dekrypted / discord-image-logger

IP Logger that uses discord's "Open Original" feature to steal IP's.
The Unlicense
2.14k stars 598 forks source link

This is not a feature request but a Note on what you have said. #62

Closed Antsbatscats closed 1 year ago

Antsbatscats commented 1 year ago

"Please note that this is NOT a "one click" image logger. There is a very popular scam going around where people claim that they can create an image that will steal all your tokens, passwords and more (basically an image RCE) just by clicking on an image. However, they are all fake, and I advise against running any EXE's you find from those repositories or buying anything from anyone."

First of all to say there is no such things as one of these is very inaccurate, there are definitely some. First of all u don't need to have some complicated stuff go on to do such a thing, for example in the video you made; you said that by clicking on an image - nothing could really happen on the magnitude of what I am saying is possible. First of all a 'One-Click' image logger is a big misconception not a scam. When i mean misconception, i mean it in that there is a lot of unknowns about what this kind of software can do. Of course there a scammers who have no idea how to do this kind of stuff, but that is not an excuse to say they are not real. For example, you could create a link that links to an executable file (I'm using the windows operating system as an example) which is instantly downloaded and run. You may have heard of the w4sp malware, this could easily have been a prime candidate for such a outcome. w4sp was designed to steal discord accounts and other personal data from programmers specifically - but you could easily have implemented this into software that is design to attack a common user.

I am going to assume you were talking 'One-Click' software to just lead you to a website of some sort, which would nearly have no chance of doing anything which I said above, but that's not what 'One-Click' software is. All 'One-Click' software means is that it is designed to only have a singular action inputted from a victim, not that it can only have one possible reaction for a user input.

Also if you'll accept this; this is software that can be exploited for malicious purposes so could i recommend that you take this down, I've already had a friend who was affected by this software.

dekrypted commented 1 year ago

when i say one click i refer to a one click image logger, or when someone sends you an image on discord and just by clicking the preview you get token logged

at this time i will not be removing this because it only steals IP info which is public anyway

Antsbatscats commented 1 year ago

https://github.com/Antsbatscats/Python-Malware-File-Stealer this is a link to software I have made that can be used in what I said earlier. I also thank you for such a quick reply.