Valve not discussing this is what has led to it being exposed, by a developer, in an attempt to getting it fixed. However, they're fucking idiots for doing it, because now anyone can do it.
The best source other than myself for this information right now, is steamDB's twitter, over here. https://twitter.com/SteamDB/status/574256881721548800
Comment has been collapsed.
Do you mean the exploit can be used to make false feedback on SteamTrades ? Or just feedback on Steam profiles ?
Because I'm pretty sure no one takes Steam profiles rep seriously.
Comment has been collapsed.
I mean real Steam profile links. And this includes in client, as well as in browser.
I got this information first hand, a developer exploited it to expose it, in an attempt to get it fixed by Valve quicker. Unfortunately, by making the exploit public, anyone can do it now.
Another source other than myself is SteamDB https://twitter.com/SteamDB/status/574256881721548800
Comment has been collapsed.
Seems like it's an XSS exploit which could lead to dangerous things.
Comment has been collapsed.
It's only happening if you click on Steam profiles, not profiles on SG.
Comment has been collapsed.
Potentially, but I would not risk it. It seems that the exploit could potentially edit profiles without the user's consent, so might propagate itself. Also, it's not entirely certain, but it might be possible to add the exploit by commenting on a profile as well, rather than just having it on the profile.
Comment has been collapsed.
Thanks for the heads up. I managed to dodge this bullet, but others that I know have been hit by it. P
I assume there's already a thread about this in the Steam forum?
Comment has been collapsed.
I've been trying to find something on the Steam forum, but I haven't been able to locate anything regarding this.
Comment has been collapsed.
So if I go to someone's SG profile and then I click to see his Steam profile, am I in danger ?
Comment has been collapsed.
What about accepting friend invites? Can it compromise security?
Comment has been collapsed.
What's the danger with bots? I mean, can actually having a bot on your friend list affect you in some way?
Comment has been collapsed.
^same thing wanted to ask as JasmineMcCoy, and when blocking scam bots, if you click their profile in Steam client, can it affect you? I clicked one few hours ago, but I don't see any changes, nothing happened so far, it was a CSGO scam bot profile.
Comment has been collapsed.
8 Comments - Last post 28 minutes ago by Vasharal
72 Comments - Last post 31 minutes ago by CommissarCiaphasCain
24 Comments - Last post 3 hours ago by MRWITEK
43 Comments - Last post 4 hours ago by valdrak3
643 Comments - Last post 6 hours ago by Yorickmeister
177 Comments - Last post 8 hours ago by wigglenose
286 Comments - Last post 10 hours ago by hbouma
92 Comments - Last post 10 seconds ago by Arwiee
43 Comments - Last post 1 minute ago by RosimInc
88 Comments - Last post 7 minutes ago by Leo64
17,008 Comments - Last post 26 minutes ago by Riszu
3,503 Comments - Last post 30 minutes ago by KPopPoyehavshiy
35 Comments - Last post 43 minutes ago by antidaz
144 Comments - Last post 44 minutes ago by DiabLXIX
Just a major heads up, but there's a huge security flaw that was just exposed, allowing people to execute code on profiles. So far I've only seen one profile that can do this, but it can comment for you, it can load iframes, and it can play youtube videos. It will fuck up your notifications.DO NOT LINK THESE PROFILES IN THE FORUMS, IN CHAT, OR ANYWHERE.
Issue has been fixed. Profiles are now safe again.
Comment has been collapsed.