DO NOT Join This Minecraft Server…

Поділитися
Вставка
  • Опубліковано 2 тра 2024
  • A new and dangerous method of minecraft account phishing has recently come to my attention, something I've never seen before in my 11 year of playing minecraft...
    Thanks for watching! Subscribe and Join My Discord!
    Discord - / discord
    Twitter - / themisterepicyt
    Twitch - / themisterepicyt
    Join my OG Minecraft Server, The OG Network! (1.8-1.20): og-network.net
    - Website: og-network.net
    - Discord: / discord
    0:00 - Intro
    0:42 - The Dangerous Server
    3:01 - A Shady Website
    5:06 - The Truth Revealed
    7:22 - Why It’s So Dangerous
    8:32 - But Why?
    9:49 - Can You Get Your Account Back?
    Music Used:
    1. Scott Buckley - Into the Unknown
    2. DBadger - Drop ( • Beats You Can Only Lis... )
    3. Scott Buckley - Catalyst
    4. Scott Buckley - Signal to Noise
    If there is any content in this video which you own and would like removed, than please contact me and I will be happy to oblige.
    #minecraft #minecraftserver #minecraftsurvival
  • Ігри

КОМЕНТАРІ • 863

  • @TheMisterEpic
    @TheMisterEpic  9 місяців тому +231

    Let me know if you've ever seen any other servers like this before! And make sure to subscribe!
    Join my discord - discord.gg/WGc9UNM

  • @SeizureSalad
    @SeizureSalad 9 місяців тому +2551

    pretty ironic how migrating accounts was supposed to be for security but instead opened a new can of worms with microsoft oauth login permissions

    • @AverageKaijuGamer
      @AverageKaijuGamer 9 місяців тому +94

      then the log4shell exploit happened 2 weeks after migration this Microsoft account migration has done more harm than good.

    • @JavaJumper
      @JavaJumper 9 місяців тому +201

      ​@@AverageKaijuGamerlog4shell exploit is unrelated to Microsoft account migration

    • @StuffandThings_
      @StuffandThings_ 9 місяців тому +159

      I mean "safety" was never the point, it was about Micro$oft exerting more control and their policy of "embrace, extend, extinguish." Probably meant to force any Linux players of Minecraft to make a Micro$oft account and to make chat reporting easier. Security is the tried and true excuse for stuff like this.

    • @kuching.sniper2792
      @kuching.sniper2792 9 місяців тому

      Suck

    • @RunicSigils
      @RunicSigils 9 місяців тому +5

      Having multiple accounts is and always will be more secure unless you're a brainlet who uses the same password on everything.
      It was never for your security, it was always just to bump MS account numbers.
      Convenience, freedom, and security are interconnected and getting more of one means getting less of both of the others.

  • @SemiHypercube
    @SemiHypercube 9 місяців тому +1228

    Never knew that phishing of Minecraft accounts could be done this way, though honestly with a name and server domain like that it's so obviously shady

    • @Tigery760
      @Tigery760 9 місяців тому +24

      This can easily go past minecraft, many games even on steam could use something similar. This is a very scary thing to deal with and just know is out there.

    • @jayemover_16
      @jayemover_16 9 місяців тому +15

      Anyone who trusts that kind of name is a certified internet noob

    • @ashleybyrd2015
      @ashleybyrd2015 9 місяців тому +21

      @@jayemover_16 On a game with a primary audience of children that's to be expected and something we should take into consideration rather than make fun of.
      You were an internet noob too once, don't be elitist just because you can spot a phishing scam.

    • @Proferk
      @Proferk 9 місяців тому

      what do you fucking mean? this is nothing new. It's just that the phishing scam is doing in minecraft instead of some scam youtube bot or discord

    • @Zylcel
      @Zylcel 9 місяців тому +1

      Everywhere I go, I see his face.

  • @Dolphin002
    @Dolphin002 9 місяців тому +460

    This is entirely Microsoft's fault. Their wording is vague ("This does not give xyz any additional permissions"?) and there's no warnings or confirmations.

    • @maxrburgess
      @maxrburgess 9 місяців тому +25

      Absolutely, it’s nuts that it doesn’t say it includes access to your MS account! Edit: Access to your Xbox account

    • @not-underscore
      @not-underscore 9 місяців тому +18

      Yeah, there's a reason why discord/google give you the scope of the app you're allowing access to, and that's to verify the permissions that the app would have. Nothing other than what's included in that scope is accessible by the app. But yeah, it seems that M$ gives full access to your account without even telling you. 🤦‍♂️

  • @Deniz3n
    @Deniz3n 9 місяців тому +394

    If that MS login permissions list is correct, that's 100% Microsoft's fault - they're giving the app access way out of the scope of what it says it is giving

    • @WalkingBrainTheMathNerd
      @WalkingBrainTheMathNerd 9 місяців тому +1

      no, they just don't tell u what it is

    • @tiggerbiggo
      @tiggerbiggo 9 місяців тому

      @@WalkingBrainTheMathNerdare you stupid or did you just not read? Or both.

