The Dumbest Discord Safety Bypass...
Vložit
- čas přidán 3. 06. 2024
- Discord spends a lot of time making features that prevent people from being scammed. They have a window that pops up if you are about to visit a website. Perfect for making sure you don't end up on a phishing page.
But there is a stupidly easy bypass that can allow people to be exposed to vile content or scams. And it's right at your fingertips, pun intended.
SOCIALS
-----------------------------------------------------------------------------
Discord Server
/ discord
Twitter
/ notexttospeech
TIMESTAMPS
-----------------------------------------------------------------------------
00:00 - Discord Link Bypass any%
02:18 - How does this work?
05:16 - Opening Calculator
06:47 - Why Does Middle Clicking Exist?
07:28 - What Discord May Do. - Věda a technologie
I love how the PH didn't give the 18+ warning, meaning he's already consented or lives somewhere that doesn't prompt it
oh
you actin like its some weird thing 💀💀
In his defense, he had to make the site come up when he clicked it so he had to go for that at least.
Oh cool...
How do you know?
I am curious, how do you know it gives an 18+ warning? Huh?
It's perfectly natural to people have sexual intercourse ig kekw
I feel like I would be dumb enough to fall for the cat one
same
Same
same
Same
Same
I absolutely love the fact that we are watching NTTS as he slowly drifts away from his sanity.
Would be nice if they added the popup when you middle click, but also add a setting to disable the popup for anything (including the open original and hyperlinks)
(Copy paste template)
To those who don't know middle click does this, in most modern browsers, when hovering over content like images, or a bare link, pressing middle click opens that content/link in new tab,
And since the Discord Client app is just a embedded browser, it'll open a new tab (but opens in your computer's default browser)
why would tehy do that? you can just click to not show pop ups from that site
@@watarod they're implying to remove it from any websites, including new ones
I think the best way to prevent scams and still keep power users happy is to just add a new setting in your security settings that's turned off by default and if you turn it on, it will allow the middle click to bypass the pop up on any link from then on.
bud if you are falling for scams on discord then you shouldn’t even be on it
@@hi-kt3qr I'm talking from a business perspective here. People are dumb and they will always be dumb and as a software engineer you know that and handle accordingly (at least you should). This means that you should try to keep every possible danger away from the user as good as you can and also you're running a business. You want those people to become/stay your customer. So saying:"If you can't even detect scams, go away" is ridiculous.
Also, there are extremly good scams out there that can even fool experts and there are always new ones on the way.
I like this solution
@@hi-kt3qr Famous last words
@@hi-kt3qr The same could be said for anyone getting on the internet. By your definition, no one should even be on the internet.
As a person who uses trackpad instead of mouse. I see this as an absolute win.
edit: i know how to middle click now with trackpad stop blowing my notifications.
Are you at the bank or something
Edit : i though trackball because my english is bad lol
people that use discord on phone
y'know how you can click with two fingers for a right click? try clicking with three
W
people who use a macintosh g3:
4:19 THANK YOU for clarifying this. people are scared of having their IP leaked, and although you don't want it leaked, it's really not hard to have it changed and not much damage can be done with it.
Depends on your ISP. Some of them don't refresh your IP often, some of them will change it any time you disconnect your router. Booters still work so you can still get ddos'd. How much damage can be done is also going to depend on how much opsec you got because sometimes that city or town name will be the last piece needed to get you doxxed.
@@djsvrlaivwfofj Hey, this was actually pretty informational, thank you! Although, I am curious as to what happens if you change your IP and the person tries to use your old IP to see your location? Will it just not be there? e.x. somebody says they just grabbed your IP, and then you quickly reset your router (hopefully before they used any software or what not to view it, I'm not too experienced). Also, do you think I'm underestimating or overestimating how safe you are even if your IP is leaked? Thanks.
@@specinix7547 IP addresses are assigned to organizations and ISPs in blocks. These blocks are often associated with specific geographic regions or countries. IANA allocates large blocks of IP addresses to regional internet registries and these RIRs, in turn, allocate smaller blocks to ISPs and other organizations called ASNs. When you change your IP, what is happening is your ISP is putting that address back into the assignable pool of addresses and giving you a different one. That IP is still mapped to that location due to the ASN it is in. Having your IP leaked is never a good thing, and how dangerous it is depends greatly on context. For the average user, the most they would have to worry about is losing internet for a bit or getting doxxed. If you are self hosting anything, knowingly or otherwise, you might be vulnerable to targeted attacks.
@@djsvrlaivwfofjMy public IP is kind of a double-edged sword.
