Discord will switch to temporary file links to block malware delivery
bleepingcomputer.com
bleepingcomputer.com
It sucks for search engine indexing and it sucks for providing support for stuff because the conversation moves on before anybody who might help will see your query.
One simple solution to this would be a Discord bot that publishes a log of all messages in a channel to a website, thus making them indexable by Google. This used to be common practice for IRC channels and you'd sometimes find an answer to a programming question in the published logs of some IRC server.
Of course, an even better solution would be for Discord to offer this natively to server admins. Give them an option to make their channel indexable by search engines, and then mirror all the posts to a subdomain. It could even be a funnel for Discord since they could get new users to signup when they land on an answer and need to signup to ask a follow-up question. It could also be a wedge to compete more directly with Reddit.
Definitely more likely than someone actually complaining that the money furnace was burning money in a way that increases engagement, gives people something to stream, and gives people a reason to buy their premium subscription.
This just happens to not be the case for larger files. I bet they have tried to find a way to monetize the data harvested from user image associations or possibly image AI training already.
But I promise you this is a very prevalent problem, to the point where discord is blocked companh wide at some places because of this this issue.
This doesn't really change Discord away from being a free file hosting platform for anyone that gets the link on Discord. It just prevents someone from uploading a file to Discord and then sending a link to the file along a different medium (email/text/etc).
Hosting files really isn't that expensive given Discord's tiny file size limit and Discord's scale. Cloudflare's R2 charges $0.36/million downloads. The problem is that if you're hosting content on your domains, you have a certain responsibility for the files on those domains. Your domain gets a reputation and at a certain point starts appearing on lists (even if you're a multi-billion dollar company). People trying to spread malware love taking advantage of any place they can store a file on a reputable domain or get a reputable link shortener to redirect to them. I don't blame Discord for wanting to cut them off.
> After the file hosting change (described by Discord as authentication enforcement) rolls out later this year, all links to files uploaded to Discord servers will expire after 24 hours.
> CDN URLs will come with three new parameters that will add expiration timestamps and unique signatures that will remain valid until the links expire, preventing the use of Discord's CDN for permanent file hosting.
This seems like a pretty straight forward change?
"stateChanges": [
{
"state": "ACTIVE",
"date": "2022-01-19T04:47:37Z"
},
{
"state": "FALSE_POSITIVE",
"date": "2022-01-26T09:13:03Z"
},
{
"state": "ACTIVE",
"date": "2022-01-28T00:41:17Z"
}
]
Discord is responsible for handling reports about malicious content, so by shortening the lifetime of all content to 24 hours they're effectively giving themselves a 24-hour response SLA for free. It's a very reasonable move.Mozilla went through the same thing with Firefox Send and ended up discontinuing it altogether: https://support.mozilla.org/en-US/kb/what-happened-firefox-s....
I am on a very niche Discord for the Battletoads video game series. I'm a former world record co-holder of the 100% NES co-op category, so, big fan. :) We've been cataloguing and saving every bit of contemporary Battletoads materials we could find and archiving them in Discord: manuals, design materials, concept art, ads, magazine coverage. Snapshots of the franchise juggernaut that never was. I need to move that off Discord and store it somewhere so the whole world can see what we've unearthed here. Battletoads wanted to go real big but a series of unlucky events just never made it. I fear that the lukewarm reception to the latest 2020 game means the series will be dormant at least for another decade.
Right now I'm planning to systematically download all of the our archived materials off Discord, move them up to archive.org, and perhaps start a little page on neocities curating the archive and highlighting some interesting stuff, for example:
Battletoads costumes:
https://cdn.discordapp.com/attachments/829695119803285504/10...
Battletoads novel, written by Rare, as background lore:
https://cdn.discordapp.com/attachments/829695119803285504/10...
Design documents for some levels, suggesting that the Turbo Tunnel might have at one time been the belly of a beast and that's why it looks so organic:
https://cdn.discordapp.com/attachments/829695119803285504/82...
All of these links will be lost, like tears in the rain.
Of course there's ways around it as it is right now, as shown in NTTS' video, but it requires effort, which the general user won't bother with.
I can’t imagine what it must be like trying to get a foothold as a new image host these days, for example. Your free offering will be misused as soon as you get the smallest amount of traction, which then prompts you to lock it down, which then stymies growth that funnels into paid plans.
cdn.discordapp.com, if you see anything that isn't actually discord connecting to that domain in your corporate network then it's most likely malware.
Matter of fact, get your own open source stealer malware, github is curating a topic for it:
https://github.com/topics/discord-stealer
I gotta make an HN submission for this lol.
First thing it'll do is disable Windows Defender. Then run a base64 encoded script as a command line arg to powershell as a scheduled task. And so on. Telemetry is sent back to the c2 about what AV was installed, and if it finds itself running in a sandbox or VM it will immediately exit.
