

    the rent a hit man site was made as a bug fixing group for programming, after people actually started requesting hitmen, they changed the site to the one that it is now

  • @Deductive
    @Deductive 10 месяцев назад +3

    Sollution? Setup a dynamic redirect link and have a Discord Bot or Crawler that simply renews the download source.

    • @shadamethyst1258
      @shadamethyst1258 10 месяцев назад

      That's a known workaround, but it makes using it as a CDN more difficult, why should be enough to ward off low-effort attacks

  • @lightbrownwolf
    @lightbrownwolf 10 месяцев назад +28

    Guilded (a discord alternative) also does direct file links, and they are less file size restrictive.

    • @StopTh3Idiots
      @StopTh3Idiots 10 месяцев назад

      Does it allow black supremacist anti-white servers and pedo servers like discord ?

    • @user-beerus
      @user-beerus 10 месяцев назад +9

      Who uses guilded

    • @trapido0296
      @trapido0296 10 месяцев назад

      @@user-beerus me

    • @dsobransingh
      @dsobransingh 10 месяцев назад +6

      ​@@user-beerusyou don't need a guilded account to use the direct download link, so the number of people who use it is completely irrelevant

    • @vincere_
      @vincere_ 10 месяцев назад +2

      It's owned by Roblox however

  • @Pr0toPoTaT0
    @Pr0toPoTaT0 10 месяцев назад +3

    I had my first discord server actually stolen from me with a crafty mod who sent me a weird bot link. Discord is actually crazy with just the flexibility it allows

  • @ground_news
    @ground_news 10 месяцев назад +3

    Thank you, Seytonic! Happy to be supporting your work. For anyone interested, check out the link above and let us know if you have any questions.

    • @johnchristian7788
      @johnchristian7788 10 месяцев назад

      Ask him to pin your comment. So, it will be easier for people to connect with you.

  • @atomiapx
    @atomiapx 10 месяцев назад +1

    I'm trying to watch this and just got done watching an ad and immediately another ad played and as of typing this I'm watching another ad

  • @GimmeZoomies
    @GimmeZoomies 10 месяцев назад +1

    Files do actually get deleted off discord even if you have the link, maybe not regular files but images do get deleted.

  • @SuperTort0ise
    @SuperTort0ise 10 месяцев назад +1

    2:10 fuuuuuuck definitely not in that 0.2% hahah

  • @BriannaTheGod
    @BriannaTheGod 10 месяцев назад +2

    I love you daddy Seytonic ❤️

  • @Jcorella
    @Jcorella 10 месяцев назад

    0:24 this is wrong. If you delete the original message with the attachment, it will expire after an indeterminate amount of time.

  • @Ixspar
    @Ixspar 10 месяцев назад +2

    This actually happened about 6 months ago. Not sure why there weren't articles about it when people could have actually done something about it. But here we are. (Meanwhile, up at the Maine Capitol: Janet: "Timmy, make sure you get those security chickens set before your Pa gets home." ...s....m....f.....h.

  • @mattjax16
    @mattjax16 10 месяцев назад +5

    I love being a maine resident and you are the first time I have heard of this data breach

    • @tatherva7387
      @tatherva7387 10 месяцев назад +2

      Aaaaayup. Also I busted out laughing when he said "unlimited resources" regarding the state. Maybe in NY or California but Maine? Nah 😂

  • @astral6749
    @astral6749 10 месяцев назад +1

    I'm not sure if I'm just having deja vu, but I feel like I've heard that exploit (or maybe it was a different exploit) on MOVEit long ago.

  • @al-gv7mq
    @al-gv7mq 10 месяцев назад +8

    It seems quite complicated considering they could create a redirect webserver which will automatically update the link and redirect you to the discord download :3

    • @tardistrailers
      @tardistrailers 10 месяцев назад +8

      You'd lose the benefit of the good URL reputation from Discord though. Also implementing an HMAC requirement to download links isn't really that complicated.

