Just a major heads up, but there's a huge security flaw that was just exposed, allowing people to execute code on profiles. So far I've only seen one profile that can do this, but it can comment for you, it can load iframes, and it can play youtube videos. It will fuck up your notifications.

DO NOT LINK THESE PROFILES IN THE FORUMS, IN CHAT, OR ANYWHERE.

Issue has been fixed. Profiles are now safe again.

9 years ago*

Comment has been collapsed.

Could you clarify the "do not click steam profile links" part?
Are you referring to the button on SG profiles, or url's in comments?

9 years ago
Permalink

Comment has been collapsed.

I mean, do not visit any Steam profiles whatsoever. Steamgifts site is not affected. But any links that lead to a steam profile, are unsafe at the current moment in time.

9 years ago
Permalink

Comment has been collapsed.

That sounds huge, got any source for that preferably from valve, or is this something currently being discussed on social media without any public statement from valve?

9 years ago
Permalink

Comment has been collapsed.

Valve not discussing this is what has led to it being exposed, by a developer, in an attempt to getting it fixed. However, they're fucking idiots for doing it, because now anyone can do it.

The best source other than myself for this information right now, is steamDB's twitter, over here. https://twitter.com/SteamDB/status/574256881721548800

9 years ago
Permalink

Comment has been collapsed.

Thanks a lot for the heads up, seems traders have to be extra careful since it is mentioned there that theoretically trade offers could be sent as well.

9 years ago
Permalink

Comment has been collapsed.

Yes. It's also worth noting that after this glitch ends, check REP on all traders, specifically dates, since this can be used to flood profile comments of any visitor, possible garnering fake reps from reputable accounts.

9 years ago
Permalink

Comment has been collapsed.

Do you mean the exploit can be used to make false feedback on SteamTrades ? Or just feedback on Steam profiles ?

Because I'm pretty sure no one takes Steam profiles rep seriously.

9 years ago
Permalink

Comment has been collapsed.

Only on Steam Profiles. And some people still check that.

9 years ago
Permalink

Comment has been collapsed.

View attached image.
9 years ago
Permalink

Comment has been collapsed.

im scared.. you are everywhere :S

9 years ago
Permalink

Comment has been collapsed.

I is ononynous, I is evrywhere, we du not forgiv, we do not froget.

View attached image.
9 years ago
Permalink

Comment has been collapsed.

fatonynous is better .-.

9 years ago
Permalink

Comment has been collapsed.

u gettin haxed m8

9 years ago
Permalink

Comment has been collapsed.

Except that this isn't anything like a scam link.

You should maybe read the opening posts. Just saying.

9 years ago
Permalink

Comment has been collapsed.

Sorry not sorry

9 years ago
Permalink

Comment has been collapsed.

That's nice, dear.

9 years ago
Permalink

Comment has been collapsed.

k™

9 years ago
Permalink

Comment has been collapsed.

oh come on those guys how create this bullshits dont they have something good to do....

9 years ago
Permalink

Comment has been collapsed.

Apparently not. P

9 years ago
Permalink

Comment has been collapsed.

You mean real Steam profile links, or phishing links that look like Steam profile links?....because these are different things. And from where you get this info?

9 years ago
Permalink

Comment has been collapsed.

I mean real Steam profile links. And this includes in client, as well as in browser.
I got this information first hand, a developer exploited it to expose it, in an attempt to get it fixed by Valve quicker. Unfortunately, by making the exploit public, anyone can do it now.

Another source other than myself is SteamDB https://twitter.com/SteamDB/status/574256881721548800

9 years ago
Permalink

Comment has been collapsed.

Seems like it's an XSS exploit which could lead to dangerous things.

9 years ago
Permalink

Comment has been collapsed.

Thank you for warning!

9 years ago
Permalink

Comment has been collapsed.

Deleted

This comment was deleted 6 years ago.

9 years ago
Permalink

Comment has been collapsed.

