Valve not discussing this is what has led to it being exposed, by a developer, in an attempt to getting it fixed. However, they're fucking idiots for doing it, because now anyone can do it.
The best source other than myself for this information right now, is steamDB's twitter, over here. https://twitter.com/SteamDB/status/574256881721548800
Comment has been collapsed.
Do you mean the exploit can be used to make false feedback on SteamTrades ? Or just feedback on Steam profiles ?
Because I'm pretty sure no one takes Steam profiles rep seriously.
Comment has been collapsed.
I mean real Steam profile links. And this includes in client, as well as in browser.
I got this information first hand, a developer exploited it to expose it, in an attempt to get it fixed by Valve quicker. Unfortunately, by making the exploit public, anyone can do it now.
Another source other than myself is SteamDB https://twitter.com/SteamDB/status/574256881721548800
Comment has been collapsed.
Seems like it's an XSS exploit which could lead to dangerous things.
Comment has been collapsed.
It's only happening if you click on Steam profiles, not profiles on SG.
Comment has been collapsed.
Potentially, but I would not risk it. It seems that the exploit could potentially edit profiles without the user's consent, so might propagate itself. Also, it's not entirely certain, but it might be possible to add the exploit by commenting on a profile as well, rather than just having it on the profile.
Comment has been collapsed.
Thanks for the heads up. I managed to dodge this bullet, but others that I know have been hit by it. P
I assume there's already a thread about this in the Steam forum?
Comment has been collapsed.
I've been trying to find something on the Steam forum, but I haven't been able to locate anything regarding this.
Comment has been collapsed.
So if I go to someone's SG profile and then I click to see his Steam profile, am I in danger ?
Comment has been collapsed.
What about accepting friend invites? Can it compromise security?
Comment has been collapsed.
What's the danger with bots? I mean, can actually having a bot on your friend list affect you in some way?
Comment has been collapsed.
^same thing wanted to ask as JasmineMcCoy, and when blocking scam bots, if you click their profile in Steam client, can it affect you? I clicked one few hours ago, but I don't see any changes, nothing happened so far, it was a CSGO scam bot profile.
Comment has been collapsed.
1,709 Comments - Last post 44 minutes ago by SebastianCrenshaw
4 Comments - Last post 47 minutes ago by WastedYears
35 Comments - Last post 1 hour ago by sensualshakti
151 Comments - Last post 2 hours ago by MeguminShiro
519 Comments - Last post 3 hours ago by Choutas
11 Comments - Last post 4 hours ago by doomofdoom
29 Comments - Last post 8 hours ago by lostsoul67
6 Comments - Last post 2 minutes ago by HappyCakeday
1 Comments - Last post 2 minutes ago by Mayanaise
492 Comments - Last post 5 minutes ago by GreyF0xx
9,481 Comments - Last post 47 minutes ago by CurryKingWurst
16,733 Comments - Last post 49 minutes ago by RDMCz
148 Comments - Last post 55 minutes ago by VladislavDracula
27 Comments - Last post 1 hour ago by xandyvan
Just a major heads up, but there's a huge security flaw that was just exposed, allowing people to execute code on profiles. So far I've only seen one profile that can do this, but it can comment for you, it can load iframes, and it can play youtube videos. It will fuck up your notifications.DO NOT LINK THESE PROFILES IN THE FORUMS, IN CHAT, OR ANYWHERE.
Issue has been fixed. Profiles are now safe again.
Comment has been collapsed.