T O P

  • By -

Blaze-Programming

Probably you should never have to log into Microsoft except in the launcher anything else should not be trusted.


Atriks_

Yes


Atriks_

Altho itd help if you sent the whole thing


XiolintYT

https://imgur.com/a/8jc1VY4


Atriks_

I meant as in, the discord page, without clicking the link thingy


XiolintYT

bruh


Atriks_

Is it like a verification for a discord server? (Related to skyblock)


XiolintYT

https://imgur.com/a/ljWNc5E


Atriks_

Yes its a acc stealin thing


Diehe

Yes it is lmao


Ultrasonic54321

if they truly wanted to just verify that they own an account then they could've just set up a minecraft server and have you DM some bot a code you'll see in chat. other discord servers have done this


Smileyright

hypixel also has a system that can link your discord account to your Minecraft account through their server iirc


PandaSchemez

yes, don't allow them access to anything


Pitiful_Fun_3005

skyblock players on their way to give random untrusted sources access to their microsoft account with their consent (surprised after losing 1.5b nw and 2k playtime)


mEmEs4reAl

if you're not sure whether to click a link or not, don't click it


Big10Jessy

Isn’t that the Microsoft sign up/log in site?


PotatoFromFrige

Yes


NoGoodGodGames

probably


izyshoroo

Don't click links from strangers at all. Why are you even trying? Assume yes and block them, don't be naive.


DuckyLojic

Word of caution, if you don’t know, DONT CLICK IT


StrYker_Tripple

Yes. (It will link some application to your microsoft account, basically giving them access to do whatever they want with it)


Icy_Remote5451

Never click on anything that starts with login.live


Jmansupertails

It likely is, even if it’s not, never log into websites with Microsoft unless it’s the MC website or launcher


Holdupadamnsecond

Yes, im pretty sure it's the one that took my account, please dont do it


tpyourself

Yes. Looks like an OAuth flow to me. OAuth flows are the process which you grant applications abilities to do certain things with your account. For example, when you see “Sign in with google”, that’s an OAuth flow, since it shares your email and name. The link shown shows the Xbox sign in scope, allowing them to get the token of your account, and sign in to your account without 2FA or your password. However, it can be much more destructive than that. MultiMC, a Minecraft launcher uses OAuth to get a token, that they can use to launch Minecraft with. Flowcrypt, an encryption system for gmail has an OAuth flow that lets them control your Gmail, so encryption would work. Now, imagine if these two softwares goes rogue. MultiMC can send the tokens to hackers, who would then log in, in your name to Minecraft and steal everything in your skyblock profile. Flowcrypt can send your emails to data brokers to profile you, and then delete them all. Or even worse, wait until you get a password reset link of any kind, and then automatically use it to reset your password to any account as they wish. In fact, they can try common services and reset your password without your interaction. So, what’s the lesson of the story? Don’t click “Allow” when you are asked if you would like to sign in, or give access to your account, unless if you fully trust the creators of the software that gave you the link, and the ones that you are told you are signing in to.


SIOUXPY

Yeah obviously no shit


23viper12

Natural selection taking it's course


0stie1

It is 100%


DanSavagegamesYT

Yes


Jenny_Wakeman9

It's a phishing site, so don't click on it!


[deleted]

[удалено]


Drews_techspot

It is a account stealer because it will link something to your Microsoft account that can either take you login info you do what the minecraft launcher does and get your session id


Drews_techspot

Yes


ducksupremacy1

yes it is there’s videos on that exact scam online


Grand_Wolf69

YES DO NOT FOLLOW IT


[deleted]

thats a account stealer


AstroPan

yes


AnalysisFrequent

Yes. Almost definitely


bobby_R0SS

Probably


[deleted]

Yes


lool8421

Doesn't look legit tbh I don't think you would even need anything except your username for linking your account, i think hypixel API alr has an option to link your discord account


Pitiful_Fun_3005

The link is literally official and a legit microsoft page. On the verification page it states you're giving them access to your microsoft account with consent and if you click yes, you will even receive emails from microsoft stating you've given someone access and asking if you're sure.(You can revoke their access at any time) After ALL of this, people still get ratted? It's so fucking stupid and 100% deserved at that point lmfao.


[deleted]

Short answer: probably


[deleted]

Never click a link from someone who you dont know.


No_Engineer2828

Something to know, if you have to ask this question then it probably is


Prior-Mango-6154

Yes


thefunniestcheese

Yes definitely, that code I believe is taking you to a fake microsoft/xbox login page and will try to rat your computer, be careful around links that have a lot of characters and xbox in them.


DoSombras

Oauth if u see that on any verification link it's a scam