Discord's Dyno Verification Bookmark Scam!

แชร์
ฝัง
  • เผยแพร่เมื่อ 7 ก.ย. 2024

ความคิดเห็น • 560

  • @NoTextToSpeech
    @NoTextToSpeech  ปีที่แล้ว +478

    IF YOU GOT SCAMMED BY THIS, PLEASE READ ME :)
    1. Before changing your password, delete the scam bookmark.
    2. Then once you do that, change your password.

    • @mineblox667
      @mineblox667 ปีที่แล้ว +5

      Best one.

    • @Iceice69420
      @Iceice69420 ปีที่แล้ว +13

      @@elderlean7876 Changing password means changing the account token code

    • @infinyer2323
      @infinyer2323 ปีที่แล้ว +13

      3. Remember 1 and 2.

    • @VeryCuul
      @VeryCuul ปีที่แล้ว

      Change your password first.

    • @ufmatt001
      @ufmatt001 ปีที่แล้ว

      Use a js decompiler

  • @maxmoors
    @maxmoors ปีที่แล้ว +654

    I'm honestly surprised that people are managing to do this. Most people that try to verify in a server can't even follow instructions to verify by clicking an emoji or copy paste a certain command

    • @funl
      @funl ปีที่แล้ว +84

      i swear everyone in the server could change their name to READ PINS and you would still get people who dont know what to do

    • @sigilkoree
      @sigilkoree ปีที่แล้ว +9

      Welcome to Discord

    • @itsTyrion
      @itsTyrion ปีที่แล้ว +33

      ikr? On my MC server, people kept struggling with the verification/discord linking. it literally says in-game "click *here* to get your code" (here being red and underlined), it's written into your chat to copy paste into Discord. nope, too difficult. some people are dumb.

    • @k1ss_1ce
      @k1ss_1ce ปีที่แล้ว +4

      @@itsTyrion frrr

    • @creeper_triste
      @creeper_triste ปีที่แล้ว +1

      YES

  • @Sung.Jin-WooAmv
    @Sung.Jin-WooAmv ปีที่แล้ว +238

    Discord has become such a mess with those scam issues man..

    • @thundurr
      @thundurr ปีที่แล้ว

      Literally every single large platform has, TH-cam, Twitter and Instagram all have so many scams. On TH-cam i think it's the worst

    • @stars227
      @stars227 ปีที่แล้ว +26

      Because their employees are entirely incompetent. Discord support is almost non existant, and when you do get a reply it's some half assed copy pasted crap.

    • @Lephiz
      @Lephiz ปีที่แล้ว

      @@stars227 then be on alert and don't click on random links.. discord can't do anything if you are the dumb person

    • @Ethorbit
      @Ethorbit ปีที่แล้ว +18

      @@stars227 Yep, exactly. And the only features they work on are the ones people aren't asking for.
      I had full access to my account, but needed them to change my email address because it was no longer accessible, and they told me to create a new Discord account. Their support is useless.

    • @k4rimaa
      @k4rimaa ปีที่แล้ว +1

      I dont know what discord employees you guys are emailing, but back when i got hacked they replied back in two days and disabled the 2-factor authentication the hacker set up on both of my accounts (yes i got hacked on 2 accounts. Im a bit stupid)

  • @saai4life
    @saai4life ปีที่แล้ว +305

    anyone remember that time where bots would DM people invite links to 'weird' servers? I found it really creepy when it happened to me.

    • @MusculosoDigital
      @MusculosoDigital ปีที่แล้ว +8

      same, one day it even sent me a jumpscare with a scam link

    • @JilanAHmed
      @JilanAHmed ปีที่แล้ว +4

      happens daily

    • @Furetto126
      @Furetto126 ปีที่แล้ว +49

      @@retroaspectgaming you don't really need to be a programmer to know how to change passwords lol

    • @nanacue
      @nanacue ปีที่แล้ว +4

      had one, it was a weird server and jumpscared me and hacked my server, stole my token and lost my 1 year nitro

    • @ras.51
      @ras.51 ปีที่แล้ว +6

      @@retroaspectgaming coder? thats not the correct word

  • @darklviper3179
    @darklviper3179 ปีที่แล้ว +44

    Its hilarious when you realize how far people go just to get your information

    • @groove7854
      @groove7854 ปีที่แล้ว +3

      This is just basic phising wym

    • @darklviper3179
      @darklviper3179 ปีที่แล้ว +1

      @@groove7854 maybe basic for you , not for people who don't know what the bookmark can do with them especially for older people or kids

    • @somedudeonyoutubefrfr
      @somedudeonyoutubefrfr ปีที่แล้ว

      @@darklviper3179 Still basic, wdym... If people fall for it, then they maybe should stop using the internet...

