[Boards: 3 / a / aco / adv / an / asp / b / biz / c / cgl / ck / cm / co / d / diy / e / fa / fit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mu / n / news / o / out / p / po / pol / qa / r / r9k / s / s4s / sci / soc / sp / t / tg / toy / trash / trv / tv / u / v / vg / vp / vr / w / wg / wsg / wsr / x / y ] [Home]
4chanarchives logo
>find security issue in Steam 2 years ago where you can make
Images are sometimes not shown due to bandwidth/network limitations. Refreshing the page usually helps.

You are currently reading a thread in /v/ - Video Games

Thread replies: 81
Thread images: 25
File: 1260675375929.jpg (35 KB, 522x399) Image search: [Google]
1260675375929.jpg
35 KB, 522x399
>find security issue in Steam 2 years ago where you can make purchases on a Steam account without verification if the user has PayPal or Credit Card info saved
>this means all someone has to do is get another user's session to be able to make purchases on paypal or creditcard
>report it to Valve's head of engineering
>they fix it a few months later by making people sign in again before finishing a purchase
>now this happens, active sessions getting assigned to random people
>tfw I literally saved millions of steam users from having their paypal and CCs emptied by reporting a vulnerability I found 2 years ago.

You're welcome guys
>>
t-thanks
>>
File: 1261089026663.jpg (11 KB, 265x297) Image search: [Google]
1261089026663.jpg
11 KB, 265x297
thanks op
>>
File: 1437131677223.jpg (31 KB, 640x570) Image search: [Google]
1437131677223.jpg
31 KB, 640x570
Thanks based nigga
>>
Thanks. But I have -88 dollars in my paypal account. So no worries.
>>
Thanks OP
>>
>>3214383>>321438303
OP is a faggot

>no payment info saved
>less than 50 cents in steam wallet from selling cards/crates/skins
>two factor authentication enabled

Let morons reap what they sow
>>
File: 1326775195795.png (85 KB, 368x377) Image search: [Google]
1326775195795.png
85 KB, 368x377
i-i knew i shouldnt have saved my credit card t-thanks op
>>
File: 1366322634494.png (122 KB, 336x327) Image search: [Google]
1366322634494.png
122 KB, 336x327
>>321438303
>not getting any profit from saving shitty corporations billions
Thanks, but you are a huge faggot if you didn't profit the fuck out of that.
>>
>>321440265
I was taught not to seek compensation for reporting vulns or it'll open me up to legal action, unless the company has a bug bounty program which Valve doesn't.
>>
uh-huh, sure you did.

Hey anons, I'm Gaben! I'm here to let you know that I in fact am Gaben. Yes, thats right, the one and only.
>>
File: Screenshot_2015-12-25-16-59-00.png (439 KB, 1080x1920) Image search: [Google]
Screenshot_2015-12-25-16-59-00.png
439 KB, 1080x1920
>>321441256
I'm on mobile atm but here's a snippet of my email to Valve.
>>
>>321441782
sweatingman.jpg
>>
>>321441782
>Ubuntu bypasses steam guard
wat
>>
you are my batman
>>
File: 1331558048215.png (80 KB, 163x196) Image search: [Google]
1331558048215.png
80 KB, 163x196
>>321441782
>>321438303
i have no idea what any of this shit means but good on you
>>
idk what this means but im safe right?
>>
File: ScreenShot00206.png (8 KB, 986x121) Image search: [Google]
ScreenShot00206.png
8 KB, 986x121
>>321445282
Yea, the "other levels of authentication" he mentioned after I emailed him back for a follow-up basically meant you had to manually log in with your username and password again before transactions can be completed.
>>
>>321438303
*sends karma*
gj bro (:
>>
>>321445908
Which means just having access to another user's session, which is what appears to be happening, won't let you make purchases on their paypal or credit card.
>>
>>321438303
You got a username bro? I'll buy you a game.
>>
File: 1446679977675.jpg (34 KB, 427x300) Image search: [Google]
1446679977675.jpg
34 KB, 427x300
>>321438303
if youre being honest you can have a game from me
>>
>>321438303
>>they fix it a few months later by making people sign in again before finishing a purchase
>>321445908
>basically meant you had to manually log in with your username and password again before transactions can be completed.

