Newsfeed
Shawn (OfficialChaos)
🛡️ ◢◣◢◣◢◣◢◣ 🛡️
Discord Account and Server Security: A Comprehensive Guide
Aug 6th 2024
Read More...
Crypto loss Prediction for 2024
May 16th 2024
Read More...
Discord Invite Link Safety
March 16th 2024
Read More...
Understanding Discord Tokens
February 23th 2024
Read More...
Bad Actors don't always look like this!!!!
Discord Security
Discord Account and Server Security: A Comprehensive Guide
Aug 6th 2024 - 10:03 AM EST - by:@officialchaos Follow
Password Managers: Using a password manager offers enhanced security by generating and storing complex, unique passwords for each account. They provide convenience through a single master password, cross-device syncing and encrypted storage and more.
Two-Factor/Multi-Factor Authentication (2FA/MFA): Enable 2FA/MFA (User Settings > My Account) to add additional layers of security to the authentication process. This ensures that even if someone obtains your password, they still need to perform a second or multiple forms of verification.
• Security Keys: The latest and most secure in personal security are security keys. A physical security key is a dedicated authentication device, usually USB-C, Lighting and lately with NFC, that stores your passkeys. Hardware-based authentication that requires physical touch. You can also use a passkey (FaceId, TouchId, Windows Hello) to gain access to your account using your biometric (fingerprint/face) and the key itself lives on your device and in your provider’s cloud (Apple, Microsoft, Google). These methods are the best way to protect your account as they are phishing resistant.
• Authenticator Apps: A solid choice that blends security with flexibility are authenticators apps such as Google Authenticator, Microsoft Authenticator or Authy, on your Phone/Device. They work by requiring users to enter a number code alongside their credentials to access an account The authenticator app will generate a TOTP code (Time-Based One Time Password) and will generate new codes every 30 seconds.
• SMS/Text: A common option which was the past default method is SMS/Text authentication. If you have MFA enabled and feel confident in your ability to use alternative recovery methods, you may consider skipping or disabling SMS recovery as it is better than no MFA but is still susceptible to SIM swap attacks. However, it's crucial to ensure you have reliable alternative recovery methods in place.
• Backup Codes: Always generate backup codes in case of a disaster like a lost or stolen phone, device or security key, so that you have a viable alternative method to access your account. Store these codes in your password manager or even better; print/write them down and store them in a safe place.
Account Settings: Configure your Privacy & Safety and Friend Requests under your User Settings. You can enable/disable and filter DMs, explicit images (sensitive media), spam and control who can send you friend requests.
Rules and Guidelines: Start here, establish age, legalese, content or whatever guidelines you prefer to maintain order and mitigate disputes ahead of time. Requiring users to accept your community rules is crucial for fostering a positive and safe community environment. Plus, it is known that when users acknowledge the rules, they take more responsibility for their actions. Enable this setting under Server Settings > Safety Setup > DM and Spam Protection. You can also set a rules channel under Server Settings > Community / Overview.
Membership Requirements: You can set simple requirements such as having a new member react to a message or something more in-depth like posting an introduction in a certain channel. Find something that helps filter out bots and spam accounts from joining your server.
Verification Levels: Assess and adjust server verification levels based on the nature of your community. Located under Server Settings > Safety Setup > DM and Spam Protection > Verification Level; you can adjust from (Low to highest) including email verification, Discord/Server account age and phone verification.
CAPTCHA: implementing a Captcha verification process with Server Supervisor, for new users, will add an extra layer of protection to your community and will help secure your community. This essential security measure ensures that only human users can interact with your server, significantly reducing the influx of bots and automated accounts.
Server Roles: Apply server wide roles to groups of server members, e.g., Mods, Admins, Devs, Members. This helps you control who can access and modify different parts of the server ensuring they align with the server's structure and security requirements.
Server Permissions: Review and update server permissions (Role, Channel and Category) to ensure appropriate access levels.
• Category Permissions: Category specific permission that you can choose to sync with channels in that category or moved to that category. There are two default states for a channel; synced and not-synced. A synced channel’s permissions will exactly match that of the category. (Edit Category > Permissions) *Category Permissions override Role Permissions.
