Discord - Advertisement Exploit (HIGH)
Introduction
First of all, the purpose of this topic is to inform and educate. Instead of misusing it, you can take precautions on your servers.
How Does the System Work?
This advertisement exploit occurs due to a feature introduced in Discord.js 14.16.0. With the recent update, Discord bots can be added not only to servers but also to profiles. When you add these bots to your profile, you can use their commands in servers and direct messages.
However, only message-sending commands are allowed. Additionally, the "Allow External Applications" option must be enabled in the server and channel permissions. If it is not enabled, messages will only be visible to the user executing the command.
Where Is the Issue?
"Allow External Applications" is enabled by default on all servers.
By writing a script, advertisement spam can be performed, and since most people are unaware of this exploit, these services are sold for a fee. People profit from this and advertise on large servers.
How to Do It? - Important Points
I wrote the script, and this is for educational purposes only. We hide the user executing the command by making a follow-up to the bot's message. This way, even if we delete the message in the audit log, it does not appear, making it difficult for server administrators to detect.
Step 1: Create a bot from the Discord Developer Portal.
Step 2: Go to the Setup section. Then check "User Setup."
Step 3: Use the link you obtained to add the bot to your own account.
Step 4: Download Download the program.
Step 5: Run the program and enter the bot token.
Executing the Command:
If the feature is disabled on the server:
Audit Log and Tracking
First, we send the message secretly and spam it using the follow-up method. Since the first message disappears, the sender cannot be tracked or logged.
| Version | Module | Description | Status |
|--------|------------------|----------------------------|-------------|
| v1.0 | Anka Red Team - Discord Exploit | Single Bot Advertisement Spam | Released | Download
| v1.1 | Anka Red Team - Discord Exploit | Multiple Advertisement Spam | Planned |
VirusTotal: Click Here
DISCLAIMER:
The code has been written for educational purposes only. It is strongly advised not to use it for malicious purposes.
Users are responsible for their own actions. This issue has been reported to Discord.
Introduction
First of all, the purpose of this topic is to inform and educate. Instead of misusing it, you can take precautions on your servers.
How Does the System Work?
This advertisement exploit occurs due to a feature introduced in Discord.js 14.16.0. With the recent update, Discord bots can be added not only to servers but also to profiles. When you add these bots to your profile, you can use their commands in servers and direct messages.
However, only message-sending commands are allowed. Additionally, the "Allow External Applications" option must be enabled in the server and channel permissions. If it is not enabled, messages will only be visible to the user executing the command.
Where Is the Issue?
"Allow External Applications" is enabled by default on all servers.
By writing a script, advertisement spam can be performed, and since most people are unaware of this exploit, these services are sold for a fee. People profit from this and advertise on large servers.
How to Do It? - Important Points
I wrote the script, and this is for educational purposes only. We hide the user executing the command by making a follow-up to the bot's message. This way, even if we delete the message in the audit log, it does not appear, making it difficult for server administrators to detect.
Step 1: Create a bot from the Discord Developer Portal.
Step 2: Go to the Setup section. Then check "User Setup."
Step 3: Use the link you obtained to add the bot to your own account.
Step 4: Download Download the program.
Step 5: Run the program and enter the bot token.
Executing the Command:
If the feature is disabled on the server:
Audit Log and Tracking
First, we send the message secretly and spam it using the follow-up method. Since the first message disappears, the sender cannot be tracked or logged.
| Version | Module | Description | Status |
|--------|------------------|----------------------------|-------------|
| v1.0 | Anka Red Team - Discord Exploit | Single Bot Advertisement Spam | Released | Download
| v1.1 | Anka Red Team - Discord Exploit | Multiple Advertisement Spam | Planned |
VirusTotal: Click Here
DISCLAIMER:
The code has been written for educational purposes only. It is strongly advised not to use it for malicious purposes.
Users are responsible for their own actions. This issue has been reported to Discord.
Son düzenleme:

