Jump to content

Scammers using new technique to bypass Valve's Steam Guard

rhodestech

I hope Valve fixes this as soon as possible. 

 

"Valve has in place a protection mechanism for stopping strangers using your account but this new phishing method bypasses its so-called 'Steam Guard'. You will see Steam Guard employed when you log into a PC you haven't used before with your Steam account. If you haven't seen it before all it does it pop up a window to input a verification code which it has sent your registered email address. No code – no logging to Steam from your new computer." 

 

 

21a86fdd-3498-429f-be28-f6bee96bbc32.jpg

 

 

Source - hexus.net - http://hexus.net/gaming/news/pc/68841-scammers-using-new-technique-bypass-valves-steam-guard/

Social Links: LTT Forum    Website    Instagram    Twitter    YouTube    LinkedIn    Steam 

 

The Build

CPU Intel i7 4770k 4.4ghz Motherboard Asus Sabertooth Z87 RAM 34gb (4 x 8gb) Corsair Vengeance 1600mhz GPU Evga GTX780 Classified Case Lian Li O11 Dynamic Storage Samsung 840 256gb SSD PSU Corsair HX750 Display Achieva Shimian QH300-IPSMS 1600p Cooling Corsair H100i Keyboard Corsair K90 Mouse Corsair M65 Sound 3.1 Surround Sound Fans 2x Corsair SP120 PWM, 3x Corsair AF140 Q.E, and 1x Corsair AF120 Q.E.

Link to comment
Share on other sites

Link to post
Share on other sites

Nooooo My $7.00 account is at risk!

Main rig on profile

VAULT - File Server

Spoiler

Intel Core i5 11400 w/ Shadow Rock LP, 2x16GB SP GAMING 3200MHz CL16, ASUS PRIME Z590-A, 2x LSI 9211-8i, Fractal Define 7, 256GB Team MP33, 3x 6TB WD Red Pro (general storage), 3x 1TB Seagate Barracuda (dumping ground), 3x 8TB WD White-Label (Plex) (all 3 arrays in their respective Windows Parity storage spaces), Corsair RM750x, Windows 11 Education

Sleeper HP Pavilion A6137C

Spoiler

Intel Core i7 6700K @ 4.4GHz, 4x8GB G.SKILL Ares 1800MHz CL10, ASUS Z170M-E D3, 128GB Team MP33, 1TB Seagate Barracuda, 320GB Samsung Spinpoint (for video capture), MSI GTX 970 100ME, EVGA 650G1, Windows 10 Pro

Mac Mini (Late 2020)

Spoiler

Apple M1, 8GB RAM, 256GB, macOS Sonoma

Consoles: Softmodded 1.4 Xbox w/ 500GB HDD, Xbox 360 Elite 120GB Falcon, XB1X w/2TB MX500, Xbox Series X, PS1 1001, PS2 Slim 70000 w/ FreeMcBoot, PS4 Pro 7015B 1TB (retired), PS5 Digital, Nintendo Switch OLED, Nintendo Wii RVL-001 (black)

Link to comment
Share on other sites

Link to post
Share on other sites

I hope Valve fixes this as soon as possible. 

 

"Valve has in place a protection mechanism for stopping strangers using your account but this new phishing method bypasses its so-called 'Steam Guard'. You will see Steam Guard employed when you log into a PC you haven't used before with your Steam account. If you haven't seen it before all it does it pop up a window to input a verification code which it has sent your registered email address. No code – no logging to Steam from your new computer." 

 

 

21a86fdd-3498-429f-be28-f6bee96bbc32.jpg

 

 

Source - hexus.net - http://hexus.net/gaming/news/pc/68841-scammers-using-new-technique-bypass-valves-steam-guard/

I don't see the importance level of this being high.. But I guess some are more inept than others.

This confirms my two theories:

• If there's a will, there's a way

• There's a bypass for everything.

 

..Interesting read, though. Thanks for the post sir.

::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::


« Current PC ~ Phantom Beast »


.::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::.

Link to comment
Share on other sites

Link to post
Share on other sites

This happened to me a few months ago, i just verified myself by sending email and confirming it.