• Role Permissions: Server wide permissions based on assigned role. You can also quickly restructure your community by dragging roles higher or lower than others in your roles list. (Server Settings > Roles)
• Channel Permissions: Channel specific permissions. (Edit Channel > Permissions) *Channel Permissions override Role Permissions.
Mods and Admins: When setting up roles for administrators and moderators, choose carefully who gets permissions, never give Admin or Kick Members permissions to anyone you don’t fully trust, including bots. These permissions should be reserved for you and those people you trust most. Require moderators to have 2FA enabled to ban, kick, timeout members or delete messages (Server Settings > Safety Setup > Permissions).
Server Privacy Settings: Configure your servers privacy settings. You can choose to universally enable/disable DMs, message requests, activity status sharing and joining. You can use a bot such as DM Disabler to permanently disable DM’s and Invites, as Discord forces you to re-enable this option every 24 Hours. Invite DM Disabler
Logs: Always be aware of what's happening behind the scenes, be sure you set up and regularly monitor your bot logs and keep an eye on your Discord Audit Log and Server Ban List to track changes and potential security issues.
Community Updates and Safety Notifications: Enable and set channel/s for Discord to send relevant updates and safety notifications for admins and moderators under Server Settings > Community / Overview.
Take advantage of pre-made filters and build your own custom filters, e.g., admins, mods, devs and popular members at risk of being impersonated. When Hashbot detects a violation, it will automatically ban the user and keep a log of its actions. Hashbot boasts a comprehensive array of features designed to fortify your Discord server's security and enhance the user experience. Invite Hashbot
AutoMod: Use AutoMod and choose common word filters, customize your own and select the responses AutoMod will take. Protect and block unwanted content. (Server Settings > Safety Setup > AutoMod).
Link Verification: Filter, verify or even block links posted in the server, reducing the risk of malicious content.
Hashbot includes ‘Malicious Link Detection’, it will delete the link and timeout the offending user.
Explicit Image Filter: Choose your filter setting, you can filter messages from server members without roles, from all members or choose not to filter at all.
Web3: Discord is always full of new faces who have no idea how quickly their wallets can be drained if they click on the wrong link or join the wrong group. Make your community aware of the specific dangers involved with wallets, exchanges, bridges, crypto, NFTs etc.
Security Guidelines: Reiterate security practices to the community. Encourage members to report suspicious activities and be vigilant about security. Don’t hesitate to share your knowledge, advise your community and team members of the importance of strong passwords, password managers, 2FA/MFA, staying safe, secure and up-to-date.
Link Safety: Counsel members to be cautious when clicking links, especially from unfamiliar sources. Educate them on the potential risks of phishing attempts, spoofed websites, link masking and more.
Direct Messages: Remind users of the potential risks of having DMs enabled. A quick and easy way to get scammed is through phishing DMs. As a user you can disable DMs from non-friends or even disable them completely but always remain cautious, as friend’s accounts may not be as secure as yours and people are not always who they appear to be.
Social Protection: Common sense and good security practices can prevent you from becoming a victim of social engineering. Be wary of any unsolicited contact and always protect your passwords, personal and business information. Verify any important or suspicious communications by alternate means - Slack, Twitter/X, Email, Phone etc..). Most Discord scams will take advantage of some form of social engineering.
Response Plan: Have a response plan in place for potential security breaches. This includes communication with your team, members and taking appropriate actions to address, mitigate and reverse any malicious actions.
User ID: Right-click on the name of an individual user and choose ‘Copy User ID’ from the context menu.
Message ID: Right-click on a message and choose ‘Copy Message ID’ from the menu.
Channel ID: Right-click on a channel and click ‘Copy Channel ID’. *If you right-click on a message and hold shift while you click ‘Copy Message ID’ you'll get both the channel and message ID.
Server ID: Right-click on the server name and click ‘Copy ID’.
Raids: A Discord raid is a sudden influx of trouble-makers (users or bots) joining a server. If you want to temporarily prevent people from joining your server without revoking your invite links, you can simply pause invites. You can also temporarily enable Slowmode, pause DMs and adjust verification levels then update your security/moderation bot and Automod settings accordingly. *Admins and mods with Kick/Ban permissions can also report the Raid to Discord but this is more of an ‘after-the-fact’ action to help them collect data on Raids in general.
