Hacking a Discord Server With a Link!

preview_player
Показать описание
My greatest fear has been unlocked...

Discord scams, hacks, and vulnerabilities are usually pretty scary for everyday people. But as a chronically online Discord mod, these things don't scare me anymore. I thought I saw every single Discord scam and knew how to avoid them.

But clicking on a link and having my Discord server ruined within a minute. Whether it be Carl bot sending a scam message, Dyno doing an admin giveaway, or Maki deciding that everyone gets admin, this destruction is all caused by vising a website.

So maybe, just maybe, think twice before clicking a link on Discord.

LINKS
-----------------------------------------------------------------------------
xyzeva's socials

SOCIALS
-----------------------------------------------------------------------------
Discord Server

Twitter

Music
-----------------------------------------------------------------------------

TIMESTAMPS
-----------------------------------------------------------------------------
00:00 - Click link = hacked server
00:26 - Carl bot scamming
01:35 - How the vulnerability works
03:10 - Dyno's admin giveaway
04:34 - Maki's admin for everyone!
05:50 - Happy ending :)
Рекомендации по теме
Комментарии
Автор

Developer of Carl-bot here, we fixed this as soon as we were notified about it. So this isn't possible anymore! Thanks Eva and Ntts for bringing this to our attention!

destroy_
Автор

Eva is straight-up shredding through vulnerabilities, would be nice if we had people as good as her at Discord and the teams making insecure bots.

AquaQuokka
Автор

We have patched this issue within the hour after we were notified.
This vulnerability made it possible to toggle a module, giving someone admin wasn't possible unless a server administrator manually and knowingly set a role with administror permissions as an automatic role.
Thanks you, Eva! 👍

MakiDiscord
Автор

no text to speech always makes our toes wiggle in excitement whenever a new video drops❤

DespondentFraud
Автор

As a web developper thats like the first few things you learn, how do people still make these mistakes, especially in these big bot websites

FriedMonkey
Автор

Been loving the ntts x Eva collab videos.

inkcloudss
Автор

Of course NTTS has a God role for himself in his discord server

LunarPriestessYT
Автор

Now my new ultimate goal is to build a Discord service that NTTS' new e-girl won't be able to hack.

Jokes aside, thanks to both of you for finding and pointing out these. You help making Discord a little bit better.

neofos
Автор

yo thanks for coming back! we missed u

fas_lol
Автор

i love how the editor included that one isaacwhy video where 2 people got higher roles by exploiting dyno, good reference!

MartimAlt
Автор

You need to do a video to assigning bots the minimum amount of permissions (Least privilege). I see too many bots asking for basically server admin.

kmcat
Автор

the crazy thing is the specific vulnerability that Eva has been finding arnt advanced at all. they’re quite simple actually, discord needs to fix their security

bubble
Автор

If every POST request needs a authorization token, CSRF would not work, and that's the best way to make sure 3rd party sites cannot use a API without proper authorization.

codrutx
Автор

Welcome back, hope you have a great break and happy new years everybody!

Infisrael
Автор

Can you do a video on LastFMRichPresence in Vencord plugins on how to use or activate and explain what does it do? thanks!

normalguy
Автор

XYZ Eva appearing in another vid is a good sign!

retrogamerfoxxie
Автор

Hey, i know its a off topic question, but what vpn should i use?
You are the only one I actually trust on internet topics, pls help me if possible:)

Vinicius.Cavallari
Автор

yo chat, the hangout chat social chill, still up there lesgo

Kenishura
Автор

Eva should become a security engineer instead of finding random discord bot bugs lol

bill.zhanxg
Автор

HAA! im managing ~30 servers with all automod and embeds are using Carl. I felt so annoyed lately, because carl shorten their cookies timeout which is led to re-login with Discord. But here's the annoying part, you can still access the inside of dashboard even your session end, you can refresh the page and you still inside, but once you save your changes, you'll be redirected to Carl login page, which absolutely lost the last work you've made before.

ArachmadiPutra