Hacker Newsnew | past | comments | ask | show | jobs | submit | tisryno's commentslogin

I don't know the specifics, but I'd assume not, Discord has made big steps recently in stopping this sort of malicious activity by adding the "Report Spam" feature as well as creating their own phishing link database to help detect spam in private messages.

Discord knows it's a big issue and I'd hope they've attempted to mitigate the malware but there's no way to stop the actual injection, so really all they can do is code shuffle frequently to make the injected code redundant, but that'd rely on doing releases frequently and hoping everyone updates just as frequently.


I'm glad to hear they're taking things more seriously. They banned my original Discord account when I showed them a critical bug that allowed for remote viewing of another user's activity, both in real time and in logs.


Yeah, Discord is still just a bad with that. If you join a server and find it's hosting illegal material and proceed to report the server, Discord will ban all members of that server, which includes you. It's created an environment in which no one wants to report anything to Discord, especially since if you appeal your ban you won't get unbanned as you were in the server.


Yes, you can send a DELETE to a Discord Webhook, but these malware projects have clocked on in most situations and now forward Webhooks through their own domains.

For the example of PirateStealer, the kid who made it ran a website where you posted your webhook and it spat out an exe that hid your webhook behind the domain, they even sold "premium" copies with additional security but in reality once they put the webhook behind their own domains they were dual-hooking, so the information was actually sent to 2 webhooks instead of just the 1.

Most of the services to create this malware now hide it behind a domain rather than directly exposing the Webhook, so shutting it down isn't as easy.


No, there's no direct API for that. What the malware does is inject javascript into your discord, so if you add any payment details to your account it will harvest the data and send it via the Webhook to the owner.

The injected code also will scan your friends for "rare" badges, like the Bot Developer, Early Supporter and Certified Moderator. They use this information to then target the malware to those people in the hopes they can sell the rare badge accounts.


Interesting article, but this type of malware has been spreading for months now. PirateStealer is definitely the most popular but it's been shutdown a few times by a discord group who are targeting this type of malware.

One of the tools they've built is https://sketchy.tel/ which can decompile piratestealer/extrack/bby.rip and more and shuts down the Webhook automatically.

There's a lot of other things we do in this community but I can't disclose it because we never know who's reading our messages and if they get found out the malware creators will adapt to stop us.


This is exactly what's happened to me also, oh well, back to procrastinating


Since OP thinks it could be a scammer doing it, perhaps just check the referral header and display a big banner stating that listing on Maps is not you and to not contact them and list real services/competitors?

Will stop people from contacting them in favour of real businesses if that's the case.


I agree that this is better, it punishes Google's reputation as well.


I got a 'nice' error page temporarily now back to the error loading the error page.


Great concept but I can see it falling out of line very quickly, on the homepage I spotted "berlin -> country -> germany" Followed by "england -> capital -> London"

If you search for the key "germany" it has no results, if you search "london" it finds no results.

The fluidity of the data is definitely a hindrance, if you wanted to use the dataset you'd have to already know what you are looking for to find the value.


The demo doesn't allow you to put in your own lyrics, keeps loading exactly the same set of words. Really awesome project though


Original author here; good catch, I've fixed it now so it'll sing whatever lyrics + notes are in the grid when you press "Set Voices". Thanks for pointing that out!


Glad to hear you got it fixed, I'll play around with it on my lunch break


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: