Discord IP Resolving exploit revealed. [PATCHED]

General Discussion related to the Plazma Burst game series!

Discord IP Resolving exploit revealed. [PATCHED]

Postby ZapruderFilm » 17 December 2016, 03:30

Hello, I'd like to warn you about something.
So today I was messing around on the internet, when I decided to consult an affiliate of mine about an irrelevant matter. When I went to speak, it turns out he had been IP resolved via discord.
So I went to do some digging.
After consulting the discord API chat (Bot coders, basically) One guy knew how it was done. He had coded this exploit.
https://gist.githubusercontent.com/leovoel/0eb72445cae32f7769040f5105366483/raw/290fae9b0d5a5c3c6c476d1247cf278efe1a4848/thing.html

Here's how it works.

Discord has a complex proxy chain that loads data and images for you without you clicking, so that you aren't IP tracked.

This code convinces discord to load data into the client while bypassing this proxy chain as it is an MP4 file.

So user sends the exploit as a GIF (It's actually an MP4 file but metadata hides this.) When you hover over it, it sends a request to that host of the MP4 file, compromising your Ip.

Here is a test I ran myself with my own website:
http://prntscr.com/dkexx5

This blocked content is because my website does not have SSL, but this is easy to get by, as you can see it directly attempts to contact my website (If it was using the proxy chain it would look like this: http://prntscr.com/dkf1q6)

This is proof of concept of IP logging without opening a link in discord.

I recommend everyone use their VPN's.
This is all.
Have a wonderful day.

EDIT:
HAS BEEN PATCHED BY DISCORD WITHIN 2 HOURS OF FINDING IT
Last edited by ZapruderFilm on 17 December 2016, 06:44, edited 2 times in total.

ZapruderFilm
Android T-01187 [200]
 
Posts: 238
Joined: 26 August 2016, 21:00
Location: USA

Re: Discord IP Resolving exploit revealed.

Postby Terror Only » 17 December 2016, 04:14

thanks bro. u r the best. pls get into global announcement section next time
User avatar
Terror Only
Falkok [250]
 
Posts: 259
Joined: 12 February 2016, 11:45
Location: pizza sauce

Re: Discord IP Resolving exploit revealed.

Postby ZapruderFilm » 17 December 2016, 04:39

Terror Only wrote:thanks bro. u r the best. pls get into global announcement section next time

Unfortunately I don't think staff want me on their team.

ZapruderFilm
Android T-01187 [200]
 
Posts: 238
Joined: 26 August 2016, 21:00
Location: USA

Re: Discord IP Resolving exploit revealed.

Postby Terror Only » 17 December 2016, 07:04

ZapruderFilm wrote:
Terror Only wrote:thanks bro. u r the best. pls get into global announcement section next time

Unfortunately I don't think staff want me on their team.

judging from your posts you know a way to much about illegal internet activities. staffs possibly expect you to use our private information some way they don't want you to. and they might be right. maybe not

have you tried to apply for the staff team?
User avatar
Terror Only
Falkok [250]
 
Posts: 259
Joined: 12 February 2016, 11:45
Location: pizza sauce

Re: Discord IP Resolving exploit revealed.

Postby ZapruderFilm » 17 December 2016, 07:27

Terror Only wrote:
ZapruderFilm wrote:
Terror Only wrote:thanks bro. u r the best. pls get into global announcement section next time

Unfortunately I don't think staff want me on their team.

judging from your posts you know a way to much about illegal internet activities. staffs possibly expect you to use our private information some way they don't want you to. and they might be right. maybe not

have you tried to apply for the staff team?

Yes I have a pending interview now.
As for talking about illegal activities:
I enjoyed for a very long time indulging in less dignified cyber activities, and it happens to be one of the things I am most knowledgable about, so it tends to be something I enjoy speaking about.
I have quit doing these things. I do not harm people any longer.

ZapruderFilm
Android T-01187 [200]
 
Posts: 238
Joined: 26 August 2016, 21:00
Location: USA

Re: Discord IP Resolving exploit revealed. [PATCHED]

Postby Missak » 17 December 2016, 16:12

You really do know much about the Internet, I am not a very educated person in IT and Computers myself.

Thanks very much :)
User avatar
Missak
Usurpation Soldier [50]
 
Posts: 68
Joined: 25 March 2016, 10:58


Return to General Discussion

Who is online

Users browsing this forum: No registered users



cron