I managed to gaslight a Discord bot into giving me it's password, but it works on more than one bot...
BotGhost, a website meant for beginners to make their own Discord bots, has a vulnerability and it affects a ton of bots on their platform. Bug hunters exploited a couple of smaller vulnerabilities which combined together resulted in this big Discord bot exploit.
DISCLAIMER FOR YOUTUBE EMPLOYEE: This is NOT a hacking tutorial, it's a retrospective on how the bot got hacked. Vulnerabilities are patched and have been disclosed to BotGhost :) And the bots shown in the video are my own bots.
SOCIALS
-----------------------------------------------------------------------------
Discord Server
https://discord.gg/ntts
Twitter
https://twitter.com/notexttospeech
TIMESTAMPS
-----------------------------------------------------------------------------
00:00 - Not just one Discord Bot
00:46 - It starts with a Simple Scam
04:03 - It got worse...
06:41 - THE MAIN EXPLOIT 9000
12:18 - That's a lot of Bots
14:16 - That's a lot of Damage
14:42 - BotGhost Responded...
15:55 - Turn left on Disappointment st.
17:47 - Avoid this?
18:46 - I'm 100% stupid
19:49 - A sorta happy ending?