On one hand, it hasn't changed once since I signed up with my ISP 6 years ago, so I always know how to remote into my PC for e.g. grabbing a file I forgot to take with me. (The only thing I port-forward is a file server, and it's password-protected so that it can't even be viewed without logging in)
On the other hand, the "location" of it isn't even in the right province. (the canada equivalent to a US state)
@@Iristallite If you don't have it behind something like cloudflare id check to see if its on any public scanners like shodan or censys, people love finding 0days for file servers. Most recent being MoveIT
this is actually smarter than 99% of scams on discord
0:40 This is a tears of happines. He finally got a reason to go to this site.
Bro
dat goofy ah emoji 💀
@@kocurro14
@@scubasteve6175
@@ItzJupiter
discord never fails to be a discord between no text to speech's last two brain cells trying to figure out what the frick discord is doing and how hackers are exploiting it and how dumb people are
i had a stroke reading this and I still have no idea what you tried to say
@@Yuxsno one asked
@internet_userr no one asked for your opinion
@@internet_userr no one asked for you to comment this
@@internet_userr?? did you reply to yourself
0:58 NOOOOOO GET OUT OF MY HEAD GET OUT OF MY HEAD GET OUT OF MY HEAD GET OUT OF MY HEAD GET OUT OF MY HEAD GET OUT OF MY HEAD GET OUT OF MY HEAD GET OUT OF MY HEAD GET OUT OF MY HEAD GET OUT OF MY HEAD!
/remove from hed
😂
The discord scam website went down in less than 5 hours because of this guy. Respect
discord never fails to disappoint us
Average comment
LMAOOOO
It's not discord's problem humans are too fucking stupid that they do anything a suspicious image says. If you are an average computer user, you must know a middle click on your mouse opens links directly, if you don't you shouldn't be on the internet at all seriously.
@@zehoudiniaverage and accurate
@@David280GG yep
1:00 as a tf2 player I can say I had been traumatized by this a long time ago
It's either buff mercs, or Mimi sentry mayhem
there is no escape from buff mercs or mimi
Ima grab your wristwatch
MGE mercs on the grannary mid (click)
I'd much rather see BUFF ENGI than mimi
2:33 What is bro looking at? 💀📸📸
how funny
@@duracell1battery Someone had to say it
5:08 Okay, that joke was great. Well played.
This video fixed my mouse's middle click.
I knew the scroll wheel was broken, so I spammed middle click on the gifs for fun.
And now it's working again.
You should probably see if there's any dirt inside.
I don't think anything has been fixed for long... I had the same problem (scroll wheel being too erratic), turns out I needed a new mouse.
Wow, thanks for teaching me about middle click to open images/links in new tabs faster! That's honestly pretty handy.
I do think the middle click not bringing up the safety popup looks like a bug, but who knows. I do hope they add the popup for middle-clickers just to be safe, since we got that checkbox to trust websites already for it.
Another method to use it, left click + ctrl
Discord being a web app is the main reason why it works. It's not a bug, it's a difficult feature to fix on their end. I doubt they have the ability to fix it without hosting the images/gifs on their server or outright disabling it.
@@cesj1 nah, it's easy. In the chat view, Discord displays GIFs as videos (GIFs are treated as videos, so Discord can pause them when the window isn't focused) wrapped inside of links (so when you hover it in the browser, you see URL in the bottom left corner, and also you can drag-and-drop the image to quickly download it).
Middle click feature is default for links, but can be disabled with a single line of JS:
imageLinkElement.addEventListener('auxclick', e => {if (e.button == 1) e.preventDefault()})
it's always worked for me on normal links, I think grabify found a bypass
@@Rikonardo gifs are not treated as videos. Gifs are treated like gifs which are a collection of pictures.
8:04 that came out of nowhere lmao
had me laughing
6:28 brits troll never stop lmao
5:27 *Hello NTTS*
Option number 4, make middle clicking images a setting as it is now, but have that be disabled on default
why would you like to open an embed without knowing the link as text beforehand, just show the popup
@@helper_bot but angry power users
make it an experimental feature xd
also what doe power user mean
@@doodlebro. means advanced user.
imagine leveling system like this:
normie - power user - sysadmin
Option 5, option 3 but you can disable the popup from ever showing up
1:46 this is funny because I was already playing subway surfers when this vid autoplayed
ADHD strat
Waste of Space Mentioned.
no.
Discord really shows you the deepest vowels of the internet, but fairly, the calculator one is a fairly harmless and inoffensive joke.
I like these weirdos' creativity
You mean bowels, right? Vowels are letters, bowels are what you call nasty things.
@@Dyanosishe's probably afraid of E, idk
Would that be U or Y?
@@yag-yet_another_gamer Golden comment.
Another option could be making it an option in settings. Probably a developer setting with a warning about it bypassing the "Are you sure you want to goto this website" prompt.
