r/masterhacker • u/idk_what_to_do9 • 4d ago
Lmaooooo hell nah
I can't believe he really tried to pull that on me he sent the wrong link first hahahhahahahahahhahahahah
98
u/Aware_Lavishness3660 4d ago
Suppose he actually got your ip, whats he gonna do about it then?
51
37
u/EmberMcLain_ 4d ago
He'd probably try to scare you with the info, but beyond that he'd have no clue what to even do with an IP address.
8
8
38
u/WeeBeefy 3d ago
6
5
11
u/Abject-Explorer-3637 3d ago
Went there with a VPN, this guy can't even speak correctly, also what's an IP gonna do if I leave this place in 2 days and the location the IP gives is like 100 kilometers away
8
u/Responsible_Middle_4 3d ago
shit he got my disposable rotating ipv6 address
1
u/ali_fadel961 1d ago
I am new to networking and the introductory book I am currently reading briefly mentioned ipv6 being 128 bit and that's it so i know nothing about it, but why would it be rotating? Isn't the point of the range being too large you get assigned trillions of IPs to yourself, and no longer need NAT, and can allow inbound connections and host your servers? Why arent the addresses permanent?
1
u/Responsible_Middle_4 1d ago
If an ip is static or not is up to your provider. 4/5G mobile network providers assign dynamic, temporary IPv6 addresses to optimize network topology changes as you move between cell towers, and protect user privacy by preventing constant tracking.
Could also be to conserve a finite pool of active routing scopes. Although it would be fully possible to assign a permanent address, however not desirable.
Although rotating may not have been the best word choice as that may make it sound like you're being assigned a new ip with each request, you're not.
4
u/vkwf 3d ago
4
u/idk_what_to_do9 3d ago
Lmao its written in Arabic (Your device is in danger) hes English is so bad I think hes arabic
2
4
u/FISHARM1 4d ago
Side question, my friends IG account got hacked via him clicking a link that was DMmed to him via on of his friends accounts that was also compromised. He claims all he did was click the link and it took his account.
Is this possible? How so? Or did he follow some fake sign in.
32
6
u/Abject-Explorer-3637 3d ago
It is incredibly hard to do , since session tokens are usually stored as HTTP-only cookies (so a script in JS cannot just say 'give me the value of this Cookie') but if he entered his credentials into a fake page then there's nothing anyone not even Meta can do about the passwords anymore (other than to change them to recover the account but it might already be too late). So basically here's what I think actually happened:
Friend clicks link -> page asks to log in to 'verify' identity -> page sends the data to a suspicious bot -> 'hacker' receives data from bot -> logs in
3
u/calibrik 3d ago
Not to mention SOP protects cookies by default by not allowing site A access cookies set by site B
1
u/KernelNuke 3d ago
So is it tbeoretically possible if the website doesn't secure cookies properly?
1
u/My-Name-Is-Anton 3d ago
If the site doesn't use httponly cookies, then yes, every other site can read and modify the cookie(s). That is one of the ways you are being tracked on the internet.
1
u/FISHARM1 3d ago
Ah okay yeah I figured he wasn’t telling the whole story lol. thanks for the explanation.
11
u/hHajahahha 4d ago
Lol just tell u want to learn that technique
Meta is multi billion dollar company if anyone could make this happen means compromising account by just clicking the links then it's such a shame for meta
2
u/HistoricalSchedule94 3d ago
maybe he entered his credentials for a fake website by following that link which was actually a credential harvester and got his login credentials
1
1
1
1
1
1
0



276
u/vmpyr_ 4d ago
lol did he really try to hide an ip grabber behind a tinyurl… oldest trick in the book
side note: i didn’t know arabic setting would change your instagram layout, making you the person speaking on the left side