Skip to content

Latest commit

 

History

History
9 lines (7 loc) · 660 Bytes

README.md

File metadata and controls

9 lines (7 loc) · 660 Bytes

Discord-Tenor-Exploit

A sparkJava application that renders an image from a Tenor URL (Used for the Discord Tenor Exploit) [tpnor.com]

Technologies used

  • sparkJava
  • Google Gson

How does the exploit work?

Discord's client utilises a search and replace system for their message editing system, this works by typing the message s/<find>/<replace> - in this example when you send a tenor URL https://tenor.com/view/my-dog-stood-on-a-bee-amber-heard-johnny-depp-dog-bee-gif-25657536 when typed s/e/p as a new message, it will replace tenor.com to tpnor.com which is our own hosted website, and grabs the Tenor Gif from the number id.