It's only happening if you click on Steam profiles, not profiles on SG.

9 years ago
Permalink

Comment has been collapsed.

Steamgifts profiles are safe. Only Steam profiles themselves are currently unsafe.

9 years ago
Permalink

Comment has been collapsed.

Deleted

This comment was deleted 6 years ago.

9 years ago
Permalink

Comment has been collapsed.

GG Volvo, now we wait for that developer who wanted to help get banned, since valve is crappy and useless as ever. And silent ofc, no need to mention

9 years ago
Permalink

Comment has been collapsed.

Thanks for the heads up Deiru!

9 years ago
Permalink

Comment has been collapsed.

It's only link to profile, right? I can still check my inventory and badges and etc..?

9 years ago
Permalink

Comment has been collapsed.

Only profiles are currently affected, as far as we can tell.

9 years ago
Permalink

Comment has been collapsed.

Thanks for the warning.

9 years ago
Permalink

Comment has been collapsed.

Deleted

This comment was deleted 2 years ago.

9 years ago
Permalink

Comment has been collapsed.

Gifting does not have that additional confirmation step, so any inventory gifts could potentially be at risk as well. As well as this, many users turned off the email trade verification due to it being annoying.

9 years ago
Permalink

Comment has been collapsed.

Deleted

This comment was deleted 2 years ago.

9 years ago
Permalink

Comment has been collapsed.

I was one of those users... but I just turned this feature on again!

9 years ago
Permalink

Comment has been collapsed.

So it's safe for those who have NoScript then.

9 years ago
Permalink

Comment has been collapsed.

No, Noscript is not picking this up, and it affects Steam Client as well.

9 years ago
Permalink

Comment has been collapsed.

So to clarify, if you visit a profile where someone has intentionally used this exploit, it can effect you. So visiting your own profile or that of a trustworthy friend should be ok?

9 years ago
Permalink

Comment has been collapsed.

Yup.

9 years ago
Permalink

Comment has been collapsed.

we all know which profile is not safe . . x. . a. . . ..

9 years ago
Permalink

Comment has been collapsed.

Potentially, but I would not risk it. It seems that the exploit could potentially edit profiles without the user's consent, so might propagate itself. Also, it's not entirely certain, but it might be possible to add the exploit by commenting on a profile as well, rather than just having it on the profile.

9 years ago
Permalink

Comment has been collapsed.

Wow, ok.

9 years ago
Permalink

Comment has been collapsed.

Deleted

This comment was deleted 2 years ago.

9 years ago
Permalink

Comment has been collapsed.

I changed my settings from only friends can comment to only I can comment on my profile. This way I assume my profile stays save (until I visit an evil profile that infects me) and I can at least visit my own profile page.

9 years ago
Permalink

Comment has been collapsed.

same here

9 years ago
Permalink

Comment has been collapsed.

Does that include my own profile? What about if I visit a profile from the friends list? Does that mean that every profile presents a vulnerability, or only profiles that are exploiting this vulnerability?

9 years ago
Permalink

Comment has been collapsed.

Just replied to Bobo with similar, but until it is fixed, treat every profile as a potential malicious one, since it could theoretically edit people's profiles without their consent.

9 years ago
Permalink

Comment has been collapsed.

I'm confused now: I've to treat my own profile as a malicious one?

9 years ago
Permalink

Comment has been collapsed.

Potentially, yes. I've not heard of anyone doing it yet, but the possibility exists.

9 years ago
Permalink

Comment has been collapsed.

So how are we supposed to know if someone/something is messing up my profile if I can't even access it? That's a fucked up security breach, if true.

9 years ago
Permalink

Comment has been collapsed.

Wait until it gets fixed, then check, nothing else we can do unfortunately.

9 years ago
Permalink

Comment has been collapsed.

Is this even discussed anywhere? Where can I check the progress of this "fix"?

9 years ago
Permalink

Comment has been collapsed.