  • @WolvericCatkin
    @WolvericCatkin ปีที่แล้ว +93

    Also of note: _Reauthorise YAGPDB if you have it..._ it doesn't actually make use of the *Join Servers for you* permission, and it's been removed from its default scope for a while now... 😅

    • @parknich081
      @parknich081 ปีที่แล้ว +1

      thanak you, underrated cfomment

    • @sigilkoree
      @sigilkoree ปีที่แล้ว +2

      thvenj yuo so muhc

    • @Krakyy
      @Krakyy ปีที่แล้ว

      thksnkd you smchu br sti oggmegltgu

    • @vedamaharaj
      @vedamaharaj ปีที่แล้ว

      bro if it doesn’t actually use the scope where the issue?

    • @Krakyy
      @Krakyy ปีที่แล้ว +1

      @@vedamaharaj hmm thats weird thism an caln spell

  • @Ketsui.
    @Ketsui. ปีที่แล้ว +15

    Lmao the "wrong tab" was some outta nowhere humor I wasn't expecting

  • @ShiloBuff
    @ShiloBuff ปีที่แล้ว +13

    HAHA love your "wrong tab". Thanks for the laugh. Also thanks for making people aware of scams.

    • @ShiloBuff
      @ShiloBuff ปีที่แล้ว

      @DDD9216A HAHA! I didn't notice because I skimmed the video. Now I see it. Have a good day!

  • @Zooiest
    @Zooiest ปีที่แล้ว +56

    I deobfed and reverse-engineered the script, and here's what I found:
    - The JSFuck portion of the code evaluates to "fortniteamongustycoonlol" (from a base-64 decode.)
    - The RE protection is more clever than one might think; the globals array is mutated until a specific alignment is reached.
    - The script registers its own module into Discord to access other modules.
    - The script can detect said module if the code has already been run.
    - jesus fuck it was annoying to reverse-engineer

    • @drm.himself
      @drm.himself ปีที่แล้ว +4

      very interesting, thanks Patrik Käpyaho

    • @ulysses847
      @ulysses847 ปีที่แล้ว +2

      thanks Patrik Käpyaho for this information

    • @mlgdoge12343
      @mlgdoge12343 ปีที่แล้ว +3

      Fortnite among us tycoon

    • @firstsurname8931
      @firstsurname8931 ปีที่แล้ว

      what is "Re protection"

    • @Zooiest
      @Zooiest ปีที่แล้ว +2

      @@firstsurname8931 protection against (r)everse (e)ngineering

  • @KudaXD
    @KudaXD ปีที่แล้ว +9

    That "Wrong tab" part killed me bro 🤣

  • @BuuyaXDev
    @BuuyaXDev ปีที่แล้ว +27

    can you teach us how to talk to girls though, its gonna be your biggest video yet

  • @real1cytv
    @real1cytv ปีที่แล้ว +27

    They really used JSFuck to obfuscate the code xD

  • @mr.slappii513
    @mr.slappii513 ปีที่แล้ว +2

    So basically. A basic feature on most browser rats them out? That's kinda cool. Imagine being a hacker/scammer and you got ratted out by a simple function like hovering over a bookmark.

  • @Fryte
    @Fryte ปีที่แล้ว +54

    4:35 yes it is possible actually, honestly it's very likely to happen considering fact you won't even realize what thing added you to some weird server
    BUT that's very much all they can do by authorizing you to their app (again, only by authorizing you, of course they can do everything when they have your token)

  • @That_0ne_Dev
    @That_0ne_Dev ปีที่แล้ว +114

    Discord seriously need to up their security and scrap account tokens altogether

    • @kellymountain
      @kellymountain ปีที่แล้ว +18

      tokens are kinda the only good option though, sure you could store an encrypted email and password but there's not much of a difference

    • @ZeldagigafanMatthew
      @ZeldagigafanMatthew ปีที่แล้ว +48

      I think the tokens are fine, but only if they are wholly unique per device. If the same token shows up on two devices, the system should immediately deauthorize it.