I haven't seen them using discord's CDN, but I'm sure some do. Redline seems to have a high amount of customization encouraged in its deployment. Each infection is a few megs of bandwidth, so if you're infection a lot of targets the bandwidth costs can be non trivial, hence using a CDN.
The recent discord change affects a different type of abuse though. The attackers upload their malware to discord and use the link to that attachment as part of the infection/dropper phase.
Let's say you get a phishing link, a social media post such as on facebook,linkedin,etc... or a search result on google, malvertising,etc... then that lets you download the desired content except it's an iso,archive, lnk,etc... you open it and the file in it. Little do you know that triggere the infection where powershell, wscript, csc or whatever else is downloading the malware using the discord permalink, if it is any good it will still need additional unpacking and decrypting before it either settles in its new home on your computer or if it is a stealer, it grabs your browser stored passwords (never use that or login to chrome/edge!!! Or mix work/personal accounts!!) , crypto wallets, api keys , interesting files such as config files, credit cards (again browsers lol) and more and posts that data archived using a webhook to the attackers channel/room and the malware will not even touch your disk before disappearing sometimes (reflective .net assembly loading, Thread injection,etc...)
If you have relatives who are not technical, either make them use macos or turn on defender with tamper protection and cloud delivered protection and make sure extensions and hidden files are visible by default. Also change the default file association for js,jse,vbs,vbe,iso,7z,rar,hta,bat,cmd and I am sure I am missing more to notepad.
You write:
>it grabs your browser stored passwords (never use that or login to chrome/edge!!! Or mix work/personal accounts!!)
I actually don't know a ton about the Windows permissions model. If the malware can already install a keylogger at this point, doesn't avoiding the use of stored passwords just delay the inevitable? (I guess installing a keylogger could cause it to be detected by antivirus software?) Also, in terms of mixing work and personal accounts -- it's not enough to use separate browsers, I'd have to use separate devices, correct?
What are reflective .net assembly loading & thread injection?
That's quite a list of file extensions! It seems like Windows is astonishingly willing to execute unwanted code. Like, I'm struggling to imagine why I'd be significantly worried about a downloaded .js file on Linux/macOS.
Browsers sync passwords. all the passwords you saved to everything get exposed to the malware. Most services you use regularly these days don't require frequent logins on the same device either. For example, you may only login to your school/work at a different pc but you sync passwords on the same google account because you also check your personal email there. Now any malware at any of those devices gets your saved password and payment info. Not to mention session cookies!
> I guess installing a keylogger could cause it to be detected by antivirus software?
Maybe, maybe not but the av might clean it up before it gets any creds keylogged. Part of the secuity model for password managers too.
> Also, in terms of mixing work and personal accounts -- it's not enough to use separate browsers, I'd have to use separate devices, correct?
Yes, and avoid allowing chrome and edge to sync stuff, it's very useful for attackers lol.
> What are reflective .net assembly loading & thread injection?
I am sure a google search would be better than me trying to explain those in depth here. Basically you can execute code in memory without having to store the code anywhere on disk, it helps with cheaper av that focus more on disk and registry than memory and api call hooking.
> Like, I'm struggling to imagine why I'd be significantly worried about a downloaded .js file on Linux/macOS.
On windows by default .js is not javascript but jscript, a native script langauge similar to javascript used a lot before powershell was a thing. The windows script host (wscript.exe) will attempt to execute any .js files you double click on by default
Do you:
A: kick them off your platform
B: turn that usage into a real paid product that meets demand
It's weird that people work so hard to come up with something that people want, and when it falls into their lap, it's seen as parasitic and killed.
This is just people hot linking things and using discord as a free file host. A product/problem that has existed for literally decades.
People wanting/using something for free does not mean you have a great business opportunity, in fact it's usually the opposite. To run a business you need someone to pay you for stuff.
You're saying the key thing here is leeching bandwidth.
You'll still see old files.
This news that I shared is now official of course.
Is this the first big move to push people off the web onto the desktop/mobile client where they have much more potential to invade privacy?
I'm sure one of the reasons they operate purely as a discord bot is to save $$$ on hosting and bandwidth
I think it's extremely unlikely this is aimed at midjourney or will affect them negatively. Most of their bandwidth will still happen over discord where users see the images generated to begin with.
The way inpainting in midjourney works is you click "remix region" on the message where the bot posted the generation and UI pops up that lets you select regions of the images, with two different types of shape selector, a rectangle selection tool and a curve selection tool. You send your message back to the bot, which includes those regions, and it only redraws those regions.
What I don’t understand is why Discord still wants to allow temporary access outside their clients.
It's every type of file, including images that are affected.