These Bot Commands can Raid your Discord Server!

preview_player
Показать описание
If you own or moderate a Discord server, you 100% have a bot on it. Whether it be for moderation, like Carlbot or Dyno, or for fun, like Dank Memer.

But with each of those bots (and many more), there are commands that raiders can use to do some naughty stuff. Bypass your automod, check. Bypass embed perms and spam unsavory images, check. Ping everyone? I gotta check.

So it's in your best interest to double check all your commands and ensure that no one can bypass your moderation systems in place that keep your server safe.

(Also you can bypass Discords automod for the Assyst bot by just inputting in a javascript string and concatenating it)

LINKS
-----------------------------------------------------------------------------
Top Discord Bots

SOCIALS
-----------------------------------------------------------------------------
Discord Server

Twitter

TIMESTAMPS
-----------------------------------------------------------------------------
00:00 - 1. Tags
02:11 - 2. AFK
03:11 - 3. Reminders
05:49 - Bonus Command
06:19 - What to Do?
Рекомендации по теме
Комментарии
Автор

It's important to note, for a lot of things these bots DO NOT need administrator permission, it requires extra work because you will have to more manually set em up, but you can control via permissions what the bot is and isn't allowed to do.
I saw setup like that on a server that had owner's personal channels, Dyno was not given admin rights to not be in those channels.

Jenner_IIC
Автор

Btw, mentions don't work because the developers of the bots can disable mention by sending enabled_mentions to the Discord API, so even if the bot pings @everyone it won't mention anyone because "everyone" wasn't included in the allowed mentions, same thing for roles and users

Antogamer
Автор

ah yes now I know how to raid my server! with zero people on because I have no friends! 😍

inampersands
Автор

Fut fact : an @everyone exploit was found in Koya. It had a hanger game and when you tried a letter or a word it would repeat it. Someone did this in the koya server and pinged all of the tens of thousands ppl here, it was really funny seeing the chat being flooded like that.

hurlemort_
Автор

I am going to understand none of this but I will watch, enjoy, and stay until the end just to experience the love I haven't felt since my youth

Louhands
Автор

(5:20) Don't give bots admin rights
You have said it yourself. This is harmful. The developers might slip up. The bot might be hijacked. Only give necessary permissions.

Liggliluff
Автор

I know someone who used webhooks to mirror an ingame chat on a game he made into the discord. He did not sanitize for pings, and webhooks always have ping permissions.

TheChaosCorvid
Автор

"wait a sec you goddamn impatient little" bro has officially entered Disney villain arc

HeisenbergFam
Автор

Going to now use these methods to irritate the biggest servers I can!.

Yeah I'm suprised you're only bringing this up now, it's been around for ages and won't lie it was always funny to me. Great video though!.

linny
Автор

Let's go new raid tutorial! Thanks it will be so useful ❤

optifire
Автор

I didn't block staff pings on my server as I have only about 400 members and I think people should ping us if something happens or so. Also, I manually changed permissions of my bots. None of them has admin or manage server perms. I use blargbot for moderation purposes, this bot isn't very popular but it's awesome and it comes with a great templating engine for tags and custom commands. I turned off the tag command for normal users, same for most of the commands, and custom commands are server-wide staff-managed so it doesn't matter here.

toslaw
Автор

I like how NTTS LITERALLY tells people how to hack people, scam people, raid servers and THEN SAYS "discord needs better security"

Drbyss
Автор

These videos serve to convince me that I absolutely do not want to own a discord server. Thanks NTTS!

kittyloveluvkitty
Автор

The legend says that tags in moderation bots will soon become so advanced that discord users will be able to kill the whole humanity of Discord using AI

codeguy
Автор

The actually good thing in this is that a while back you could spam invite links with the tag / remindme command, but now they removed the possibility to add invite links.

Tovaritch
Автор

I kinda miss those normal commands that you actually have to put on chat for most bots, I still prefer the slash commands but there is something with it that idk... nostalgia ig

mauron
Автор

Yet another reason for rejecting general-purpose bots and rolling your own custom bot with just what you want/need.

pfqniet
Автор

Plot twist, NTTSs editor is NTTS and he's bashing himself in this meta comentary.

danser_theplayer
Автор

the integrations menu is the best way to manage your slash commands by far, it's discord built in and you can choose what role, channel the command is available to.
and not having to go to any website

ArtByAhri
Автор

This video actually made Site-32, Asgard and Noctum aka some SCP discord servers which got raided by this

I_RefuseTo