    • @mallusrgreat
      @mallusrgreat ปีที่แล้ว +9

      @@ZeldagigafanMatthew NO. I use Discord on multiple devices and it would be a huge problem for me to log in everytime.

    • @chocolateimage
      @chocolateimage ปีที่แล้ว +7

      I think tokens are like session id's, It needs tokens because else it doesn't know what user you are currently logged in.

    • @evangaming7447
      @evangaming7447 ปีที่แล้ว +7

      @@mallusrgreat thats not what they mean its per device so each device has a different token and if one is stolen off one device you would then have to relog in because the token was stolen on that device.

  • @mc-mc2645
    @mc-mc2645 ปีที่แล้ว +6

    I think they WOULD want your account. Seems like you have so very valuable information on how to get a girlfriend. Those scammers will need it to actually get a girlfriend.

    • @BenCos2018
      @BenCos2018 ปีที่แล้ว

      LOL
      one of the best comments I've seen

  • @Nullifys
    @Nullifys ปีที่แล้ว +6

    I gotta send this to my friends, thanks for letting this be known!

  • @tbuk8350
    @tbuk8350 ปีที่แล้ว +1

    This scam exploits the fact that if you put "javascript: (code here)" into a URL bar in a browser, it executes the code on the current website.
    You can try it here on TH-cam, actually! Try copying: "javascript: alert('Hello, World')" into your browser bar (without the double quotes). It'll create an alert popup.
    Now, where am I going with this? A bookmark is basically just a hyperlink embedded in a bar in your browser. If you click on the bookmark, it'll bring you to whatever page you bookmarked, just like a link. The catch is, that also means if you put JavaScript in a bookmark, it does the equivalent of putting the JavaScript in your URL bar (There are intentional versions of this, called bookmarklets. They can be useful, though they aren't malicious, they're basically just advanced JavaScript macros). Additionally, the JavaScript in the URL bar can access all of your local client data, due to JavaScript giving any other script running on the page access to the scope.
    So, how do you protect against this? There are two main options:
    1. Don't add/open any bookmarks you didn't create yourself, or you haven't checked over to make sure it's safe. As I've said, not all JavaScript bookmarks are bad, but they often can be, so be cautious and check bookmarks you didn't create.
    2. Don't use a Chromium browser. I'm not sure I know of any Chromium-based browsers that aren't vulnerable to this, as they all support running JavaScript in the URL bar for some reason (You shouldn't use Google Chrome anyways (has Google trackers embedded in the browser, terrible performance) or Opera (purchased by a chinese consortium and contains injected spyware), Edge is fine for now).
    I highly recommend using Firefox as your primary browser, no matter what, as it's more performant that Chromium, blocks these sorts of attacks, prevents trackers from following you on the web, and doesn't track you itself. You'll be much safer on the web using it.
    Edit:
    Oh yeah, forgot to mention, these attacks can also be injected in hyperlinks or buttons. This is why sites typically don't let you manually create them, and if they do, they filter them. You can set a button's "onclick=" to JavaScript, just like how you would in a browser bar, and you can set a hyperlink's source to JavaScript, and it will do the same. If sites let you create hyperlinks manually, you could quite literally steal people's usernames and passwords with nothing more than a hyperlink.

  • @BowDown097
    @BowDown097 ปีที่แล้ว +22

    It's incredibly stupid that JavaScript bookmarks are still a thing. They're pretty much completely obsoleted by extensions and pose a huge security risk.

    • @czebosak
      @czebosak ปีที่แล้ว +3

      @@kxi remove them entirely

    • @czebosak
      @czebosak ปีที่แล้ว +1

      I didn't even know that they existed

    • @filo1819
      @filo1819 ปีที่แล้ว

      @@kxi ​ not discord, your internet browser

    • @pfqniet
      @pfqniet ปีที่แล้ว +3

      I use JavaScript bookmarks for automation tasks, but then again I'm a nerd who uses JavaScript for automation... Just like every tool, they have a use, and just like sledgehammers they can be misused to devastating effect.

