Stekeblad / Stekeblads-Video-Uploader

Easier bulk-uploading to Youtube
MIT License
31 stars 13 forks source link

Stekeblads Video Uploader was granted access to you google account !!!! #44

Closed yasmeen2001234 closed 2 years ago

yasmeen2001234 commented 2 years ago

Can you the creator of the program plz explain how I got hacked and granted access to this FU*** program ???

My google account is highly secure with 2-step verification , and when I got the email I removed the access and changed my password but still they were able to upload videos on my channel. Videos that were illegal or against YouTube guidelines , which lead to banning my YouTube channel.

I am heartbroken and confused at the same time , I read other people issues and your respond was like ( " Stekeblads Video Uploader was made to make it easier to upload videos " ) ( "Stekeblads Video Uploader is not a tool for hacking channels " )

I know you work hard on the application , the coding and the debugging etc. , but no normal person uses stekeblads to upload videos. I means it is kinda useless , only hackers could really benefit from it. Plz do something about it or ....

Stekeblad commented 2 years ago

Hi @yasmeen2001234

I can't tell you how you got hacked, it could have happened in a million ways. 2-step verification is a good extra security layer but there are many ways for getting around it too. To just give one example: A phishing e-mail with a link to a fake login page, tricking you into giving the hacker your email/username, password and 2FA code.

I do not know how Google's security systems work on the inside and how the hackers could still upload after you removed access and changed password. Maybe the hackers was not automatically signed out by the password change? (Just guessing)

From one of other issues you commented on you know that Stekeblads Video Uploader can not tell a legitimate user apart from someone using a hacked account, all authentication and authorisation is handled and (if correct) approved by Google. With Google convinced, the hackers can give any program, website or piece of code access to the account. It's not like they need Stekeblads Video Uploader, they have all permissions they need to upload videos directly on YouTube's upload page or through any other third party program. It appears like they just found this alternative to be the easiest to use.

but no normal person uses stekeblads to upload videos

I consider myself to be a normal person that does not do illegal things and on the rare occasions I do upload videos I have always used Stekeblads Video Uploader since I released version 1.0. (Not that my word may be much worth in this situation...) I want to believe the best and that there are many users that have saved hours uploading videos to their own channels with the help of Stekeblads Video Uploader.

But, please don't get me wrong. I feel really bad over that some bad guys use Stekeblads Video Uploader to get their evil videos up to innocent users' channels. I just don't know if there is anything I can do to prevent it -- but I also know that if Google can't block the bad guys or channel owners can't keep their accounts safe then this will continue, with or without Stekeblads Video Uploader.

ReyGraph commented 2 years ago

umm btw i the video i didnt made is being uploaded by your bot stekeblads at first i thought its a hack or virus then i googled and showed its not a birus btw helps people but i dont understand how it uploaded videos that i didnt make

Stekeblad commented 2 years ago

Hi @ReyGraph I am not sure what you are trying to say, but if you see videos on your channel that you did not upload then someone else has logged into your account and uploaded them. You may want to check activity on your account and review your security settings. https://myaccount.google.com/security

WolfTM commented 2 years ago

Well let me go in on this topic.

How would you explain all of my google accounts were granted your stuff permission to youtube at the same time. Screenshot_115 From my own device? Without me knowing? You got some shady stuff going on here.

I would like a valid reason why this is happening without my supervision. All at the same time and even from my own device. I think your stuff is implemented in software and other stuff. Software that uses a mask to cover the truth of them selfs.

This happened after I installed an app called DriverMax to update my drivers. Very shady. Malwarebytes then alerted me of unwanted software and such. When I uninstalled it and malwarebytes did the clean up it was all over. If no valid reason you and DriverMax will be under fire. This will be reported to Google and others. Because it uploaded roblox hack videos on my channel

Stekeblad commented 2 years ago

Hi @WolfTM

I have never heard of DriverMax but when I look it up I find just what you mention, Malwarebytes flags it as a potentially unwanted program. I also saw links to "cracked" versions and unofficial downloads, these have a high risk of including malware with the installation. Always download stuff from the official location to reduce the risk of getting other unwanted stuff at the same time...

If it happened to all your accounts at the same time then it sounds like some malware may be on your computer and has stolen all your cookies and saved accounts from your browsers. With this it can pretend to be you, Google and others will believed it.

I am not sure what more to say other than that you should hurry checking and securing your accounts. It's likely more than just your Google accounts that are at risk. I hope you can get those bad videos deleted and you do not get more unpleasant surprises.

WolfTM commented 2 years ago

Yes,

I get it I payed for the software but that is not the point. If you are unaware than others are abusing your software currently. And are using it for illegal purpose. I find it sad that this happens but at the same time I am glad that it is not you.

Sorry for the words. I will report this and the software and get it checked out. MY PC is clean now. I just find it so sad why people have to use other people their creations and abuse them. Sorry for this. Keep up the great work on your app.