    • @dagdnoob
      @dagdnoob 9 місяців тому +31

      ​@@WalkingBrainTheMathNerdThats what he said

    • @WalkingBrainTheMathNerd
      @WalkingBrainTheMathNerd 9 місяців тому

      @@dagdnoob true, I kinda misunderstood it

    • @Theunicorn2012
      @Theunicorn2012 Місяць тому

      If the MS login permissions list is correct, that's 100% Microsoft's fault - they're giving the app access way out of the scope of what it says it is giving

  • @realryleu
    @realryleu 9 місяців тому +538

    this isn't an exploit, per se. it's entirely intended behavior, specifically made for 3rd party launchers. the issue here is that microsoft worded their warning poorly. it should make it very obvious that you're HANDING OVER ACCOUNT ACCESS.

    • @venturoes1912
      @venturoes1912 9 місяців тому +1

      Exactly this, just look at how Xiaomi designed their UI for allowing third party downloads on their phones, just google "xiaomi dangerous permission screen"
      Unlike Microsoft, Xiaomi decided to add a red warning triangle, a wall of text that very clearly tells you that you would be at risk allowing this, explained in a very clear tone that even a grandma or kid could understand and finally, there is a 10 second cooldown before you can even proceed, after pressing a separate checkbox.

    • @motherchuckair404
      @motherchuckair404 9 місяців тому +2

      if its open source and can be community peer-reviewed and audited, this is technically not the case.
      you also need great op-sec to browse the internet these days

    • @fireworkstarter
      @fireworkstarter 9 місяців тому +5

      maybe handing over access to an account isnt that good? how about some diffrent kinds of rights for apps so that they cant just hyjack it afterwards

    • @venturoes1912
      @venturoes1912 9 місяців тому +9

      @@fireworkstarter It's not account access, rather it just lets it generate login tokens, aka it can only let it join servers with your name.
      This is required for third party minecraft launchers, however as you can see it can easily be abused by scams

    • @mega_gamer93
      @mega_gamer93 9 місяців тому

      @@fireworkstarter there are other kinds of account access, it's just that piglinbrute requested authentication tokens and people got phised into giving them to them

  • @Faustch..
    @Faustch.. 9 місяців тому +164

    Never thought i'd see the day where some Minecraft servers use the same scam methods as PH ads 💀

  • @guncolony
    @guncolony 9 місяців тому +451

    Wow this is a shame, I was actually planning to develop a legitimate Minecraft linking system through Microsoft login, but the fact that Microsoft is giving entire account access to sites you sign into makes that idea impossible without feeling like a red flag to players.

    • @wojtekpolska1013
      @wojtekpolska1013 9 місяців тому +32

      just make sure to set up the permissions correctly, you probsbly only rly need the player ID from the account for most purposes

    • @gerobi1233
      @gerobi1233 9 місяців тому +36

      make it open source and you're good

    • @tartas1995
      @tartas1995 9 місяців тому +4

      Why would you need to link it though? How and why does it add anything to anything?

    • @JohnDoe-sg1qb
      @JohnDoe-sg1qb 9 місяців тому +5

      @@tartas1995 microsoft makes sure that sensitive actions (like oauthing applications) couldn't be done by robots

    • @mo-s-
      @mo-s- 9 місяців тому +1

      What do you mean by "linking system"? It sounds interesting

  • @guedosha
    @guedosha 9 місяців тому +278

    Mojang: We are forcing people to migrate to Microsoft accounts for better security
    Meanwhile the better security:

    • @N0TAN1M3
      @N0TAN1M3 9 місяців тому +9

      no security?

    • @309electronics5
      @309electronics5 9 місяців тому +5

      Microsoft was probably the one who told Mojang to do it so microsoft themselves made the attack surface of the game bigger causing more hackers

    • @sus-ft3vu
      @sus-ft3vu 9 місяців тому

      @@309electronics5 but mojang is microsot

    • @KiraSlith
      @KiraSlith 9 місяців тому

      It's wild to think that every change Microsoft has made to Minecraft has proven to be not only worthless, but actively destructive to Minecraft from every possible angle. Just wait until you hear about what they did to their EULA terms yesterday, they basically gave themselves permission to kill peoples' entire Microsoft accounts if they post unfavorable videos like the above, as well as reversing the old trademark use terms Notch setup, making anyone using the word "minecraft" in anything's title the "wrong way" a criminal overnight. 🤬

    • @PaxTheCat
      @PaxTheCat 8 місяців тому

      "free rectangle and bugrock/yava"

  • @StuffandThings_
    @StuffandThings_ 9 місяців тому +339

    Its kind of amazing how messed up the Minecraft multiplayer ecosystem has become. Very, very few servers are fun, safe, and have a good community these days.

    • @keagaming9837
      @keagaming9837 9 місяців тому +6

      I know of servers that are still safe, but yes they are getting rarer and rarer these days. :(

    • @friedrichhayek4862
      @friedrichhayek4862 9 місяців тому +4

      userbase*

    • @DeafEars5723
      @DeafEars5723 9 місяців тому +2

      Singleplayer mode

    • @StuffandThings_
      @StuffandThings_ 9 місяців тому +9

      @@DeafEars5723 For real, singleplayer is becoming the only viable option. But it gets kind of boring after a while, after all sharing the results of your work is part of the fun, as is hanging out with friends.

    • @DeafEars5723
      @DeafEars5723 9 місяців тому

      @@StuffandThings_ I started playing Minecraft by mining on singleplayer, and my last play through will be mining on singleplayer, multiplayer is just such a huge risk to your account, and is only fun when you’re actually good at the mini games

  • @NationalGamer24x
    @NationalGamer24x 9 місяців тому +546

    2b2t players: Definitely a Popbob thing.

    • @thedrunkenknight
      @thedrunkenknight 9 місяців тому +29

      Watch it be actually popbob

    • @Akira__743
      @Akira__743 9 місяців тому +30

      Popbob is a girl 🤫

    • @zoes32flavaz
      @zoes32flavaz 9 місяців тому +3

      69 likes on this comment

    • @VRavTech
      @VRavTech 9 місяців тому +27

      The popbob sex account duplication glitch

    • @norcobick
      @norcobick 9 місяців тому +1

      what the heck is a popbob

  • @mwtb7309
    @mwtb7309 9 місяців тому +160

    I accidentally got ratted on skyblock yesterday so thank you for bringing this to light so nobody else suffers the same mistakes

    • @kingacrisius
      @kingacrisius 9 місяців тому +7

      How tf did you manage that

    • @100Create
      @100Create 9 місяців тому +14

      ​@kingacrisius he verified a "hypixel" bot to his Microsoft, same as me which just takes ur acc, I recovered my stuff and acc but many cant

    • @lilnasnusnus7867
      @lilnasnusnus7867 9 місяців тому +3

      Same bro I got ratted a few days ago too cause Microsoft gives zero shits about random websites and so on havin full access to your account

    • @pierrotA
      @pierrotA 9 місяців тому +5

      Sorry for you and all the others. Grinding for years and losing everything is never funny.
      Personnally I simply stopped playing minecraft because I refuse to link it to a microsoft account, especially because I mainly play solo and I see no reason at all to do it.
      But even if I understand that few people want to go to that extreme, I cannot understand why people still accept to give so much access to any games/apps they download.
      If you download a game or an app (mobile or PC) that ask you to give a ton of permission that are not necessary, it's *always* to sell your informations and/or to do shady things with them.
      I hope that someday people will massively say NO and switch to an other game (or an other server) each time they need to give away all their data for no reason, but I know it's not for tomorrow.
      The worst is on mobile, when some people give all the permissions (camera, memory, account,...) to games they do not know...

    • @slicepie410
      @slicepie410 9 місяців тому

      ​​​@@lilnasnusnus7867​​ maybe you shouldn't give access to your entire account to these random websites yourself.
      You live am you learn. Blaming microsoft for what is essentially a mistake on your part will not fix anything
      What microsoft could've done is not make it so vague. "Allow app to see and update the data you give it access to" doesn't *really* explain what data exactly.
      Either way, letting an app modify data on your behalf is already suspicious

  • @shyshsh
    @shyshsh 9 місяців тому +71

    1:37 the "checking physics" thing actually does make sense, bot accounts usually emulate the java edition client instead of actually using it (to save resources and for flexibility), meaning they have to properly emulate the players physics too. it can check if your player falls, and if your player doesnt fall or falls in a way that doesnt seem legit, it can flag you based off of that (obviously this server has been rigged to flag everyone, but thats certainly a normal check)

  • @FilthyCasual268
    @FilthyCasual268 9 місяців тому +39

    This happens so often in both games and social media accounts. Thank you for calling it what it is when so many people want to call it "hacking". It's not hacking, it's "account theft".

    • @TristanY_
      @TristanY_ 9 місяців тому +3

      Yeah, hacking is more of things like DDoS attacks, hacking into websites, and other things. Also video game "hacking" is actually exploiting, as they are exploiting vulnerabilities in the game's code.

    • @road__house
      @road__house 9 місяців тому +1

      ​@@TristanY_A very surprising majority of people don't know the difference between exploiting and hacking. Its kinda sad

    • @LilacMonarch
      @LilacMonarch 9 місяців тому +1

      ​@@road__housePeople call leaving their twitter logged in on their friend's computer and that friend making a troll post getting "hacked" it's so dumb

  • @wonghy1115
    @wonghy1115 9 місяців тому +44

    And this only possible due to the account migration… ahhh thanks again Microsoft. We all knew this would happen…

  • @Chloroxite
    @Chloroxite 9 місяців тому +11

    I love how when someone discovers a new account stealing exploit it *always* comes down to them tricking you into giving up account details yourself. The pattern is there people, be wary of it.

    • @caustictoad
      @caustictoad 9 місяців тому

      Yeah lol. Joining the server yourself doesn't do nothing.
      Only if you enter your own credentials, - then something will happen.

  • @Gildfesh
    @Gildfesh 9 місяців тому +18

    Thank you for covering this. I have been pushing for this to be sorted out for a very long time. There are so many solutions and yet no department in Microsoft seems interested in doing anything.

  • @sulembape695
    @sulembape695 9 місяців тому +5

    3:29 we have to thank that one policeman from Scotland for taking down the site

  • @swellestorc975
    @swellestorc975 9 місяців тому +11

    5:16 NOOOOOO!!! Hot Minecraft Girls Are Not Waiting For Me!

  • @JPmagicMC
    @JPmagicMC 9 місяців тому +17

    Legend says the policeman from Scotland was actually inspector gadget all along!

  • @mu11668B
    @mu11668B 9 місяців тому +12

    I like how Microsoft was making glorious claims about their authentication system outperforming Mojang's Yggdrasil and yet ended up here.

  • @MisterPancake778
    @MisterPancake778 9 місяців тому +14

    I love the hoops people are going through just to steal some kids' virtual lego account, that virus that was on Curseforge was was impressive for how elaborate it was, im sure the same happens on Roblox as well.

    • @TristanY_
      @TristanY_ 9 місяців тому

      roblox is far more simple, you google "free robux" and you find a pdf file hacked onto a dentist's website that contains a link to a phishing website

    • @SoftisNelaris
      @SoftisNelaris 9 місяців тому +1

      If I'm understanding things correctly, they're not just stealing Minecraft. They're getting into peoples' *Microsoft* accounts which will include any personal or payment info associated.

    • @MisterPancake778
      @MisterPancake778 9 місяців тому

      @@SoftisNelaris Yeah and the entry point is some lego game a bored swede came up with one day, since so many kids play it and arent educated on online saftey regarding phishing scams it creates a hotbed for malicious people trying to steal their info.

    • @TristanY_
      @TristanY_ 9 місяців тому +2

      @@SoftisNelaris Yeah and Roblox has your stuff stored but censored. Although, if you have 5,000 robux (Or maybe more? I don't remember) and you make games for the platform, you can cash out your robux for real money (At the rate of a free money mobile game basically, so not much money, but it's still money that they can take from you). So all they have to do is gain access to someone who has millions of robux, then change the credit card associated with the account, then cash out.

  • @wojtekpolska1013
    @wojtekpolska1013 9 місяців тому +12

    you need to be really wary of these micosoft login screens if they say *anything* more than just accessing your player ID.
    when multimc asked for similar permissions i had to research it for a couple minutes to make sure i trust them. and i would definitely not give such trust to a random mc server

  • @KatOnline
    @KatOnline 9 місяців тому +9

    This reminded me of this crazy situation that happened on skittlemc where players were getting doxed because of a leak or something not sure of the whole story because I was gone during that time. Microsoft shut them down for almost a year for not following certain guidelines. They made a lot of changes in the server to make more acceptable. It also lost alot of the playerbase it once had. I think I accidentally spoke to the doxer who helped me find a job exploit to earn emoney on the server. He later blocked me on discord and he hid his past names on namemc and went off into the unknown somewhere. He was perm banned but they unwhitelisted him then whitelisted him back.

    • @quantdev
      @quantdev 9 місяців тому +3

      the IP leaking is probably because of Minecraft literally printing your ip in the server console when you join, which is really stupid

    • @KatOnline
      @KatOnline 9 місяців тому

      @@quantdev Yeah it is really stupid.
      I questioned whether I should use a VPN, but I'm worried Microsoft would terminate my account. They've been known for freaking out about people going on their account in different ip locations because they don't permit selling or borrowing people's Minecraft accounts. I don't want them to take my VPN as some else using my account.
      Idk if a VPN now would matter anyway because they prob have my real ip stored somewhere.
      I don't care that much if the server admins know my location, I just worry about it getting leaked to everybody.

  • @mathgeniuszach
    @mathgeniuszach 9 місяців тому +34

    7:40 just a tip, you probably should put a black bar over sensitive information like your email there instead of blurring it out. It's possible to read out some of the characters manually (because of the screen movement) or via using an AI. A black bar is a bit more protective.

    • @sajeucettefoistunevaspasme
      @sajeucettefoistunevaspasme 9 місяців тому +1

      Although you can sometimes read it you just have to apply the mosaic then do the movement which soloves the problem
      and yes, some AIs can read through blurs but not through mosaic where information is lost

    • @mathgeniuszach
      @mathgeniuszach 9 місяців тому +8

      By "blur" I mean blur and mosaics. Some techniques can work through mosaics by applying the mosaic on guesses for letters until a best match is found. They aren't as safe as a black strip over data.

    • @schrenjaminsstift92
      @schrenjaminsstift92 9 місяців тому +3

      @@sajeucettefoistunevaspasme blur loses data aswell, but you can still see through it. Same with mosaic.

  • @Wo0Fly
    @Wo0Fly 9 місяців тому +52

    You know it’s a good day when mister epic uploads

    • @realredguy9999
      @realredguy9999 9 місяців тому +3

      yup

    • @leogaitsgorypiano8870
      @leogaitsgorypiano8870 9 місяців тому +5

      never heard that one before

    • @RidinWithMyLocsOn
      @RidinWithMyLocsOn 9 місяців тому

      it all seems fake though, the document is full on trolling and he throws it out there like its real lol

  • @XanCraft21
    @XanCraft21 9 місяців тому +59

    Man if only there were people smart and brave enough to take out the server at the source in person, maybe some of this stuff will never happen. Thank you for warning us about this.