    • @ilmansalt
      @ilmansalt ปีที่แล้ว +2

      I use them, but browsers should really have an option to disable or enable JavaScript bookmarklets, and it should be disabled by default.

  • @johnthemannn
    @johnthemannn ปีที่แล้ว +4

    Another thing you should do if you get hacked is to check your Devices settings menu and delete everything.

  • @iangreen180
    @iangreen180 ปีที่แล้ว

    I didn't go through with it, but I searched for the suspiciously dangerous "verification" method from the supposed MEE6 bot and found it described here on your video. Thanks. When Discord server admins have their Discord token stolen it's "hell to pay" in their community as admins get kicked from their own server!

    • @generalidea2897
      @generalidea2897 ปีที่แล้ว

      Sometimes secrets are kept by projects on Discord in "private" channels, that can be exposed if an admin has their Discord token "hacked"!

  • @maciejkag2735
    @maciejkag2735 ปีที่แล้ว

    bro, im actually impressed by people making these scams, like they are using such crazy but simple methods to scam you really legitimately.

  • @_purple_44_
    @_purple_44_ ปีที่แล้ว

    Being a verified bot developer i know for fact that bots cant send messages or make you join servers!
    Dont click on sussy links (make sure the dashboard links do belong to the bot , the domain of the url should be accessible by some command)
    Thats it.

  • @yodaluca23
    @yodaluca23 ปีที่แล้ว +2

    yea using bookmarklets to inject JS into the console is a pretty smart tactic for people who are not tech-inclined...

  • @light3466
    @light3466 ปีที่แล้ว +2

    That "How to get a girlfriend" tab got me hard 😭

  • @trev647
    @trev647 ปีที่แล้ว +3

    "how to get a girlfriend"

  • @LerpCat
    @LerpCat ปีที่แล้ว +1

    “How to get a girlfriend” made me laugh so hard

  • @boigd7995
    @boigd7995 ปีที่แล้ว +1

    “What to do if you fell for this Sam” lol😂

  • @mer6266
    @mer6266 ปีที่แล้ว +1

    I thought dyno is a very safe bot so i press into the link and do everything it ask. Thanks for posting this video to let me know that its a scam. I've always wondering why there is new server when I turn on my laptop.

  • @jumanshandillya
    @jumanshandillya ปีที่แล้ว +3

    This guy is the best on 2022 who make legit make sense and good discord video keep the good work, best wishes.

  • @Patrik2166
    @Patrik2166 ปีที่แล้ว +2

    Thank you! Shared it already with my members :D

  • @Svn_
    @Svn_ ปีที่แล้ว +4

    how much you wanna bet NTTS cleared all the sussy bookmarks for this video

  • @pjok
    @pjok ปีที่แล้ว +1

    If people are dumb enough to let this happen to them in 2022, they deserve having their account compromised.

  • @neuzie
    @neuzie ปีที่แล้ว +3

    “how to get a girlfriend” “wrong- wrong tab”

    • @RobloxNerd_YT
      @RobloxNerd_YT ปีที่แล้ว

      💀

    • @ChiDaFox
      @ChiDaFox 28 วันที่ผ่านมา

      To add on that he wrote a script so that you can talk to girls

  • @yigitsalar
    @yigitsalar ปีที่แล้ว +1

    scam website: to enable your bookmark bar press (CTRL+SHIFT+B)
    me enters this website on phone: how?

  • @NotJaden.
    @NotJaden. ปีที่แล้ว +3

    One of the sections has a mistype in it. It says ‘sam’ instead of ‘scam’

    • @Bumble._.Jellybottom
      @Bumble._.Jellybottom ปีที่แล้ว

      CRYSTAL AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA

  • @SheepieAnimations
    @SheepieAnimations ปีที่แล้ว

    thank you for covering this, its been happening to me, i turn on my phone and im in a rando server ive never heard of, but i didnt do the bookmark thing, but thanks to you, i fixed it

  • @johnsonsaji6557
    @johnsonsaji6557 ปีที่แล้ว

    Even though it is for bad use, this method of gaining your Discord Token is actually impressive - can't believe this could exist.

  • @Scott170c
    @Scott170c ปีที่แล้ว +1

    These executable bookmarks are called bookmarklets. It can also have some helpful uses and can bypass your school admin 0-0

    • @chri-k
      @chri-k ปีที่แล้ว

      what do you mean by “bypass your school admin”

    • @Scott170c
      @Scott170c ปีที่แล้ว +1

      @@chri-k normally my school wouldn't allow my chromebook to use the inspect element. By using a bookmarklet I could use it and return the output using an alert.

    • @chri-k
      @chri-k ปีที่แล้ว

      @@Scott170c why in the world did they block the developer tools

  • @MrKneeBeeYT
    @MrKneeBeeYT 6 หลายเดือนก่อน

    the fact that people actually believe a BOOKMARK is a legit way to verify.

  • @ceecide
    @ceecide ปีที่แล้ว +3

    why does chrome have the feature to run javascript from a bookmark? seems dangerous to tech-illterate people, does it have any actual use cases?

    • @Zooiest
      @Zooiest ปีที่แล้ว

      It does! I have a few bookmarklets for things like special static URLs (such as Wikipedia's /wiki/Special:Random), utility functions (such as evaluating code quickly/on mobile, bypassing some adblockers, or loading an external script), etc.

    • @lifinale
      @lifinale ปีที่แล้ว +1

      not only chrome, any browser can run Javascript from a bookmark. Mozilla has a whole guide on how to use them. It’s a unique way to replicate extensions without having to publish your extension to the web

  • @breberton
    @breberton ปีที่แล้ว +11

    Discord needs to fix these scam issues one way or another. If they don't do it soon I don't see it going well for Discord in the future.
    or alternatively, people can just use their brains :P

    • @realgrenja
      @realgrenja ปีที่แล้ว +1

      And move to Guilded, probably

    • @taureon_
      @taureon_ ปีที่แล้ว

      @@realgrenja "move to guilded" isnt a problem solver as they could just make it work on both apps

    • @amongsussyballs
      @amongsussyballs ปีที่แล้ว

      guess we are all moving to matrix then

    • @somedudeonyoutubefrfr
      @somedudeonyoutubefrfr ปีที่แล้ว

      @@amongsussyballs We are already in one, we don't need another /s

  • @void6670
    @void6670 ปีที่แล้ว

    I remember this from "how to get your discord token in mobile" is basically the same bookmark scam

  • @ninethetwotailedfox
    @ninethetwotailedfox ปีที่แล้ว

    We're all talking about that, but what's more dangerous is trying to find a girlfriend on google.

  • @L0V3V4MP1R3
    @L0V3V4MP1R3 ปีที่แล้ว +1

    Running JS through bookmarks is such a novel idea holy fuck

  • @thiagopenteado886
    @thiagopenteado886 ปีที่แล้ว

    They are using as Mee6 now too... running a different code not sure what is does, but it runs as a "javascript:fetch(atob...
    "

  • @nezo2k522
    @nezo2k522 ปีที่แล้ว +3

    The only time i were scammed was when i got five euros and my mom told me she'd keep it safe in her wallet...

    • @pexie7755
      @pexie7755 ปีที่แล้ว

      And then she goes off to buy makeup products

  • @Theo_1390
    @Theo_1390 ปีที่แล้ว +1

    I love how nobody in the comments section mentioned the fact that he searched up "how to get a girlfriend"

  • @Toothily
    @Toothily ปีที่แล้ว +3

    I’m amazed and baffled that JS bookmarklets are a feature in browsers. Does anyone use them legitimately any more?

    • @RJCUN
      @RJCUN ปีที่แล้ว +2

      I'm amazed and baffled that are a feature in . Does anyone use them legitimately any more?
      But to answer your question, yes, they do see use from time to time. If we removed every feature just because a scammer used it at some point, we'd stop using computers and mobile devices altogether and be left with old analog TV sets. Oh, wait, those are used for scams, too, only they call them "advertisements".