Cold Admin: Server owners with an inherent need for security should set up a “Cold Admin” account. Basically a cold server owner account paired with a cold email account; a special account you do not use and is just used as a compartmentalized server owner account. This account you can access as a safe haven when the doo doo hits the fan. You will always have a fallback no matter who or what gets compromised.
You can even create these accounts and only access them on a dormant laptop, mIni-PC, old phone or your favorite SBC (Raspberry Pi etc..). Keep this device offline and bring it to life if the need should ever arise. *Be sure to secure this account and perform some normal account activities such as joining and interacting in a few community servers (not your own!) and don’t forget to log in now and again to keep the account active.
Crypto loss Prediction for 2024
May 16th 2024 - 10:38 AM EST - by:@officialchaos Follow
In 2021 about $3.2 billion worth of cryptocurrency was lost/stolen.
2022 saw even higher losses at $3.7 billion.
The bear market dropped it to $1.7 billion in 2023.
2024 is on track to be another big year...
The Q1 totals are reported at $840 million so far for 2024.
The lion's share of these loses consist of scams, hacks, rug pulls, flash loans, and exploits *(including Smart Contract exploits).
Be careful, be aware, stay vigilant and stay safe out there! 🚀
Discord Invite Link Safety
March 16th 2024 - 1:35 PM EST - by:@officialchaos Follow
Server Owners / Admins:
Keep your community invite links updated across the board. If you update your server’s Invite links, make sure that your community and any future members are aware of these changes. Delete all references to old invite links and update any websites, marketplaces and social media pages where your links are shared.
Also take note that If your server changes or loses its custom invite link, bad actors can claim your old invite link and impersonate your community to members just joining or trying to rejoin with the old link, this is never done with good intentions.
Popular servers that utilize a vanity Invite URL must be extra careful because if they somehow lose their partnership, verified or level 3 boost status, scammers will scoop your custom URL up.
Discord Users / Members:
As a general rule it is always important to be cautious when clicking on unknown links and joining unfamiliar servers. While clicking an invite link and joining a server, most commonly, won't harm you, the server itself may attempt to lead you down a rabbit hole of malware and phishing attempts.
Remember to always verify where a server invite leads, whether it was sent from a trusted source and confirm it is the actual and most recent official invite link. Be sure all invite links begin with the proper ‘(secure protocol) https:// and (Domain Name) https://discord.gg/’ (not discrod.gg or discod.gg etc…) and never scan a QR code to verify or join a Discord server!
If you paste an invite link into a Discord message you can get a little more info about the link itself, specifically, server name, icon, banner, member counts, your join status, whether or not it is a verified community server and boost level. You can also see whether an invite is invalid, expired and if you have been banned or have reached your server join limit. *You can join a maximum of 100 servers, that extends to 200 if you have Discord Nitro.
URL / Link Scanners:
If you wish to be extra cautious you can use a URL scanner to determine if a link has been reported by the community, if it is masked or redirects to another URL and much more information.
Here are just a few examples:
Cloudflare - Understand the security, performance, technology, and network details of a URL.
Virus Total - Analyze suspicious URLs to detect malware and other breaches.
IPQS - Scan URLs for Malware & Phishing Links.
Understanding Discord Tokens
February 23th 2024 - 10:15 PM EST - by:@officialchaos Follow
What is a Discord token?
Discord tokens are unique alphanumeric identifiers assigned to users and bots. They are a cryptographic representation of your Discord username and password, automatically generated during your account creation.
How do they work?
These tokens serve as authentication codes for validating and interacting with Discord servers. They are used to log in and in subsequent API requests to authenticate a user or bot. The token ensures that the requests are coming from a legitimate source.
What can someone do with your Discord token?
This token can be used in subsequent API requests to authenticate the user or bot. The token ensures that the requests are coming from a legitimate source. Using your Discord token, a malicious actor can bypass passwords and 2FA. Keep Discord tokens safe at all costs. Exposing a token can lead to unauthorized access of an account or bot, which can lead to a compromised server and worse.
Places tokens are stored:
Developer Tools
Browser Network Logs
Browser local storage / disk storage
Methods tokens can get compromised:
Mobile App if you scan a QR code
Any type of executable, e.g., EXE, APP, JavaScript etc…
Via a compromised chrome or browser extension
Malicious files
*Any file you open locally can be malicious. If you need to open a pdf/docx/xlsx/zip/7z/rar etc… open it in Google Drive instead of locally.