  • @privexinc3022
    @privexinc3022 9 місяців тому +20

    We’re the server host features in this video and may have been in the thumbnail for a while, we’ve since taken both servers down - the Minecraft server and the strange phishing site itself - note we have zero control over the domains but were the host of the servers 🥲
    We were only informed of this phishing Minecraft server today after the video was released, we would’ve appreciated being alerted before releasing the video, but at least it’s taken down now 😅
    We do not tolerate abusive services such as phishing, malware, hacking (without ethical hacker / security research credentials), etc.
    We never expected to end up featured by a 600k sub Minecraft UA-camr, but we at least appreciate that you didn’t place the blame entirely on ourselves 😅
    ~SG123 - CEO @ Privex ❤️

    • @SupersuMC
      @SupersuMC 9 місяців тому +4

      True Chads right here.

  • @eurofeature
    @eurofeature 9 місяців тому +44

    This is a very important issue, and I'm thankful you are making the general community aware of it. Some skyblock youtubers have already made a video on this topic a while back, but even hypixel skyblock is small compared to the rest of minecraft, and I don't think you share a lot of viewers with it.
    MIGRATION promissed better SECURITY, but all we got is new ways of exploitation.

    • @WalkingBrainTheMathNerd
      @WalkingBrainTheMathNerd 9 місяців тому

      true, as before the only ways to steal accounts before was through mods and blatant login pages, both not so effective. I have been oath ratted nearly 3 weeks ago, when I joined a discord server for a guild I was in

    • @piebit101
      @piebit101 9 місяців тому

      😢חבי ‏‪0:39‬‏ 😢חהבחבנב😢

  • @blademasterzero
    @blademasterzero 9 місяців тому +5

    Every single time I see something like this I’m expecting it to be something like “just logging on and nothing else can put you at risk” instead of a variation on the same old “oops put my password and information into the shady website and now it’s doing shady things!” Like I’m glad it’s always the latter but it always boils down to user gullibility

  • @qy9892
    @qy9892 8 місяців тому +3

    This is thankfully easy to avoid. It can be made more elaborate if went like: This server is modded, here's the modpack you need: ... Then you'll get a malicious mod, it can even go and say, don't forget to share this modpack with with your friends! Or you can make it better by actually letting the person in and require another player to access a feature, it'll attract more players duss more accounts to steal. So stay careful outhere giving credentials.

  • @rexgaming1248
    @rexgaming1248 8 місяців тому +2

    You clearly understand the OIDC authorization process. I liked how you made a clear distinction between access and refresh tokens. This kind of problem exists for all OIDC SSO technologies because people don't check what permissions they are allowing on their accounts. Nice vid

  • @noah_smw
    @noah_smw 9 місяців тому +5

    The checking physics thing is actually real on some servers. some clients tend to have physics modifications, for example meteor client where you for some reason take falldamage from 3 blocks instead of 4. this is an anticheat to detect if people are running certain cheats or certain clients. A good example is Purity Vanilla. It's an anarchy server where no cheats are allowed and this system there works so well that people are barely able to join with cheats on.

  • @Semirotta
    @Semirotta 9 місяців тому +5

    Funny thing is, the microsoft page where you change the permissions is "under maintenance" and has been for some time now.

  • @IceTank
    @IceTank 9 місяців тому +4

    You are actually lucky if they only steal the Minecraft account token. There is a similar phishing attack on discord. That one has the Microsoft authentication set up in a way where they can change your email and password to kick you out of your Microsoft account.

  • @J______b
    @J______b 9 місяців тому +2

    Something similar happened to me when I signed into steam through a fake login screen. With in 1 minute I lossed my account

  • @shadowshowz8060
    @shadowshowz8060 9 місяців тому +3

    I was almost a victim of something similar to this through a discord verification tool. It was only due to my experiences with these kinds of things that I had realized what I had done and immediately revoked access and secured my account. Somebody without the years of experience dealing with these things like I do would be none the wiser to this trick. Great video.

    • @auser1078
      @auser1078 9 місяців тому +3

      Holy shit. Ur the guy from spokes old civ events

  • @killmace
    @killmace 9 місяців тому +10

    Pretty much the same is happening in older CODs, the problem is that the servers are still directly hosted by Activision
    It's literally safer to play cod on modded clients other than the fact that they have anticheats & better servers in general

  • @electricindigoball1244
    @electricindigoball1244 9 місяців тому +15

    What makes this particularly ironic is that one of the reasons given for the migration of Minecraft accounts to Microsoft accounts was increased security. Instead this has increased the attack surface for people's MS accounts. At least back when Minecraft Java accounts were separate the damage was limited if your MC account was phished/hacked.

    • @Max128ping
      @Max128ping 8 місяців тому

      Technically it did. That just a side effect. It just matter of convenient and security.
      You guys seems fine having 1 steam account for several tens of MP games and your credit card. Yet annoyed when using a separate account for Ubisoft, EA or Epic, but they provide increase security by the fact it is separate from each other

  • @nyrowastaken
    @nyrowastaken 9 місяців тому +2

    Its sad to see, that mojang doesnt care about this issue..