But i think someone got into my account because steam showed their ip address and location where they accessed my account 

Link to comment
Share on other sites

Link to post
Share on other sites

I don't see the importance level of this being high.. But I guess some are more inept than others.

This confirms my two theories:

• If there's a will, there's a way

• There's a bypass for everything.

 

..Interesting read, though. Thanks for the post sir.

 

I think any vulnerabilities should be publicized, so that the company in question are even more inclined to fix it as soon as possible. 

 

No problem! :)

Social Links: LTT Forum    Website    Instagram    Twitter    YouTube    LinkedIn    Steam 

 

The Build

CPU Intel i7 4770k 4.4ghz Motherboard Asus Sabertooth Z87 RAM 34gb (4 x 8gb) Corsair Vengeance 1600mhz GPU Evga GTX780 Classified Case Lian Li O11 Dynamic Storage Samsung 840 256gb SSD PSU Corsair HX750 Display Achieva Shimian QH300-IPSMS 1600p Cooling Corsair H100i Keyboard Corsair K90 Mouse Corsair M65 Sound 3.1 Surround Sound Fans 2x Corsair SP120 PWM, 3x Corsair AF140 Q.E, and 1x Corsair AF120 Q.E.

Link to comment
Share on other sites

Link to post
Share on other sites

I think any vulnerabilities should be publicized, so that the company in question are even more inclined to fix it as soon as possible. 

 

No problem! :)

Oh yes, you are totally right. People should always be totally aware of what they are dealing with.

::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::


« Current PC ~ Phantom Beast »


.::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::.

Link to comment
Share on other sites

Link to post
Share on other sites

This happened to me a few months ago, i just verified myself by sending email and confirming it.

But i think someone got into my account because steam showed their ip address and location where they accessed my account 

what happens when you do get their ip address and location? Does steam do something to them after you tell them it wasn't you (with some logical reasoning to the support agent)?

Selling my parts of my 900D rig for a jacked up Ncase M1. PM me for offers if interested (will take some reasonable-low offers because I'm desperate).

Parts that I'm selling: 900D (1 slot cover broken for stealth DVD drive mod) | Asus Z87 Deluxe | Cooler Master 212 Evo | Corsair 4x2GB black ram @1600mhz | EVGA 1000G2 PSU (2 cables with missing heat shrink) | DVD drive | HP membrane keyboard | Ducky Shine 3 YOTS in blue switches (warranty sticker broken)

Link to comment
Share on other sites

Link to post
Share on other sites

Geez they are just making articles about this now? Pretty sure this has been out in the wild for a month or more.

Link to comment
Share on other sites

Link to post
Share on other sites

what happens when you do get their ip address and location? Does steam do something to them after you tell them it wasn't you (with some logical reasoning to the support agent)?

Nothing really happened.

I just confirmed it was my account via email and was back to using my steam, though i did have to change my password  :wacko:

Link to comment
Share on other sites

Link to post
Share on other sites

This is out for a while now and I always get misspelled links from random people who add me telling to add the person as he cannot trade. Just have to be careful of the links that you go to.

Hello and Welcome to LTT Forum!


If you are a new member, please read the rules located in "Forum News and Info". Thanks!  :)


Linus Tech Tips Forum Code of Conduct           FAQ           Privacy Policy & Legal Disclaimer

Link to comment
Share on other sites

Link to post
Share on other sites

This is out for a while now and I always get misspelled links from random people who add me telling to add the person as he cannot trade. Just have to be careful of the links that you go to.

Same here I have been getting them messages since January of this year by now I've probably got close to 50 of them messages.

PC Specs: - *NZXT Phantom 410 Black/Orange* - *AMD FX-8320 3.5GHz* - *CM Hyper 212 EVO* - *Gigabyte 990FXA-UD3* - *Corsair Vengeance 8gb 1600mHz* - *Gigabyte 780 Ti* - *Seagate Barracuda 500gb 7200rpm HDD* - *ModXStream PRO 600W PSU* -

Monitors: 2x BenQ GL2450 and 1x Some 22" 1080P Tv

Link to comment
Share on other sites

Link to post
Share on other sites

  • 2 months later...

I can't believe people fall for this crap..