  • @GiantAndShaman
    @GiantAndShaman 10 месяцев назад +1

    Honestly good on the hitman site owner for contacting the fbi instead of laughing off "jasmine". Some random woman out there could be dead by now if jasmine pursued other means.

  • @x1cOfficial
    @x1cOfficial 10 месяцев назад +1

    hello from australia!

  • @koghs
    @koghs 10 месяцев назад +1

    Damn, Apple users getting railed by their own devices again.

  • @ReligionAndMaterialismDebunked
    @ReligionAndMaterialismDebunked 10 месяцев назад

    Indeed broken grammar. XD

  • @PepsiMaxVanilla
    @PepsiMaxVanilla 10 месяцев назад

    rip

  • @DennisFranz
    @DennisFranz 10 месяцев назад

    Rent-A-Hitman, can I place a hit on the waiter that keeps giving me a paper straw? I mean, dayum! Leave three. I can't even stir my ice tea and lemonade without the straw bending or disintegrating.

  • @angw3l
    @angw3l 10 месяцев назад

    what if we strip the link from those parameters

  • @sarahjuraan
    @sarahjuraan 10 месяцев назад

    Hello World 👋

  • @mu11668B
    @mu11668B 10 месяцев назад +8

    Discord should've done that at least a year ago. For some reasons I have to deal with infection source quite often, and Discord has been on the top of the malware hosting list. I even made a post over a year ago complaining about the issue and how easy it is to them to fix it, only to meet some unpaid muggles trying to defend Discord for funny reasons. Finally they have chose to do the right move.

    • @YT7mc
      @YT7mc 10 месяцев назад +1

      What was your easy fix?

    • @mu11668B
      @mu11668B 10 месяцев назад

      @@YT7mc Add the same authentication check already applied to chatroom messages to CDN entries. Just like the solution they're going to push but simpler.

    • @YT7mc
      @YT7mc 10 месяцев назад

      @@mu11668B Yep that makes sense; wonder why they aren't doing this.

  • @teckcity5721
    @teckcity5721 10 месяцев назад

    A UI is responsible for the hacks

  • @duckydev9427
    @duckydev9427 10 месяцев назад

    Inb4 the method is to call a local server that constructs a valid extension on the url

  • @themetapodmemes2789
    @themetapodmemes2789 10 месяцев назад

    Why does discord directly embed a ttl in the link? Wouldn't that be pretty easy to forge?

  • @beatsbycf
    @beatsbycf 10 месяцев назад

    How did a whole state get hacked

  • @razorgaming3.0
    @razorgaming3.0 10 месяцев назад

    42th 1 hour ago

  • @ioawhdiouwahduwioahwauio
    @ioawhdiouwahduwioahwauio 10 месяцев назад

    hi

  • @aymanazad1443
    @aymanazad1443 10 месяцев назад

    e

  • @blakexe
    @blakexe 10 месяцев назад +8

    The first part of the numbers in discord cdn links is the server / DM “channel” id which is really bad for hackers because discord publicly lets you view info about a server just from having it’s id.
    On top of that even if the server or the message got deleted discord still logs who made the server and who sent messages in it. They started logging ALL messages ever since their new anti trust policy was implemented back during covid :/

    • @neey3832
      @neey3832 10 месяцев назад +2

      as i've searched, only discord servers with widget enabled allow people to publicly see info about their server

    • @blakexe
      @blakexe 10 месяцев назад

      @@neey3832 That is true. Though being snowflakes they can still be somewhat useful in supplying the time the server or channel or message was created

  • @b3njamin602
    @b3njamin602 10 месяцев назад +1

    nice! this should make discord more secure!

  • @Chrromeetalk
    @Chrromeetalk 10 месяцев назад +3

    Who thinks this is a good Discord update?
    👇

  • @lewiskelly14
    @lewiskelly14 10 месяцев назад

    Misleading title

  • @MeboMichael
    @MeboMichael 10 месяцев назад +1

    We love you @seytonic

  • @tostupidforname
    @tostupidforname 10 месяцев назад

    How cool is the airtag thing