  • @mindblowersgaming
    @mindblowersgaming 9 місяців тому +1

    I remember once i joined a discord server being advertised as a giveaway server, and It asked me to verify using this method. It looked so sketchy and I am now so glad that I didn't click verify.

  • @danflash8639
    @danflash8639 9 місяців тому +3

    “Join out of curiosity” 8:04

  • @HumanPersonThing-yp1dn
    @HumanPersonThing-yp1dn 9 місяців тому +3

    Thanks to TheMisterEpic's videos about these scams, it has made me better at spotting them. Keep up the good work :)

  • @norcobick
    @norcobick 9 місяців тому +4

    "You can get no info" was so badass tbh

  • @Useott
    @Useott 9 місяців тому +3

    UA-cam buffering doesn't want to let me watch

  • @pikamonchampion
    @pikamonchampion 9 місяців тому +18

    As a cracked player i see this as a absolute win

    • @Akira__743
      @Akira__743 9 місяців тому +4

      Lmao

    • @matheuscarneiro899
      @matheuscarneiro899 9 місяців тому +1

      Holy🗿

    • @JavaJumper
      @JavaJumper 9 місяців тому +4

      As a player with more than 1 braincell i see this as a absolute win

    • @Kitulous
      @Kitulous 9 місяців тому

      same. been playing Minecraft since 2010 and never gave Microsoft/Mojang a dime

    • @nectabs8994
      @nectabs8994 9 місяців тому +3

      ​@@Kitulousi dont think thats a thing you should brag about.

  • @felixchen1796
    @felixchen1796 9 місяців тому +41

    A way to stop other people griefing servers that you play on can be asking the server owner to implement login security mods so you can only log in with a password.

    • @truerandomchannel
      @truerandomchannel 9 місяців тому +1

      or, hear me out, whitelist

    • @ashleybyrd2015
      @ashleybyrd2015 9 місяців тому +4

      @@truerandomchannel That wouldn't work here since the griefer in question would have access to your account, unless you used an IP whitelist I suppose.

    • @felixchen1796
      @felixchen1796 9 місяців тому +1

      @@truerandomchannel No I mean if somebody steals your account or you are sharing your account with a sibling or friend

    • @felixchen1796
      @felixchen1796 9 місяців тому +2

      @@ashleybyrd2015 The login security mod makes you log in with a password on the server that isnt saved to the server instead of your account and therefore they wont be able to access the password.

    • @ashleybyrd2015
      @ashleybyrd2015 9 місяців тому

      @@felixchen1796 I was responding to the person who said "or, hear me out, whitelist"

  • @maxrburgess
    @maxrburgess 9 місяців тому

    It’s worth mentioning that although they have similar effects the login with email code feature and oauth are 2 completely different systems. e.g. 1 attack uses officially provided APIs for account access and the other simply forwards user input to the real service

  • @IronSK
    @IronSK 9 місяців тому +1

    The moment a server ask me to give them my account i dip out. Why anyone would give up their info for a server is beyond me.

  • @Leyleyag
    @Leyleyag 9 місяців тому +2

    This happened to me but on a discord server. Thank you for making everyone aware of these.

  • @Pineapple123Gaming
    @Pineapple123Gaming 9 місяців тому +1

    wow thats amazing there still doing this! I logged into a server like this back in like 2014

  • @mchanna06
    @mchanna06 9 місяців тому +2

    That one policeman from scotland was definitely in charge of the whole investigation.

  • @cheeseybreezy518
    @cheeseybreezy518 7 місяців тому

    From mass content farms, UA-camrs basically scamming children on p2w servers, and people straight stealing accounts in ways I didn't even think possible it's nice to see somebody genuinely caring about the player base and helping inform the masses for us to be wary.

  • @LiEnby
    @LiEnby 9 місяців тому +4

    i thought there was some crazy session exploit or smth, and then its just a phishing scam, my disappointment is immeasurable and my day is ruined

  • @Ryleyisthegoat
    @Ryleyisthegoat 9 місяців тому +1

    This happens in Hypixel Skyblock Dungeons- the party finders that say "Free Carries for joining Discord server" have discord servers that have verification websites exactly like this. I almost fell for it once lmao

  • @russianyoutube
    @russianyoutube 9 місяців тому +1

    The checking physics thing totally makes sense. Knockback, falling and similar stuff is all mostly handeled on the client

  • @RamenNoodiles
    @RamenNoodiles 9 місяців тому

    i remember a few weeks ago i tried to go into this server out of curiosity because i thought it was funny not knowing it was an actual account stealing thing. I joked around with some friends "lol there goes my IP" and instantly removed the account connection from my account not realizing how BIG of an issue this actually was. Jeez, I almost got my stuff YOINKED, thank god I'm really strict with my security stuff.

  • @747Simulation
    @747Simulation 9 місяців тому +4

    Just wanted to say, I am thankful I have never been hacked before. My ip was once leaked, but that was more than 5 years ago, and I use a vpn since then. Just like the video explained, Its really easy to be baited into giving your info, even though it looks like the same screen a 3rd party launcher would ask for. So I think that as long as you never enter your account info in verifications, you should be good.

  • @neoncopycat589
    @neoncopycat589 9 місяців тому +5

    When he says no pressure for the subscribe button I can feel the pressure building in my mind as he continues the video.