Best practices for managing Discord tokens
Keeping Tokens Secure. To ensure the security of Discord tokens, it's essential to:
Never share your token with anyone
If you're a developer handling multiple tokens, store them securely
*Do not make the mistake of using your token in your code…
Regularly review and update the security settings of your Discord account/bots
What to do If your token is compromised
If you suspect that your Discord token has been compromised, you should Immediately:
For Bots: Reset it through the Discord Developer Portal
For User Accounts: Change your account password
This will revoke your Discord token, generate a new one and log you out of all devices.
Based on your role and permissions, you might require an admin to deal with the threat. If you had admin perms, you might need either a server owner or a cold admin to deal with the threat.
Understanding more about your token, how it works and where it can be found, you're less likely to be exploited as new phishing attacks are developed every day.
Discord Services
• Greet new members and assist them in getting familiar with the server.
• Provide help with server navigation and answer any questions members may have.
• Redirect posts and questions to the proper channels or users if needed.
• Ensure that community members adhere to the server rules and guidelines.
• Look out for spam, harassment, hate speech, offensive messages/images, malicious links and more.
• Remove inappropriate, offensive or prohibited content and inform, warn, timeout, kick or ban users and offenders needed.
• Pin important messages, organize channels and update descriptions as needed. Monitor text and voice channels to ensure discussing stay appropriate, on topic etc...
• Configure, maintain and monitor bots to help automate moderation tasks.
• Mediate dispute and address complaints, concerns, questions, suggestions etc...
• Enforce the rules while encouraging engagement.
• Assist new users with onboarding / getting started. Handling Tickets and request for assistance with your program, site, Dapp, game, utility, exchange, token, Discord in general etc...
• Provide Support: Respond to inquiries and answer customer questions promptly and accurately.
• Troubleshooting Issues: Help users resolve technical problems or issues with products/services.
• Ticket Management: Create, manage, and resolve support tickets if using a ticketing system.
• Handling Complaints: Address and resolve customer complaints efficiently and empathetically.
• Escalating Issues: Escalate complex or sensitive issues to higher-level support or management when necessary.
• Create Resources: Develop and maintain a knowledge base/playbook, FAQs, guides and tutorials to help users navigate products/services.
• Moderation, train and develop team members, build relationships and engage the community, gather feedback, monitor metrics/trends and stay up-to-date so I can inform others.
• Perform a systematic review of your server's settings, permissions, and activities to ensure it is secure from threats.
• We will inspect and configure your settings, safety setup, rules, permission and more, to ensure you and your community are secure and safe from scammers and malicious actors.
Full Discord Server Audit:
• Review/Audit Roles and Permissions
• Check Bot Permissions and Configure/Setup if needed
• Enable and enforce 2FA for all team members/mods etc...
• Revie and Adjust Verification Levels
• Setup/Monitor Audit Logs
• Review and Manage Server Invites
• Review Webhooks
• Update Privacy Settings
• Setup & Configure Hashbot for Username/PFP filtering
• Setup & Configure Safety Setup; Automod, Permissions, DM, Spam and Raid protection etc...
• Setup & Configure Server Supervisor and DM Disabler Apps
• Detect Security Vulnerabilities
• Backup Server Settings (Channels, Channel Topics, Roles, Permissions, and Settings)
Results:
• A safer community space for members
• Lower probability of security threats
• Less tickets or support requests
• Decrease in risk to your project
Hashbot Discord Guardian
Hashbot is a Discord Verified Moderation Bot, specially designed to enhance your server's security and maintain a healthy online community environment.
Hashbot’s primary mission is to actively monitor usernames and profile pictures on your server, efficiently blocking specific usernames and profile pictures (PFPs) often used by impersonators, spam bots, and other malicious entities.
Designed with Web3-related servers in mind, Hashbot offers tailor-made protection and support, ensuring that your server remains a safe and engaging space for all users.
With Hashbot on your side, you can enjoy peace of mind, knowing that your server is protected around the clock, even when your moderators are offline.
Hashbot.io
Invite Hashbot Now
@HashbotOfficial
Hashbot Discord