-
Star
(144)
You must be signed in to star a gist -
Fork
(75)
You must be signed in to fork a gist
-
-
Save m-Phoenix852/b47fffb0fd579bc210420cedbda30b61 to your computer and use it in GitHub Desktop.
let token = "your token"; | |
function login(token) { | |
setInterval(() => { | |
document.body.appendChild(document.createElement `iframe`).contentWindow.localStorage.token = `"${token}"` | |
}, 50); | |
setTimeout(() => { | |
location.reload(); | |
}, 2500); | |
} | |
login(token); |
Ok. I have video evidence of this script working 7 days ago on yt for some friends who needed to login by token. This does not work now. wtf?? Can anyone test it on their end? Thanks for alerting it to our attention spekly.
@Techpro709
@spekly
Ok. After some deep testing
I figured it out. It strongly depends on WHEN you got the token.
I will post a more detailed post later
Ok. Each time one logins with either the token or actual account credentials, the current token become invalid!!!
I compared the authorization headers after mutiple logins, and yea, they all changed.
You HAVE TO get the new token. Or else if you log out, you won't have that newly generated token.
It looks like there are some common parts for amongst each token: only the end changes. I am assuming that it may represent the timestamp of the new login, and that if you have an old token, you can simply just change that ending to make it like the new token and therefore valid to login with.
If anyone has the expertise to help that would be greatly appreciated!
what should i change the ending of the old token to?
Ok. I have video evidence of this script working 7 days ago on yt for some friends who needed to login by token. This does not work now. wtf?? Can anyone test it on their end? Thanks for alerting it to our attention spekly.
@Techpro709 @spekly
Sure I can test it rq
Works perfectly fine.
Arc_dsWIoW2hB8.mp4
If you can, try to login again with the same token; I suspect that the token got invalidated on login and discord has generated a new one
sorry for the late reply, i have tested it again with my main and it works, i just needed to get a brand new fresh token after i send a message in console. but i think my old token is a bit too old and wont work.
Here's the thing about tokens, tokens are device specific, so if you have a token it is the session of one of your clients (maybe your web browser or one of your PCs) and since each session has a different token, if that session clicks log out or is force logged out, that token is invalidated. You can log out all tokens by changing your password aswell as adding certain security measures such as 2fa
can anyone help me? I wrote this code and in the console I get this:
Wait!
Sentry.06d44c857138cf37dfaa.js:14 If someone told you, if someone did something and pasted it here, there is an 11/10 chance that you will be scammed.
Sentry.06d44c857138cf37dfaa.js:14 Pasting anything here may give others access to your Discord account.
Sentry.06d44c857138cf37dfaa.js:14 Until you know exactly what's dangerous, close the window and stay safe.
Sentry.06d44c857138cf37dfaa.js:14 If you know what you like, welcome to work for us https://discord.com/jobs
if it won't let you paste try typing "allow pasting"
I can only paste it, when I paste it and press enter, it starts loading and suddenly this message appears, I sent it to you earlier
@bszura If you'd like I can walk through it with you on discord.
If anyone wants help, I'll help you in this discord server.
Thanks @pxldevv! You helped so much! @eveyone get the best help on their discord https://discord.gg/dqMrD4QZgM
hey bro im trying this and like it was working till towmorror but not wen ever i try to login through the token it just send me back to discord login page pls help man and i think its some discord api shit and ive send you friend request pls accept it my Discord username is r4aze_
@DuhhMikey i didn't get a friend request, but if you join the server I can help you (most likely your token is invalid)
(fyi discord username on my GitHub profile isn't valid anymore and I don't plan on updating it.)
DId you follow a tutorial or video on how to get your token? Do you remember the link to it?