Valve not discussing this is what has led to it being exposed, by a developer, in an attempt to getting it fixed. However, they're fucking idiots for doing it, because now anyone can do it.
The best source other than myself for this information right now, is steamDB's twitter, over here. https://twitter.com/SteamDB/status/574256881721548800
Comment has been collapsed.
Do you mean the exploit can be used to make false feedback on SteamTrades ? Or just feedback on Steam profiles ?
Because I'm pretty sure no one takes Steam profiles rep seriously.
Comment has been collapsed.
I mean real Steam profile links. And this includes in client, as well as in browser.
I got this information first hand, a developer exploited it to expose it, in an attempt to get it fixed by Valve quicker. Unfortunately, by making the exploit public, anyone can do it now.
Another source other than myself is SteamDB https://twitter.com/SteamDB/status/574256881721548800
Comment has been collapsed.
Seems like it's an XSS exploit which could lead to dangerous things.
Comment has been collapsed.
It's only happening if you click on Steam profiles, not profiles on SG.
Comment has been collapsed.
Potentially, but I would not risk it. It seems that the exploit could potentially edit profiles without the user's consent, so might propagate itself. Also, it's not entirely certain, but it might be possible to add the exploit by commenting on a profile as well, rather than just having it on the profile.
Comment has been collapsed.
Thanks for the heads up. I managed to dodge this bullet, but others that I know have been hit by it. P
I assume there's already a thread about this in the Steam forum?
Comment has been collapsed.
I've been trying to find something on the Steam forum, but I haven't been able to locate anything regarding this.
Comment has been collapsed.
So if I go to someone's SG profile and then I click to see his Steam profile, am I in danger ?
Comment has been collapsed.
What about accepting friend invites? Can it compromise security?
Comment has been collapsed.
What's the danger with bots? I mean, can actually having a bot on your friend list affect you in some way?
Comment has been collapsed.
^same thing wanted to ask as JasmineMcCoy, and when blocking scam bots, if you click their profile in Steam client, can it affect you? I clicked one few hours ago, but I don't see any changes, nothing happened so far, it was a CSGO scam bot profile.
Comment has been collapsed.
236 Comments - Last post 1 hour ago by sfkng
21 Comments - Last post 1 hour ago by Rabban
913 Comments - Last post 1 hour ago by MeguminShiro
115 Comments - Last post 2 hours ago by Reidor
449 Comments - Last post 5 hours ago by Chris76de
40 Comments - Last post 9 hours ago by ImpAtience
1,041 Comments - Last post 10 hours ago by Spez95
354 Comments - Last post 1 minute ago by Ali811
14 Comments - Last post 3 minutes ago by FlameB1
48 Comments - Last post 3 minutes ago by herbesdeprovence
109 Comments - Last post 25 minutes ago by Webraven
983 Comments - Last post 38 minutes ago by Chris76de
100 Comments - Last post 42 minutes ago by quijote3000
6,566 Comments - Last post 58 minutes ago by DkXfS
Just a major heads up, but there's a huge security flaw that was just exposed, allowing people to execute code on profiles. So far I've only seen one profile that can do this, but it can comment for you, it can load iframes, and it can play youtube videos. It will fuck up your notifications.DO NOT LINK THESE PROFILES IN THE FORUMS, IN CHAT, OR ANYWHERE.
Issue has been fixed. Profiles are now safe again.
Comment has been collapsed.