    • @BlackStartx
      @BlackStartx ปีที่แล้ว +6

      @@RJCUN Damn bro, sorry if they attacked your favourite browser feature D:

    • @amongsussyballs
      @amongsussyballs ปีที่แล้ว +4

      @@RJCUN they should be off by default

    • @taureon_
      @taureon_ ปีที่แล้ว

      i use them a lot

    • @lifinale
      @lifinale ปีที่แล้ว

      I use them a bunch

  • @iamv1ce
    @iamv1ce ปีที่แล้ว

    i love how i had the tf2 scaredy-cat taunt under this lmao
    it looks like it was reacting to this

  • @DA99972
    @DA99972 10 หลายเดือนก่อน

    Pro tip: if you ever see an obfuscated script, don't run it. The only reasons for code to be obfuscated are: a) "Security through obscurity" which is a joke, or b) to hide malicious code.

  • @JohnSmith-oq7bg
    @JohnSmith-oq7bg ปีที่แล้ว +5

    Someone commisioned me to make this for them. The code was fairly simple to make, and it was really easy to understand and learn.

    • @object.toString
      @object.toString ปีที่แล้ว +1

      Do you still have the source code?

    • @JohnSmith-oq7bg
      @JohnSmith-oq7bg ปีที่แล้ว

      @@object.toString I do yes

    • @obinonso978
      @obinonso978 ปีที่แล้ว

      @@JohnSmith-oq7bg please can you make it available?

  • @mythic_rblx776
    @mythic_rblx776 11 หลายเดือนก่อน

    I remember watching you 2 years ago, then i didn't see you for like 1 year, das crazy

  • @Tiguex
    @Tiguex ปีที่แล้ว +1

    Bro got me sending every link i see to my FBI agent for him to see if its good or not

  • @Notdaowl
    @Notdaowl ปีที่แล้ว

    “The first step to getting a girlfriend is stop trying” ☠️☠️☠️☠️☠️☠️☠️

  • @blllk8189
    @blllk8189 ปีที่แล้ว +2

    As soon as it said to bookmark the code I knew what was going to happen

  • @funnythe7th
    @funnythe7th ปีที่แล้ว

    the "How to get a Girlfriend" killed me 💀
    also i just noticed the notepad++ tab 💀

  • @samover6603
    @samover6603 ปีที่แล้ว +2

    time for some trolling (spamming the api)

    • @aldyreal
      @aldyreal ปีที่แล้ว

      We do a little trolling, that jsfuck is nothing lmao

  • @Furby.1987
    @Furby.1987 ปีที่แล้ว

    still knew about this method and did a warning on our discord about it but thx a lot for that video :) u explained it rly good

  • @nitsua1103
    @nitsua1103 ปีที่แล้ว +2

    I'm willing to bet the people disliking this video are the same people that are stealing account tokens 💀

  • @Artplanefish
    @Artplanefish ปีที่แล้ว +2

    all the serious things aside
    "how to get a girlfriend"

  • @asfdirt
    @asfdirt ปีที่แล้ว

    oooh, this is a new type of scam, they always find ways to get people into scams. How creative are these people

  • @pold111
    @pold111 ปีที่แล้ว +1

    could someone constantly run the js script through the bookmark and constantly send them useless garbage?

    • @trejkaz
      @trejkaz ปีที่แล้ว

      Yes!

  • @0Nullifications
    @0Nullifications ปีที่แล้ว +4

    since we now see the URL its posting to, lets make a small little script that spams the site with fake tokens >:)
    edit: tho it may have some authentication system in the background that verifies if tokens are real or not, which would make the spam useless i guess..

    • @AveryChow
      @AveryChow ปีที่แล้ว +2

      I figured it out! they used some really stupid way to hide their key (lmao), their key is "fortniteamongustycoonlol" and I bet you can just spam it with requests
      EDIT: I don't know if they are checking to see if the keys are valid, but that doesn't matter if you have thousands and thousands and thousands of keys to check. sure, you can weed out all the fake tokens, but that takes a very long time. especially when there's so many "totally legit" keys.

    • @raik1766
      @raik1766 ปีที่แล้ว

      @@AveryChow You could also make a alt and spam the website with the token of your alt

    • @Zooiest
      @Zooiest ปีที่แล้ว

      Pseudo-valid (i.e. valid to the format but not based on real data) tokens can be generated randomly

  • @koishikomeji6969
    @koishikomeji6969 ปีที่แล้ว +1

    not the "How to get a girlfriend" tab lol

  • @vaaaampire
    @vaaaampire ปีที่แล้ว +3

    I can't believe Sam fell for this scam... Hope his account is ok.
    5:05

    • @afartingguy8541
      @afartingguy8541 10 หลายเดือนก่อน

      my friend got scammed by this :(

  • @Guardie
    @Guardie ปีที่แล้ว

    So what you're saying is that if we see one of those in the wild we just copy the link from the script and spam their API with a bunch of random bullcrap?
    Gotcha!

