registerlogin | squad up
  3,323 HIPHOP SPORTS WILD ISH NEWS open menu
THOTTIES        TV/MOVIES        GAMING        RANDOM ISH        GOOD EATS        BXWF        GEAR        GUAP        TECH

Security flaw for unlimited Steam Wallet funds found, fixed

ADVERTISEMENT
People viewing this now  1   0 bx goons and 1 bystanders Share this on Twitter       Share this on Facebook

 
section gaming
 
@
avatar
Faythung triple plat x2
Props 42 K    
  '12 
A security researcher picked up a $7,500 bounty for the find.

With the help of a security researcher, Valve has found and fixed an exploit that would have allowed a user to falsify the value of deposits to their Steam wallet. The exploit worked by—for example—turning a $1 deposit into a $100 deposit. It was accomplished by changing the account's email address to one including "amount100," then intercepting a message to a payment company API.

The writeup for the hack was posted on white-hat hacking bug bounty site HackerOne by the handle drbrix. Valve and drbrix later made the exchange public, once a fix was implemented. Drbrix first posted the bug as "medium" priority, saying "I think impact is pretty obvious, attacker can generate money and break steam market, sell game keys for cheap etc."

Valve, after testing the exploit and trying a fix, subsequently upgraded the bug to "Critical" severity and the corresponding payout to $7,500 USD "reflecting the potential cost to the business."

"We hope to hear more from you in the future," the Valve staff said.

Yes, I'm sure they would.

Valve told The Daily Swig that "Thanks to the person who reported this bug we were able to work with the payment provider to resolve the issues without any impact on customers." Valve did not say whether anyone had actually abused the potential exploit.

 Source
+2   
4 comments best trash
avatar
Novii triple plat x12
Props 28 K    
  '16 
But......Was it really worth it though?
emoji
avatar
P-Hill
Props 47 K    
  '05 
Hackers are different.

Don't even know what would possess one to change their email to include "amountX" ..
+1   
avatar
Top 10 most propped recently OldBusiness triple plat x5
Props 255 K    
  '12 
 P-Hill said
Hackers are different.

Don't even know what would possess one to change their email to include "amountX" ..
 Novii said
But......Was it really worth it though?
emoji
Probably no punishment coming, as Valve has been paying hackers who find exploits pretty good for like 13 or 14 years. So it looks like the hacker took the quick payday rather than exploiting it - cashing in off it - and eventually getting hit with charges.

They actually invite and pay successful hacking attempts cause they use it to plug holes.

Heres an article from 2008 about it:

emoji

One from 2018:

emoji

And heres a dude who got a 20 thousand dollar check for finding a flaw:

emoji

And they'd paid him 25 thousand a few months before that for finding another flaw.

They learned to embrace that sh1t and just pay + plug the hole after them Russians cracked Ubisoft's PC Catalog before Uplay and had folks downloading source code for games + Ubi's whole PC Library/Catalog..

Them dudes gave away 58 million folks personal information + everything on Ubisoft's systems
emoji


Last edited by OldBusiness; 08-15-2021 at 10:17 PM..
+1   
avatar
Occult Mayne triple plat x10
Props 87 K    
  '19 
 OldBusiness said
Probably no punishment coming, as Valve has been paying hackers who find exploits pretty good for like 13 or 14 years. So it looks like the hacker took the quick payday rather than exploiting it - cashing in off it - and eventually getting hit with charges.

They actually invite and pay successful hacking attempts cause they use it to plug holes.

Heres an article from 2008 about it:

emoji

One from 2018:

emoji

And heres a dude who got a 20 thousand dollar check for finding a flaw:

emoji

And they'd paid him 25 thousand a few months before that for finding another flaw.

They learned to embrace that sh1t and just pay + plug the hole after them Russians cracked Ubisoft's PC Catalog before Uplay and had folks downloading source code for games + Ubi's whole PC Library/Catalog..

Them dudes gave away 58 million folks personal information + everything on Ubisoft's systems
emoji
Unlike Sony who had the PS3 unplayable for damn near a year and aint fix nothin or apologize or give refunds
emoji
say something...


Sign me up
 
 
yesterday
most viewed right now
+49
Video inside Bruh I’ve Watched This Clip A Million Times And Never Caught This Until..
18 sectionmovies  •  99 replies  •  31 min ago
by JohnnyCage202  •  19 hr
most viewed right now
+126
This is how much we pay for being lazy
10 sectionwild'ish  •  124 replies  •  36 min ago
by Kodack sixnine  •  1 d
back to top
register iwantin contact privacyprivacy/DMCA