arisuchan    [ tech / cult / art ]   [ λ / Δ ]   [ psy ]   [ ru ]   [ random ]   [ meta ]   [ all ]    info / stickers     temporarily disabledtemporarily disabled

/feels/ - personal experiences

share your thoughts, feelings, and experiences.
Name
Email
Subject
Comment

formatting options

File
Password (For file deletion.)

Help me fix this shit. https://legacy.arisuchan.jp/q/res/2703.html#2703

Kalyx ######


File: 1512059834577.png (131.57 KB, 536x244, 1.png)

 No.963

Why is it that people are generally just really bad at handling their own sensitive data?
Over about a course of an hour, I have completely wiped about fifteen discord guilds off their data.
It's easy when people upload their tokens into the repo, but even worse when they're really lazy and give them pretty much full permission.
Blatenly not even hacking, just abusing a simple flaw of the user/admin

But I don't feel any powertrip out of it, and I don't feel pity for my actions.
Maybe I enjoy the chaos I can't see, a satisfaction, or something.
Watching a spew of text, each line showing more destruction to add to the mix

 No.964

>>963
most sys admins are just trying to get everything to work, security be damned

 No.1073

File: 1512594305837.jpg (55.46 KB, 516x800, 0ebb694c83f3c3e24178ea2d1a….jpg)

Hey Alice, It's been a while.
I don't think you care that much about what I've been doing, and that's fair enough. I'm not here for you, I'm here for me.

Anyway,
I've been improving on the script bit by bit. It's still just a purge machine, but I can store logs of text channels if I feel, as well as detecting more of if a channel is supposed to be hidden.
Regular botnet soykaf I guess

But that's really why I'm around
I hit a jackpot on a few searches today.

These guys have had their entire history removed;
https://gamejolt.com/games/pokemon-mega-adventure-new-update/211206

As well as this entry here;
https://discordbots.org/bot/329323350084026369

I'm learning a lot about how risky it is to run services like this in such a centralised environment. A simple ninja commit ends up with a heavy fatality like what I've witnessed.
Maybe I shouldn't keep this log I have. I know this soykaf is seen wrong, but I don't feel like that. All I feel is an overwhelming lust, which is all I can really say without confusing myself.

 No.1074

File: 1512595136633.jpg (94.94 KB, 737x454, 20171204_102852.jpg)

>>1073
Geez. You say it's not a powertrip but it sure sounds like that's what you're getting out of it.

 No.1075

>>1073
Oh well. I don't see much point in trying to convince you to stop so just keep doing what you're doing and leave Alice out of it.

 No.1076

>>1074
In my perspective, It would be a power trip if it made me feel superior over those at loss.

But maybe it's grown on me

>>1075
I'd actually really would like to know what you have to say, if you really want to say anything that is

 No.1077

how does someone wipe discord guilds?
links / materials / docs

this has to be patched by now if the chinese investors at discord
are worth their salt.

 No.1078

File: 1512599111309.jpg (28.35 KB, 500x500, 1512504860114.jpg)

>>1076
Nothing to really say. "But that's wrong!" I could whine. But I know you're not stupid. You know it's a dick move to destroy other people's hard work, you just want to do it anyway. Once you're at that point people are just wasting their breath.

 No.1079

>>1077
This isn't a bug, this is a human error.
There's a MANAGE_CHANNELS and MANAGE_ROLES permission bit when allowing a bot account access to the guild

unfortunately, it seems that many people are just too trustworthy of their administrators, or unaware of how valuable the auth token is meant to be

alternatively, I'm surprised the machine I use hasn't been blacklisted

As to say how it wipes;
It attempts to delete every channel possible, rendering invite codes removed. All messages along with it since it's how channels work.
Roles are removed too.

 No.1080

>>1079

Can you teach me how to search and exploit these tokens?

I want to harden discords against this turrible opsec (translation: I want to troll some discords that have legitimate autists larping as anime avatars).

 No.1082

>discord guild
>"private" data
Lol nope, kid. This data is the whole property of Benchmark Capital™ and Tencent Corporation®.
Did you read the End User's License Agreement and Terms of Service page 59 section 15 line 8?

 No.1087

>>1082
You're the only one talking about private data

 No.1088

>>1087
>their own sensitive data
Isn't this the same?

 No.1089

>>1088
That was referring to the authentication tokens. Of course Discord knows those, they are the ones giving them out.

 No.1096

>>1078
Maybe he's baiting you, trying to make you write a very long, careful, elaborate post before he wipes arisuchan Present Day, Present Time! HAHAHAHAHAHAHA!



[Return] [Go to top] [ Catalog ] [Post a Reply]
Delete Post [ ]