  • @kgiotakos
    @kgiotakos ปีที่แล้ว

    The kiss in the end hit different

  • @XaneMyers
    @XaneMyers ปีที่แล้ว

    Who else is thinking about spamming that "token logging" website with random trash, like random gibberish strings that look like keys but aren't? 😏

  • @CLaVitre
    @CLaVitre ปีที่แล้ว

    2:03 holy shit I didn't expect that! XDD you're a genius :'))

  • @kosmaaaa
    @kosmaaaa ปีที่แล้ว

    Is it just me laughing at the fact that he has a tab opened in the browser called “how to get a girlfriend”?

  • @Lsunix456
    @Lsunix456 ปีที่แล้ว +2

    That tab bro💀💀💀

  • @Raf99
    @Raf99 ปีที่แล้ว

    I'm 99% sure all verification methods that aren't "click emoji" or "send message" are scam.

  • @meriofrog
    @meriofrog ปีที่แล้ว +1

    Bruh, I just love the people in the comments who have no idea how authentication works but still say stupid crap about auth tokens ☠

  • @centycebra4447
    @centycebra4447 ปีที่แล้ว +5

    hey you were right about the authorization part the only thing is they can also add some weird things which basically access your ip and sell that stuff because that all can be accessed through the console too and other stuff.
    surely not written by an java coder.

    • @dylon4906
      @dylon4906 ปีที่แล้ว +3

      nobody is gonna sell your ip. it's not a 100% accurate indicator of location and it gets changed periodically by your isp. also your ip is given out to literally every single website you visit so it's not hard to get either

    • @v01d_r34l1ty
      @v01d_r34l1ty ปีที่แล้ว +3

      @@dylon4906 That is not entirely 100% true. Your IP is basically your web address and it doesn't always change. For example, I'm still living with my parents right now, and they don't pay for a static public IP address, yet the public IP address hasn't changed in years. Not to mention that the only time it did change was with a new router on a new package with a whole new configuration. Unless your ISP is different, IPs are still a great resource to track people across websites and harvest data for purposes such as advertising and identity building. Your IP is not always geographically accurate, but it's also generally pretty easy to decipher what ISP is providing your service, and with a little social-engineering or backdoor services, you can find out exactly where somebody lives. It's less common nowadays, but this was a bigger problem 10 years ago.

    • @Zaary
      @Zaary ปีที่แล้ว

      java is not javascript? XDDDDDDDDDDDDDDDDDDDDDDDDD

  • @arbitervildred8999
    @arbitervildred8999 ปีที่แล้ว +1

    don't worry Heroku is disrupting all bots by the end of october, no more dynos for scripts and cloud apps

    • @helper_bot
      @helper_bot ปีที่แล้ว +1

      its still a JSbookmark exploit, if anything we need to notify google/other web browsers so this cant be exploited but still usable

    • @trejkaz
      @trejkaz ปีที่แล้ว

      No more dynos for my clock server either. Luckily it isn't really needed anymore though.

  • @helper_bot
    @helper_bot ปีที่แล้ว

    i would have never for the life of me thought you can run js code just in your bookmark, lmao! imo every web browser need to either run a check on the js script before putting it into the bookmark, or just straight up disable the feature. these scams man, they're getting quite wack

  • @brendanpls
    @brendanpls ปีที่แล้ว

    They grab ur discord account for a certain server your in, they dont give a shit for ur account once you post a singular msg in a server ur in.

  • @Dolphin002
    @Dolphin002 ปีที่แล้ว

    I remember this exact same scam was being used on another site, crazy how it's spreading

  • @igntiktok1105
    @igntiktok1105 ปีที่แล้ว +1

    The thing is: one of my friends can code and made an exploit for this bookmark thing, it can do many more harmful things than just getting your token

  • @Boypogikami132
    @Boypogikami132 ปีที่แล้ว

    This is exactly why I like Notepad++. And I really appreciate that my Computer teacher made us download it.