Unfortunately, Steam are notoriously bad at communication regarding these things. I suggest following the @SteamDB twitter account for information, they're pretty much my go to. They're a third-party, but they're pretty good.

9 years ago
Permalink

Comment has been collapsed.

I've checked quite a few profiles in the past hour, including my own after finding this thread, what should I expect if I will be affected? Does this vulnerability take effect the moment you visit an exploited profile or what exactly?

9 years ago
Permalink

Comment has been collapsed.

Most of the exploits done with this so far were very high visibility, in the sense that if you were affected, you'd know. If you didn't see anything, you should be fine. But other than that, there is potentially no way to know.

9 years ago
Permalink

Comment has been collapsed.

If no one has left a comment on your profile recently, you can disable comments and your profile should be ok.

9 years ago
Permalink

Comment has been collapsed.

I never had comments enabled, since I don't like to clutter my profile.

9 years ago
Permalink

Comment has been collapsed.

Damn. O_o Thanks for the heads up indeed... now let's hope Valve will fix that real quick.

9 years ago
Permalink

Comment has been collapsed.

I was wondering why I got 2 invites today of people linking me the community. Good I deleted them without clicking the link.

9 years ago
Permalink

Comment has been collapsed.

Thanks for the heads up. I managed to dodge this bullet, but others that I know have been hit by it. P

I assume there's already a thread about this in the Steam forum?

9 years ago
Permalink

Comment has been collapsed.

I haven't checked myself, but it does appear that Valve is aware of the glitch.

9 years ago
Permalink

Comment has been collapsed.

I've been trying to find something on the Steam forum, but I haven't been able to locate anything regarding this.

9 years ago
Permalink

Comment has been collapsed.

Good luck. Anytime there is an issue with Steam itself, the mods cover it up very quickly.

9 years ago
Permalink

Comment has been collapsed.

So if I go to someone's SG profile and then I click to see his Steam profile, am I in danger ?

9 years ago
Permalink

Comment has been collapsed.

Yes. Any Steam Profile could be affected.

9 years ago
Permalink

Comment has been collapsed.

tnx you ;)

9 years ago
Permalink

Comment has been collapsed.

What about accepting friend invites? Can it compromise security?

9 years ago
Permalink

Comment has been collapsed.

Should be safe, beyond the normal bot invites.

9 years ago
Permalink

Comment has been collapsed.

What's the danger with bots? I mean, can actually having a bot on your friend list affect you in some way?

9 years ago
Permalink

Comment has been collapsed.

omg

9 years ago
Permalink

Comment has been collapsed.

In the past 2hours I've visited around 20 steam profiles(my friends)... >_> I quess I'm fu*ked? Anyway thanks for the heads-up :)

9 years ago
Permalink

Comment has been collapsed.

You should be fine, most of the current exploits based on it were high-visibility, and very obvious if they affected you.

9 years ago
Permalink

Comment has been collapsed.

based on last fixes from steam that prevent account hacking, we won't have any longer steam profiles

9 years ago
Permalink

Comment has been collapsed.

^same thing wanted to ask as JasmineMcCoy, and when blocking scam bots, if you click their profile in Steam client, can it affect you? I clicked one few hours ago, but I don't see any changes, nothing happened so far, it was a CSGO scam bot profile.

9 years ago*
Permalink

Comment has been collapsed.

Blocking directly from friend invites should be safe. Do not visit their profile, just in case.

9 years ago
Permalink

Comment has been collapsed.

Yes, it works in client & browser alike.

It isn't in the wild yet. There was one profile that had sample, but that's it. (It's down now).
It posted simple comment, so it not exactly unsafe.

9 years ago
Permalink

Comment has been collapsed.

It is in the wild. Once the "sample" was posted, people started copying it.

9 years ago
Permalink

Comment has been collapsed.

Thanks for this heads up

9 years ago
Permalink

Comment has been collapsed.

Sign in through Steam to add a comment.