I require the “VARUS detected, middle click bruv” and “middle click for calculator” gifs I NEED THEM
Was gonna say you should explain that middle click isn't just a discord thing and then you did, so that's cool.
I learned about it for general browsing use a little while ago and it really is incredibly convenient
damn discord actually needs to fix this, imagine random innocent kids falling for this trick...
Doxbin skids boutta start doing this shit istg
Yeah
They ain't even meant to be on there
MINORS?!??!
@@zakingcuh unfortunately, yes.
NTTS's videos keep getting more and more unhinged and i am all for it lol
I think there should be a toggle to have the warning message, whilst keeping the "trust this site" option. I can't imagine how easy it would for discord to have the middle click having the warning message pop up as a fix.
You offered your search history for us! You are a true legend
Deep down, petting the cat turned out to be the best decision after all.
This guy makes me stay on Discord for longer with every upload 💀
Your channel is deeply disturbing yet incredibly hilarious, i feel you on every level and step of the way, i relate to you man, and your sadness paired with humour is peak comedy.
your muah at the end of the video is my new favourite thing😭❤️
5:16 You actually beat it
The reason why middle clicking bypasses the pop-up is because of the browser. Discord likely uses event.preventDefault() in JavaScript on the click event to prevent clicking on a link from replacing the current tab with the page, which is the normal behavior for web pages.
However, for whatever reason, preventDefaulting click events does not prevent middle clicking, so it makes sense why this Discord let this happen; it's a pretty easy oversight and not obvious at first how it could be abused. It's not entirely obvious how to fix it either; searching "prevent middle click on link js" doesn't really give a solution in the first few results. From my testing it seems, at least in Chrome, preventing the auxclick event works to prevent middle clicks, so it's not impossible to fix.
"goddamn come back bouy" - NTTS 2023
Another somewhat obvious option is to enable middle clicking as a setting. Those who don't use the feature can leave it off and never have to worry, and those that understand the risk and still want to use it can simply toggle it on.
4:28 I have no ddos prot, I have a static IP, I have DSL internet, guess why I learned the first two.
The more he tells us about where he doesn't live, the more we know about where he does. We need to give that goodnight kiss.
I love how I got this video recommended to me, not because of the channel, but because of a two-second gag where he briefly mentioned "hello little stylus" from the 3DS presentation. God bless this enigma of an algorithm.
"middle click a link and it would open up a new tab" bro ive watched all your vids and this is the one that had my jaw dropping
I laughed out loud when you said you would put the Subway surfer on the side lol. Well done NTTS.
same
this is kind of conflicting because middle clicking image to immediately go the source image is actually useful for a long time for me
the problem isn't the feature, the problem is how people exploits it
Make it a setting (in the developer settings)
The problem is that people are stupid
because the waste of space community is so small i felt so happy to see a picture of the faction hub thing
damn bro your vids are so good! i always discover new things with you
6:50
Thats the thing, middle click is basically the shortcut for "Open in a new Tab" Thats why it happens to discord
i like how in a lot of his videos he doesnt even try to blur very personal information, it might be fake but still he is not scared
3:28 You opening the IP section of the IP Grabber website, and it showing North Charleston almost make me shit bricks before I realized I hadn't clicked or looked at the image
Bro same 😭
dude this video's thumbnail actually just taught me that middle clicking is the hot key for opening things in new tabs
They can always pull a twitter and convert all links into their own "analytics" link so when you middle click them it goes through that analytics redirect link and phishing attempts can be intercepted.
This sounds good, something I wouldn't necessarily expect from something you'd call "pull a twitter"
And it is extremely annoying on mobile, when a can't copy the link.
As someone who uses the middle click feature more than any other existing being I feel perfectly fine
7:05 Linus don't got nothin on you Tech Tip Man
As a person with a broken mouse without the middle key. I see this an absolute win.
Ctrl + left click.
you obviously dont have 47 tabs open at any given moment throughout the day
@@grqfes who doenst?
@@mr.eisbearnormally i have around half that open
@@yag-yet_another_gamer have a max of 8 tabs per day and when I do, I just close them when I don't need them and if I need them, I just press Ctrl + shift + T to get them back because I usually have 2-4 IDE's running (jetbrains) that eat my poor 8gb stick
as part of Waste of Space not very big community im proud of whoever made the thing on 0:34
so true...
We do in fact exist
Waste of space is now famous
the crazy insanity moment
@@rockets-space tci got real
to those who don't know middle click does this, in most modern browsers, when hovering over content like images, or a bare link, pressing middle click opens that content/link in new tab,
And since the Discord Client app is just a embedded browser, it'll open a new tab (but opens in your computer's default browser)
I learned about middle clicking for new tabs shortly after HTTPS was released for the wider internet. Best thing I ever learned about in regards to the internet.
