Jump to content

new XSS exploit discovered in STEAM, stay away from profile pages - it's now fixed

zMeul

source: https://www.reddit.com/r/Steam/comments/5skfg4/warning_regarding_a_steam_profile_related_exploit/

 

 

Steam_logo.png?t=20111214052439

 

why I say again? because another XSS exploit was discovered 2y ago: https://steamdb.info/forum/292/why-an-xss-exploit-on-steamcommunitycom-is-scary/

 

Quote

Currently, there is a risk (i.e. phishing, malicious script execution, etc.) involved when viewing or simply opening PROFILE pages of other steam users as well as your OWN activity feed (both desktop and mobile versions on all browsers including steam browser/chromium). I would advise against viewing suspicious profiles until further notice and disable JavaScript in your browser options. Do NOT click suspicious (real) steam profile links and Disable JavaScript on Browser. Appropriate information has been forward to Valve and this issue should be resolved soon, sorry for any inconvenience.

 

enable your two-factor auth people, and stay away from profile pages .. any profile page

 

it's good that ValvE notified users as soon as possible about the security risk

 

---

 

edit: exploit has been fixed and profile pages are now safe to browse

 

Edited by zMeul
Link to comment
Share on other sites

Link to post
Share on other sites

I remember when this happened a few years ago, I had just made another steam account the same day, luckily i dont save my payment info but i did get access to other peoples account!

Hello

Link to comment
Share on other sites

Link to post
Share on other sites

And this is why noone should be setting password remembering on for paypal in steam or anywhere 

Link to comment
Share on other sites

Link to post
Share on other sites

8 minutes ago, MadOlive said:

And this is why noone should be setting password remembering on for paypal in steam or anywhere 

That's why there is 2 factor authentication

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, deXxterlab97 said:

2 factor authentication doesn't help with that

Yea ik... a friend of mine got her account hacked a while back and the hacker bought 50pounds worth of csgo cases. He couldnt get them out of her account due to the 2-step but he could buy them and you wont get the damage refunded.

So never ever make steam remember your paypall password! At most your login mail adres!

Link to comment
Share on other sites

Link to post
Share on other sites

10 minutes ago, deXxterlab97 said:

That's why there is 2 factor authentication

But its so annoying. I would rather get my account hacked and go through 2 weeks of trouble with steam to get it back, than having to deal with 2FA.

 

 

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, Senzelian said:

But its so annoying. I would rather get my account hacked and go through 2 weeks of trouble with steam to get it back, than having to deal with 2FA.

How is it annoying? You just enter the code that was given to you and you can also save the code for this device so it doesn't prompt you anymore

Link to comment
Share on other sites

Link to post
Share on other sites

13 minutes ago, deXxterlab97 said:

That's why there is 2 factor authentication

2 factor doesn't completely prevent hacks, especially with PayPal's idiot phone support. I managed to hack into over a dozen of people's accounts on PayPal that had 2FA just to show them that PayPal doesn't protect your account at all.

4 minutes ago, Senzelian said:

But its so annoying. I would rather get my account hacked and go through 2 weeks of trouble with steam to get it back, than having to deal with 2FA.

You're fucking lazy, it takes less time to type the 6-digit code than it does to type in your password.

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

8 minutes ago, Senzelian said:

But its so annoying. I would rather get my account hacked and go through 2 weeks of trouble with steam to get it back, than having to deal with 2FA.

Having had my account hacked and now using two-factor authentication I have to say that you're mad!

 

Install the Steam app on your phone and whenever you try to log in somewhere new or do something that needs a two-stage process you're phone will go off with the info you need right there on the notifications screen. Damn sight easier than going through Steam customer services and resetting all my account information.

Link to comment
Share on other sites

Link to post
Share on other sites

5 minutes ago, Jed M said:

You're fucking lazy, it takes less time to type the 6-digit code than it does to type in your password.

unless his password is 5-digits, or less :P

Link to comment
Share on other sites

Link to post
Share on other sites

5 minutes ago, deXxterlab97 said:

How is it annoying? You just enter the code that was given to you and you can also save the code for this device so it doesn't prompt you anymore

I tried it, it didn't even work half of the time. Then there is this weird 16billion digit code which I don't even know what it does. 

 

4 minutes ago, Jed M said:

You're fucking lazy, it takes less time to type the 6-digit code than it does to type in your password.

 

No it doesnt, since I have to look at my phone first. Srsly, that wasnt even my point.

 

 

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, Senzelian said:

I tried it, it didn't even work half of the time. Then there is this weird 16billion digit code which I don't even know what it does. 

 

No it doesnt, since I have to look at my phone first. Srsly, that wasnt even my point.

You obviously don't understand what 2FA is.

 

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, Senzelian said:

I tried it, it didn't even work half of the time. Then there is this weird 16billion digit code which I don't even know what it does. 

 

No it doesnt, since I have to look at my phone first. Srsly, that wasnt even my point.

You must have a really bad phone then. It worked flawlessly for both my previous iPhone 5s and my current Samsung S5 Neo

Link to comment
Share on other sites

Link to post
Share on other sites

8 minutes ago, Senzelian said:

But its so annoying. I would rather get my account hacked and go through 2 weeks of trouble with steam to get it back, than having to deal with 2FA.

 

6 minutes ago, deXxterlab97 said:

How is it annoying? You just enter the code that was given to you and you can also save the code for this device so it doesn't prompt you anymore

 

3 minutes ago, Jed M said:

You're fucking lazy, it takes less time to type the 6-digit code than it does to type in your password.

 

Sometimes I want to disable it. The app is just so annoying. They should allow us to use something like Google Auth

Hello

Link to comment
Share on other sites

Link to post
Share on other sites

5 minutes ago, deXxterlab97 said:

You must have a really bad phone then. It worked flawlessly for both my previous iPhone 5s and my current Samsung S5 Neo

OP2. Schould work just fine.

5 minutes ago, Jed M said:

You obviously don't understand what 2FA is.

Yes, that must be it. Thank you.

 

 

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

Thank gooses for two-factor.

if you have to insist you think for yourself, i'm not going to believe you.

Link to comment
Share on other sites

Link to post
Share on other sites

Heh, well good password and two-factor authentication as well as no payment info saving, all good.

Don't even browse anything on Steam really, or use any social stuff. Just preview a game if I'm interested to buy and that's it :3

| Ryzen 7 7800X3D | AM5 B650 Aorus Elite AX | G.Skill Trident Z5 Neo RGB DDR5 32GB 6000MHz C30 | Sapphire PULSE Radeon RX 7900 XTX | Samsung 990 PRO 1TB with heatsink | Arctic Liquid Freezer II 360 | Seasonic Focus GX-850 | Lian Li Lanccool III | Mousepad: Skypad 3.0 XL / Zowie GTF-X | Mouse: Zowie S1-C | Keyboard: Ducky One 3 TKL (Cherry MX-Speed-Silver)Beyerdynamic MMX 300 (2nd Gen) | Acer XV272U | OS: Windows 11 |

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×