  • @thecrimsoncreep6665
    @thecrimsoncreep6665 9 місяців тому +2

    This is the funniest phishing scam ever. I wouldn't be surprised if they made this just because it was so unbelievably easy.

  • @ktheveg
    @ktheveg 9 місяців тому +1

    They should make account tokens its own OAuth scope. Maybe having one service-specific token for misc services, but then they can request to use a different service token, then have that clearly outlined. The way they worded it is that they can view what details you have on your xbox profile, NOT login tokens.
    Just what I'd do to resolve this.

  • @capn
    @capn 9 місяців тому +2

    I was looking into MS OAuth and the Xbox scopes were locked out and required special permission from Microsoft to use. I'm not sure how they managed to get that...

  • @hurtfulmusic1
    @hurtfulmusic1 9 місяців тому

    It’s crazy how simple this can be recreated, the plugin would take less then an hour to make and the website maybe a few hours. Verification is a good way to secure logins (since I own a server) but never sign in with your Microsoft account to get verified on a server. I’ve been reading some other comments its crazy that Microsoft does not explain what is going to happen if you allow access, it gives very brief detail.

  • @RandomPerson-bv3ww
    @RandomPerson-bv3ww 9 місяців тому +4

    Meanwhile mojang is banning servers for having guns

  • @lovelysakurapetalsyt
    @lovelysakurapetalsyt 9 місяців тому

    This is why I don't even go on servers anymore tbh. It's better to make sure things are fine routinely and occasionally play on singleplayer or with friends on a personal server

  • @kyled00m
    @kyled00m 9 місяців тому +1

    You'd think a captcha itself would make people avoid places. "Why do I have to do an extra ANNOYING thing just to visit this place that I know nothing about and is only slightly alluring?"
    I guess people just want to be ANNOYED maybe?

    • @HungryWarden
      @HungryWarden 9 місяців тому

      Captchas suck. The one on the Roblox website was so excruciatingly difficult and when I finally completed it, it gave me this
      “An error occurred”
      🤬

  • @ocushu
    @ocushu 9 місяців тому +6

    Thx for informing us dude

  • @ryanbasu59
    @ryanbasu59 9 місяців тому +1

    MisterEpic, just wanted to ask what shaders you use for your videos? They look gorgeous and I’d like to copy those settings

  • @PaxTheCat
    @PaxTheCat 8 місяців тому

    Sounds creepy. Thanks for causing awareness about these kind of methods

  • @matthewmspace
    @matthewmspace 9 місяців тому +1

    This is why I’m glad I only ever play on locally-hosted servers I make with my friends, lol.

  • @thatjamguyog
    @thatjamguyog 9 місяців тому +6

    Interesting stuff, as usual :D

  • @PhonyLyzard
    @PhonyLyzard 9 місяців тому +41

    Dang, I really like that people like you make these videos to warn people about these account thieves, especially since it's extremely hard for even Mojang and Microsoft themselves to prevent this stuff, even though they've made efforts in the past. (BT dubs, I felt targeted by those guys when you said younger, more susceptible players.)

    • @venturoes1912
      @venturoes1912 9 місяців тому +2

      It's not hard for them to prevent this, this is literally pure stupidity by Microsoft to design a dangerous screen to look like that.

  • @AngelaAmaryllis
    @AngelaAmaryllis 9 місяців тому +1

    In bedrock I've joined servers where, after joining and playing in them, I suddenly found myself having to relog into my microsoft account, often more than once a day. One time it was so bad I almost lost the ability to log in (something messed with the log in box). All of them were cross-play servers, and so far I still haven't found an explanation for it.

    • @nikkiofthevalley
      @nikkiofthevalley 9 місяців тому +1

      Huh. Weird. I haven't seen that with my personal server with Geyser installed, so either they borked their configs or something shady is happening. Geyser itself is fine, (in terms of security) whatever server you're connecting to may not be.

  • @hazardperceptiontest
    @hazardperceptiontest 9 місяців тому +3

    fire video as always, thx for the information

  • @xTheToolx
    @xTheToolx 9 місяців тому

    Don't play MC, but this got my attention. Great work!

  • @ericwheton6935
    @ericwheton6935 9 місяців тому

    One thing i will say on domain registration, you almost always want to privatize your information when registering a domain, i forgot to once while registering a domain for a website, and i was flooded with texts literally every day about "developers" wanting to build me a website for cheap. Doesn't take away from the scam at all just saying its a pretty common thing to hide your information if your not a company

  • @dcincco3292
    @dcincco3292 9 місяців тому

    That type of microsoft verification is commonly used in skyblock discord scams. I got my account hacked by it once, but managed to recover it.

  • @FizzieWebb
    @FizzieWebb 9 місяців тому

    Here's the thing, if it gives access to the gamertag associated with the minecraft account, if you've also bought stuff from the windows store or the xbox marketplace, there's a decent chance your card info, or in the case of a minor, their parents card info, is saved to the account.
    Getting access to the account doesn't then just give them a free account, it gives them access to that card, even if they can't see the card details to use elsewhere, they can still add their main account as a friend, and then gift themselves games and game currencies on someone else's cash.
    Granted, there are built in safeguards you can setup to prevent that if your account gets compromised, the most simple being a custom passcode you need to input before making any purchases, but something tells me not many people would have that set up, and less parents would have that set up on a child's account.