1:57 I really can't blame tiktok users now this really is enticing, so much so I ignored the rest of the video while it was still up
A naked man fears no pickpocket.
Man came back a beast after middle-clicking, sounds like I'll have to try.
the first part is a rollercoster of emotion
Roblox Waste of Space is real
MAWESOME?!?!
holy shit
5:47 what on earth is a pro fart smeller
I don't care what this video was really about, it's just the humor that makes my whole day better.
"Ive beat this joke to death." Well played funny discord man.
my favorite uri is ms-cxh-full:// because it completely blacks out the screen
it doesnt respond to alt+f4 and the only way to exit is to blindly type a taskkill command or restart your computer
0:39 poor ntts :(
middle clicking is also useful if you want to open another instance of an app from the taskbar while one is already running
I have never once middle-clicked my mouse until today, I didn't even know it was a thing. I middle-clicked a google doc and it made it scroll. Thank you for making me aware that middle-clicking is a thing that could actually be useful for writing in a google doc. I know that's not the point of the video, but it's still helpful lol
2:09 Ty for the subway surfers
The thumbnail LMFAO
its not that hilarious 💀🙏
it was unexpected considering the past thumbnails 💀
hai eagle :3
@@marilenbasanes3003it still is kinda unexpected from him ☠️☠️
@@thetoastedpotato you here fr
4:17 tbh would genuinely wanna see a vid going in depth on why getting ip grabbed isnt as big a deal now as it used to be with info on how modern ddos protection and the sorts work
it's not being ddosed that's the issue, it's having people know your location (or, a relative area)
The burger king thing reference was honestly so funny
Honestly, discord should flag grabify links and give the user a warning that it’s a grabify link and to proceed with caution
finally, someone who understands that your ip getting stolen isn't a death sentence. its public information bro, its the first thing a website or video game server gets when you go to it most of the time
Thanks for the warning! I appreciate the information. Have a sub.
I always laugh at the "You're Location Is Exposed!" warnings, because ever since I changed ISPs, my IP address always shows me as being in Atlanta. That's not even in the right State.
6:21
Nice message
im not a moron :(
Hello, The Crazy Insanity.
Hello, The Crazy Insanity.
Hello, TheCrazyInsanity.
Hello, The Crazy Insanity.
Hello, The Crazy Insanity.
The Windows Security one reminded me of a false positive shenanigan audio I was exposed to on ROBLOX once, actually.
I don't think discord can remove the middle click, since it's just a website inside a wrapper and middle click is just "Open in new Tab". I wonder if the discord wrapper could intercept this.
truly a waste of space moment 0:52
i bet you gun spam smh
Indeed
@@thecrazyinsanity i bet i only made one experimental model which can be classified as gunspam
Gunspam? Warhead grid
@@rockets-space cap
Useful shortcuts:
Ctrl + Left Click = opens link on a new tab (same as middle click)
Ctrl + W = closes current tab (same as middle click on the tab)
Ctrl + Shift + T = reopens a closed tab
Ctrl + Tab = next tab
Ctrl + Shift + Tab = previous tab
Ctrl + Shift + B = hides/shows favorites, useful for minimizing distractions
Ctrl + F4 can be used to close your current tab too
NTTS is the only youtuber i can watch with BUG reports and stuff.
If Discord makes it so the warning popup appears on middle-click, then opening the media will still switch you to that new tab, unless you can middle click the confirm button. But after that you could simply trust the domain and not have to worry about that either.
0:11 THATS MY GIF!! IT SAYS MY USERNAME ON IT LOOOOOOL (I am tootaly the real artist I toootallly didnt just upload it)
nice
How do you get it redirect to a different website
I want to know too
as a person whose middle mouse click is broken. I see this as an absolute win.
W
I did not expect to see big buff tf2 mercs in any of his videos
Discord could just leave the middle click functionality on links and add the popup on images. It should be possible by adding certain event listeners on images to trigger the popup and leaving the links alone but idk I've never tried it.
Yup there are a couple of events available for this to be possible. onauxclick and the regular onclick events seem to work just based on some googling
I know a guy in my discord that keeps doing that i swear
Edit: watched the video and it's actually him
hello, thecrazyinsanity
Middle click for calculator was the nicest thing i've ever seen, it shortcuts you to a calculator.
that subways surfers got me dozed in 💀
6:00 im pretty sure you can use this to run steam games and even join a server with some older stuff.
Middle click to lan party.
yes you could, ty for the idea
but how tho
"Middle click for egirl" gotcha
Bro just pulled the greatest gamer reacts impression and didnt even noticed
The little stylus is such a good meme
7:27 and my 4 numbers were 0765 so difficult bwomp
Bwomp
Bwomp