  • @PhilXavierSierraJones
    @PhilXavierSierraJones ปีที่แล้ว

    Oh, bookmarklet stuff. I thought this died back in 2017.

  • @sfisher923
    @sfisher923 ปีที่แล้ว

    I somehow learned something new
    I didn't know you could book Javascript Code

  • @b-eleven
    @b-eleven ปีที่แล้ว

    Damn, these scams are getting so obvious i can't even make a legit Wick verification system because people are leaving because they think it's a scam on first sight, now Dyno too?

    • @trejkaz
      @trejkaz ปีที่แล้ว

      Rule of thumb, any verification that goes out to another site is a scam until proven otherwise.

  • @shwetakejriwal9380
    @shwetakejriwal9380 ปีที่แล้ว

    I love how this guy has easter eggs!
    the notepad said a tutorial for talking to girls
    the search bar has how to get a girlfriend
    lovely!

    • @Raka_
      @Raka_ ปีที่แล้ว

      wow

  • @HatTrex
    @HatTrex ปีที่แล้ว

    I had no clue that bookmarks Js was a thing.
    I don't see any legitimate usage for this function

  • @overlisted
    @overlisted ปีที่แล้ว

    Of course a technology as old as bookmarklets can only now be used in malware...

  • @7heMech
    @7heMech ปีที่แล้ว +1

    I showed the joke to my bro, and then I remembered he has a gf now...

  • @LocalTrashyt
    @LocalTrashyt ปีที่แล้ว

    those x blocks are characters like "f" or any unicode character, but its a link that a computer use to get a character from it's memory instead of displaying. Mostly used for unicode characters that aren't on a keyboard.

  • @GamingWithBenji
    @GamingWithBenji ปีที่แล้ว +1

    How do you get those beautiful folders?

  • @Slipper.The_Avaitor_Films
    @Slipper.The_Avaitor_Films ปีที่แล้ว

    as a person that uses too much internet
    xyz is the cheapest domain so
    if you didn't know that

  • @SnowyRVulpix
    @SnowyRVulpix ปีที่แล้ว

    I had my account stolen recently due to token theft. Was locked out of my account within 2 seconds of running the fake game. I was really dumb that day, but discord’s security is a joke. It should NOT be that easy to steal accounts

    • @chri-k
      @chri-k ปีที่แล้ว

      the real problem is that you can get lock someone out of an account without proving identity. The session token stealing will be possible for as long as session tokens exist, but tokens are the best way to handle accounts to this date, and they are secure as long as the user does not let them get stolen.
      but a token should not count as enough to something like that, and discord does not implement basic verification systems like “if the same token just came from opposite sides of the planet, it’s probably compromised”

  • @hayatimfivemolmus
    @hayatimfivemolmus ปีที่แล้ว +2

    2:16 check left corner💀💀

  • @QDetective
    @QDetective ปีที่แล้ว

    is no one going to talk about how that one notepad++ page he has open says "hi what is up guys today we will be making a tutorial on how to talk to girls"

  • @very_smort
    @very_smort ปีที่แล้ว +1

    is anyone gonna talk about his "wrong tab"

  • @DeccrRG
    @DeccrRG ปีที่แล้ว +1

    I think it's using a thing called JSFuck, its a version of javascript translated to the 'brainfuck' coding language (thats what all those []{}()!'s are)

    • @chri-k
      @chri-k ปีที่แล้ว

      no, JSFuck is regular JavaScript but you abuse type nonsense and class nonsense to make it extremely unreadable, and it ends up looking like brainfuck as a side effect

  • @Arvl.
    @Arvl. ปีที่แล้ว

    This is starting to get out of hand

  • @Mempler
    @Mempler 9 หลายเดือนก่อน

    kde background on windows is just cursed ngl

  • @taureon_
    @taureon_ ปีที่แล้ว +3

    i found out the link that it sends the discord token to so i sent it like 21 thousand fake tokens, i hope that helped

  • @sharkbait_gaming
    @sharkbait_gaming ปีที่แล้ว

    2:27 ayo "how to get a girlfriend" in his tabs?