You knowingly lied to us and in fact did nothing, why?
>>
>>321445908
>>321446173
fuck thanks bro
>>
W-what happened?
>>
>>321446857
I would say lied but he does seem to contradict himself.
>>
File: 1451025474621.png (78 KB, 900x900) Image search: [Google]
1451025474621.png
78 KB, 900x900
>>321438303
>>321441782
Thanks bro.
>>
File: Mami x Kyouko 003.jpg (201 KB, 850x1258) Image search: [Google]
Mami x Kyouko 003.jpg
201 KB, 850x1258
>>321438303
Thanks bro.
>>
>>321446857
What do you mean? For all I know they could've already had it in the pipeline to require resignin before finishing a purchase but at the time they didn't.

I tested it using my own steam account by hijacking my session on a PC I've never logged into before and was able to bypass Steam Guard and make purchases on it without ever having to log in (type name/pass).

I reported that. And a few months later I emailed Valve again asking for a follow up and that was the reply they gave me. And when I tested it again, I was stonewalled by a login screen on my attacker machine, which meant it was fixed.

>>321446458
>>321446793
Sure if you guys want to, http://steamcommunity.com/id/hyzzy/
>>
>>321447552
Oh, so they basically said it was there the whole time and just sneakily put it in?

Well, thank you for helping us all. What kinda games do you like?
>>
File: ScreenShot00207.png (137 KB, 1423x943) Image search: [Google]
ScreenShot00207.png
137 KB, 1423x943
>>321441782
Back on my computer.

Here's the full email of the report I sent before. The highlighted portion is the main thing that Valve fixed after my report as you now have to sign in again before completing a transaction.

So if your steam session is stolen, your funds should still be safe as the attacker does not have your password.

>>321447772
Still not sure what you mean, but the fact that Valve made it so that you MUST sign in again before purchasing is what's keeping others from making unauthorized purchases on your account.

I was eyeballing 7 Days To Die or that new RTS game from Stardock but haven't pulled the trigger yet.
>>
>>321449096
>deleted my paypal details from steam a week ago
thank the lord
>>
>>321438303
I am a virgin girl but I've been told that I'm cute, can I do you a sexual favor perhaps?
>>
>>321449096
Huh. Cool. Nice going there, anon.
>>
>>321449096
>Sent from my Boomerang
>>
>>321449096
did they at least refund you for the game you bought?

>having secrets of the magic crystal in your library
>>
>>321449096
>6/28/14
>>
>>321450136
Yea got my dates confused, not exactly 2 years ago. But still.

>>321450086
Nope, just ended up trading the games away for TF2 keys so I could trade those for games I want in the future.
>>
File: 1414383116044.jpg (67 KB, 640x480) Image search: [Google]
1414383116044.jpg
67 KB, 640x480
You're a cool guy OP
>>
File: 1284874544556.jpg (6 KB, 207x229) Image search: [Google]
1284874544556.jpg
6 KB, 207x229
>>321449096
Never stop fighting the good fight
Need more white hats around here
>>
File: fuck.png (172 KB, 451x377) Image search: [Google]
fuck.png
172 KB, 451x377
>>321450086
>tfw buying secrets of magic crystals to my steam friends every sale
>one of them buys it to me
>>
>>321438303
Thanks, dude. You're a cool dude/gril.
>>
Bring this to valves attention maybe they'll hire you.
>>
File: 1450548267291.gif (1 MB, 330x312) Image search: [Google]
1450548267291.gif
1 MB, 330x312
>>321438303
You did get some kind of compensation right?

At least some free games or something.
>>
>>321450867
>anon can't read
>>
>>321451068
Nah, but it's alright I just used it as a learning experience and I had fun doing it.
>>
>>321449096
HE
DID
IT
FOR
FREE
>>
>>321451068
He shouldn't have. That'd be something like ransom. Don't put your trust into these guys all willy nilly man, if they can access a vulnerability like this they sure as fuck can sell/give it to a hacker.
>>
>>321449096

Good job man.
>>
File: 1450038301314.jpg (83 KB, 500x714) Image search: [Google]
1450038301314.jpg
83 KB, 500x714
>>321451304
Same anon here. Sorry OP didn't mean to discredit you. You're a good man. <3
>>
>>321449096
Noice

>sent from my boomerang
>>
>>321438303
Fuck you OP. I could have sued the shit out of them.