  • @CraftMackncheese
    @CraftMackncheese 9 місяців тому +3

    Let's take a moment to appreciate how he makes his videos it's seems like a interesting history lesson with music in back ground to make it more dramatic. This video keeps my interest

  • @ClawlikeBro
    @ClawlikeBro 9 місяців тому +1

    This just made me think about something - is it possible to hide malware in a server resource pack? When you download a server resource pack the file stays on your computer.

  • @Omena0MC
    @Omena0MC 9 місяців тому

    ive been developing minecraft launchers for a while now, but in my login process it never asks the users to grant some permission, its just a login page.. yet it still gives me a token and refreshToken......

  • @3nderall
    @3nderall 9 місяців тому +1

    this is actually the same page you get directed to whenever you play a gamepass/ms store game for the first time, making it seem less malicious

  • @mighty_gladiator8717
    @mighty_gladiator8717 9 місяців тому +1

    I got ratted in a similar way and an even crazier way - I joined a discord server and allowed a bot and 30 seconds later my Microsoft account was gone and they had infinite access I only knew abt it cuz they had logged into hypixel while I was on so I knew somone had access and saved it but still is crazy to me that just a click of an allow button to a discord server that I didn't even think abt could control my account

  • @d3mon1x46
    @d3mon1x46 9 місяців тому +1

    5:05 damm, if you would say "over and over, again" it would fit the music a lot

  • @mikk.t.7824
    @mikk.t.7824 9 місяців тому

    1:05 is that minewind on the bottom i used to play it all the time?

  • @maxrburgess
    @maxrburgess 9 місяців тому +2

    4:40 domain privacy services are very common and quite often included with a domain. Not really sus as most people wouldn’t want to have their real address and phone number publicly accessible. Also they don’t register “on behalf” they just proxy communications (you put their address instead). Love the video though - nuts.

  • @KeRimoYT
    @KeRimoYT 9 місяців тому +1

    can a minecraft server steal your session id if you just join if the owner modifies the server? i've heard the session id pops up in the tcp protocol when joining to verify your account

  • @nakano8412
    @nakano8412 9 місяців тому +3

    I've seen a few videos about something similiar, it's quite scary, but there is one way around this from happening, use common sense. As harsh as it may be, most victims don't see the blatant red flags. Seen a similiar system used, instead of having a server like this, instead a discord "verification", which suprisingly a decent amount have been tricked by it. I wouldn't recommand allowing any launcher to get permission to the account, even the ones that seems legit.

  • @ayalabaleeiro8398
    @ayalabaleeiro8398 9 місяців тому

    Microsoft has a very bad reputation for security, literally my personal microsoft account and some other disposable ones getting almost 50 sign-in requests each day with the excuse of bruteforce password log-in attempt.

  • @altedhmarsperez4231
    @altedhmarsperez4231 9 місяців тому

    Oh man That's a Method I didn't know about and thank you for Info MisterEpic

  • @tookytoucan7236
    @tookytoucan7236 9 місяців тому +1

    Almost had my account stolen once by this method, I wanted to join a discord server but you needed to verify. Luckily I found it a bit suspicious so didn't lose my account.

  • @pokameni
    @pokameni 9 місяців тому

    One thing you didn't think of was modded servers and their launchers.
    For my own launcher, now I have to set authentication via Microsoft and be approved by Mojang. That said, it's pretty easy to get. So it must also be easy to hijack.

  • @ARVN_Ranger
    @ARVN_Ranger 9 місяців тому +3

    Hm yes 5am maybe its time for me to sleep oh wait TheMisterEpic Just uploaded,Well guess i wont get sleep tonight

  • @BicirikBey
    @BicirikBey 9 місяців тому +5

    Wow I can't believe that Microsoft account security is worse than Mojang account security.

    • @309electronics5
      @309electronics5 9 місяців тому

      I bet Microsoft realy was excited and happy when they got to buy the game from notch implementing their things.....

  • @horse3015
    @horse3015 9 місяців тому

    Thanks for educating the Minecraft community about all this suspicious stuff.

  • @reeseon10
    @reeseon10 9 місяців тому

    the migration was advertised as a way to improve account security yet its easier to steal accounts now than ever before

  • @MyTv-
    @MyTv- 9 місяців тому +2

    Highlights the questionable morality of companies data mining users. It’s a bloody big security risk.

  • @dotjj
    @dotjj 9 місяців тому +3

    What mods were used at 1:07? That clip looks stupid pretty and I wanna emulate it

    • @maxrburgess
      @maxrburgess 9 місяців тому +1

      Presumably just some shaders and a realistic sky texture pack… or maybe there are some shaders with Aurora

  • @goldgrasshoppernein9451
    @goldgrasshoppernein9451 9 місяців тому +1

    Its always an amazing day when you upload!!

  • @BigVirusBoi
    @BigVirusBoi 9 місяців тому +1

    The Microsoft Consent page is currently under maintenance :D How fun.