sanjaybaskaran01 / Valorina

Discord 🤖 to never miss a Valorant skin drop!
https://discord.com/oauth2/authorize?client_id=888741654482272276&permissions=2147739648&scope=bot
MIT License
35 stars 12 forks source link

Someone try to sign in to my account on 23 - Jan 2022 at 2:21am (GMT +7) #15

Closed havinhphu188 closed 2 years ago

havinhphu188 commented 2 years ago

Not sure if this bot has leaked my password, but I have only leaked my riot account to 2 sites. This valorina, and valorant.store (already shut down). Valorant.store claim that they do nor store our password (and the fact that I have to type password every time, make me believe the leak must came from valorina) Luckily, I have 2-factor auth, but I am not feeling safe with valorina anymore.

github-actions[bot] commented 2 years ago

👋 Thanks for reporting!

sanjaybaskaran01 commented 2 years ago

Hey @havinhphu188 , if you go through our code over here in line 17 and 25. You will get a better oversight of how we store your password encrypted which is necessary to get the headers from Riot. If I'm not wrong riot sends notification when there is an unsuccessful login (password entered incorrectly). We store the passwords encrypted and only decrypt it when we need to make an API call to retrieve the headers. For example we retrieve headers in line 112 when someone enters the command +store.