You mean the article or this stupid phishing? :P

Link to comment
Share on other sites

Link to post
Share on other sites

This same scam has been done multiple times before. It's all the same, manually upload a file from your PC. Like any company would ever ask you to do that!

 

I think it shows how well secured Steam is if user stupidity is the only real weakness.

The stone cannot know why the chisel cleaves it; the iron cannot know why the fire scorches it. When thy life is cleft and scorched, when death and despair leap at thee, beat not thy breast and curse thy evil fate, but thank the Builder for the trials that shape thee.
Link to comment
Share on other sites

Link to post
Share on other sites

The reason no one has made a thread about this is because no one here is stupid enough to fall for it. (Alright that might be somewhat optimistic)

Link to comment
Share on other sites

Link to post
Share on other sites

The reason no one has made a thread about this is because no one here is stupid enough to fall for it. (Alright that might be somewhat optimistic)

That may be true. :P

I guess only the people who is new to Steam?

Link to comment
Share on other sites

Link to post
Share on other sites

hmmm, hmmm. You'd have to be an idiot.

Beneath this mask there is more than flesh. Beneath this mask there is an idea, Mr. Creedy, and ideas are bulletproof.

As I get older I get angrier more cynical, meaner. I feel some warning posts coming. I feel a ban coming. I was warned.

CPU-i5 2400 GPU-Sapphire Radeon HD 7970 OC Mobo-H67MA-D2H-B3 Ram-G.Skill Ripjaws 8gb 1333mhz Case-Fractal Define R4 PSU-Corsair CX750 Storage-Samsung EVO 250gb, 1tb WD Black,Hitachi 1tb Other stuff-Corsair K90, M90 Cooling-3x 140mm Fractal fans Sound-Sennheiser HD438 headphones
Link to comment
Share on other sites

Link to post
Share on other sites

i remember someone posted this exploit many months ago.

| Intel i7-3770@4.2Ghz | Asus Z77-V | Zotac 980 Ti Amp! Omega | DDR3 1800mhz 4GB x4 | 300GB Intel DC S3500 SSD | 512GB Plextor M5 Pro | 2x 1TB WD Blue HDD |
 | Enermax NAXN82+ 650W 80Plus Bronze | Fiio E07K | Grado SR80i | Cooler Master XB HAF EVO | Logitech G27 | Logitech G600 | CM Storm Quickfire TK | DualShock 4 |

Link to comment
Share on other sites

Link to post
Share on other sites

Anybody who falls into a blatant trap like this should have their account taken from them. I mean, you don't fall for things like this where you could get your bank account credentials stolen do you? The same thing applies for Steam. If you are silly enough to upload a file like this just to get some "free games" or something like that, you are truly stupid.

Link to comment
Share on other sites

Link to post
Share on other sites

I'm surprised the article makes no mention that you can deauthorize all machines trying to log in with your account.

 

Would be a good idea for those who are not so knowledgeable of these thing to be aware of this.

Link to comment
Share on other sites

Link to post
Share on other sites

I can't believe people fall for this crap..

 

 

The reason no one has made a thread about this is because no one here is stupid enough to fall for it. (Alright that might be somewhat optimistic)

 

 

hmmm, hmmm. You'd have to be an idiot.

 

 

So you guys just haven't considered there are more diverse people who use steam than just self-centered teens.  My son who suffers a language delay would fall for this easy, but his innate intelligence would leave most of you for dead.   You don't have to be stupid or simple or and idiot to fall for this.

Grammar and spelling is not indicative of intelligence/knowledge.  Not having the same opinion does not always mean lack of understanding.  

Link to comment
Share on other sites

Link to post
Share on other sites

Anybody who falls into a blatant trap like this should have their account taken from them. I mean, you don't fall for things like this where you could get your bank account credentials stolen do you? The same thing applies for Steam. If you are silly enough to upload a file like this just to get some "free games" or something like that, you are truly stupid.

please see the above post and stop being ignorant.

Grammar and spelling is not indicative of intelligence/knowledge.  Not having the same opinion does not always mean lack of understanding.  

Link to comment
Share on other sites

Link to post
Share on other sites

Guest
This topic is now closed to further replies.

×