Nah but for real thanks.
>>
File: 1450468369846.png (7 KB, 801x577) Image search: [Google]
1450468369846.png
7 KB, 801x577
>>321438303
>>
File: mohammed.jpg (280 KB, 960x711) Image search: [Google]
mohammed.jpg
280 KB, 960x711
>google old email address 7 years ago
>gawker has everyone who has ever signed up for their website in plain text on a page with their emails and username
>send them an email to inform them
>they reply with a snide remark
>say fuck if I care I never used the e-mail address anyways
>literally save no one from anything
>>
>>321451693
>Gawker
aren't they going assfucked by the courts right now for that exact reason?
>>
>>321451989
no, they might get assfucked because the hulkster got mad
>>
>>321451290
Worse, he PAYED to do it!
>>
>>321449096
>Sent from my Boomerang

phone brands are starting to get ridiculous
>>
>>321440265
That's called blackmail you retard
>>
>>321451290
>>321452104
OP here.

kek, you guys are actually right.
>>
>>321438303
OP! AH AHHHH! SAVIOR OF THE UNIVERSE!
>>
Security researcher here

This guy >>321452161is right and what OP did was the safest thing he could've done. You can't just contact a company and say "i have a bug, give me something and I'll tell you what it is" without getting lawyers on your ass. It's dangerous. The best thing to do is to just report it and hope the company is nice enough to give you something in return
>>
File: 1295196825750.gif (87 KB, 256x306) Image search: [Google]
1295196825750.gif
87 KB, 256x306
>>321450623
>>321452785
>mfw there were white hats near me
>>
>>321447552
http://steamcommunity.com/id/hyzzy/wishlist

this your wishlist OP?
>>
don't mind me

>>>/g/52055843
>>
>>321453669
yes

>>321454079
also https://twitter.com/SteamDB/status/680528031761481728

Issue was read only, not a happening. Time to go home lads.
>>
>>321438303
Based OP, the world needs more people like you
>>
File: 2fast.png (313 KB, 363x518) Image search: [Google]
2fast.png
313 KB, 363x518
>finally get back into account
>last purchase is killer is dead which I bought during the thanksgiving sale
>check paypal
>nothing, still unlinked just to be safe

I think I survived, but knock on wood and all that.
>>
>>321454369
>Rustle Avatar

NOOOOOOO
>>
File: ScreenShot00208.png (10 KB, 77x52) Image search: [Google]
ScreenShot00208.png
10 KB, 77x52
>>321454664
>>
File: 1402760269656.png (85 KB, 219x225) Image search: [Google]
1402760269656.png
85 KB, 219x225
>>321447552
>>321453669
>TESO
>>
File: 3602586464_523c1055b9.jpg (111 KB, 500x333) Image search: [Google]
3602586464_523c1055b9.jpg
111 KB, 500x333
>>321438303
Thank you for your service.
>>
>>321454885
I-It looked fun in youtube gameplay videos ;_;
>>
OP here.

It seems that it was just a caching issue where people were being served pages cached for other users. At worst you could navigate to the user info page and see their emails and the last 4 digits of the credit card, but you couldn't actually do anything with the person's account. It was not a session-related bug.
>>
>>321449096
>Sent from my Boomerang
I didn't know Steam Support hired Australian
>>
>>321438303
You just saved Christmas, anon!
>>
>>321457008
Isn't the creator of TF2 Australian?
>>
>>321457690
That would explain why the game is such unplayable shit.
>>
>>321450703
>tfw that's why I have SotMC as well as Bad Rats, among plenty of other "why the fuck is this even on Steam" games
>>
File: 1449684756416.jpg (13 KB, 144x189) Image search: [Google]
1449684756416.jpg
13 KB, 144x189
>>321438303

>mfw paysafecard
>>
>>321449096
>I've forward it
This is the caliber of employee Valve hires
Thread replies: 81
Thread images: 25

banner
banner
[Boards: 3 / a / aco / adv / an / asp / b / biz / c / cgl / ck / cm / co / d / diy / e / fa / fit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mu / n / news / o / out / p / po / pol / qa / r / r9k / s / s4s / sci / soc / sp / t / tg / toy / trash / trv / tv / u / v / vg / vp / vr / w / wg / wsg / wsr / x / y] [Home]

All trademarks and copyrights on this page are owned by their respective parties. Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.
If a post contains personal/copyrighted/illegal content you can contact me at [email protected] with that post and thread number and it will be removed as soon as possible.
DMCA Content Takedown via dmca.com
All images are hosted on imgur.com, send takedown notices to them.
This is a 4chan archive - all of the content originated from them. If you need IP information for a Poster - you need to contact them. This website shows only archived content.