Just a major heads up, but there's a huge security flaw that was just exposed, allowing people to execute code on profiles. So far I've only seen one profile that can do this, but it can comment for you, it can load iframes, and it can play youtube videos. It will fuck up your notifications.

DO NOT LINK THESE PROFILES IN THE FORUMS, IN CHAT, OR ANYWHERE.

Issue has been fixed. Profiles are now safe again.

9 years ago*

Comment has been collapsed.

I wonder if the steam forums are safe. Seems like anything you can execute in your profile should be able to execute on the forums as well.

9 years ago
Permalink

Comment has been collapsed.

To my knowledge, the exploit is only possible in profile summaries, and was fixed everywhere else before this.

9 years ago
Permalink

Comment has been collapsed.

Well I hope it's fixed soon. I guess I'll stop sending out gifts for a while until it's fixed

9 years ago
Permalink

Comment has been collapsed.

Oh, damn it, Volvo...

9 years ago
Permalink

Comment has been collapsed.

Volvo?

9 years ago
Permalink

Comment has been collapsed.

last i knew it was a vehicle

but steam loves this stupid little things like Thanks for Skyrim,Heresy,and countless others for some reason people like to be a follower and not a leader so they copy what others say and think it is funny when it just silly and annoying.

None the less it just how i feel and this whole exploit thing just get use to it as long as idiots fall for scams and click on links they should not and have inventory it is always going to be at risk.Pretty much as long as there is steam gifts and trading there will always be hackers or exploits to just and scam people out of there stuff.

9 years ago
Permalink

Comment has been collapsed.

Calling them Valve is being a leader?

9 years ago
Permalink

Comment has been collapsed.

Yea...i didnt understand much of that either...

9 years ago
Permalink

Comment has been collapsed.

Deleted

This comment was deleted 2 years ago.

9 years ago
Permalink

Comment has been collapsed.

I just clicked on the profile of 2 bots.....

9 years ago
Permalink

Comment has been collapsed.

You should be fine.

9 years ago
Permalink

Comment has been collapsed.

Couldnt a malicious user potentially use Steamgifts giveaways as a shoehorn into something like this exploit? "Will friend request the winner" a.s.o....

9 years ago
Permalink

Comment has been collapsed.

Potentially, but as long as you just follow the general rule of not visiting profiles until it is fixed, should still be fine.

9 years ago
Permalink

Comment has been collapsed.

Deleted

This comment was deleted 6 years ago.

9 years ago
Permalink

Comment has been collapsed.

But don't ya worry, they added captchas all over the place. -___-

9 years ago
Permalink

Comment has been collapsed.

Fun fact that's no longer relevant, but this actually happened. There was an exploit that got downloaded with the game "Portal 2 - The Final Hours". It was fixed after that.

9 years ago
Permalink

Comment has been collapsed.

Thank you for alerting this to everyone, looks like i'm going to lay off trading today.

9 years ago
Permalink

Comment has been collapsed.

i just clicked a bot profile to report it and block it.... Oh no...

9 years ago
Permalink

Comment has been collapsed.

You should be fine, the bots don't seem have to caught on.

9 years ago
Permalink

Comment has been collapsed.

Why do I have a feeling that this is going to spread like wild fire, before Valve fix it?

Thanks for the PSA, Deiru.

9 years ago
Permalink

Comment has been collapsed.

Yea, with them (or at least the SteamDB twitter guys) acting all like Barbrady from South Park: "Move along, nothing to see here!" and trying to downplay how serious this is i agree with you.

9 years ago
Permalink

Comment has been collapsed.

They never fixed this? Gaddangit valve! Welp, now that pretty much everybody on the planet knows of it now time to set everything to private. :/

9 years ago
Permalink

Comment has been collapsed.

Thx to for the heads up..and in a better world i would have expected Volvo for shutting down the profiles until the problem is solved..

9 years ago
Permalink

Comment has been collapsed.

Wow, that's interesting. Thank you for the heads up, Deiru.

9 years ago
Permalink

Comment has been collapsed.

any ideas on when would this be fixed?

9 years ago
Permalink

Comment has been collapsed.

Eh, not cool. I visit quite a few profiles, and check my own frequently. I've disabled all comments on mine, made inventory private, and will keep email trade notifications enabled. Hopefully that will keep my own profile safe to view... :/

9 years ago
Permalink

Comment has been collapsed.

Then that's why Steam's support is taking so much to attend my ticket? :P

9 years ago
Permalink

Comment has been collapsed.

Wasn't there like the SAME issue with steam store pages where devs could put malicious shit on their game page; and it was known for like forever but Valve didn't do shit about it... Then when a dev decided to demonstrate the exploit to urge them to action he got banned or something? You'd think they'd check around for similar things elsewhere after an incident like that....?

9 years ago
Permalink

Comment has been collapsed.

Nope, not unless it loses them money. -.-

9 years ago
Permalink

Comment has been collapsed.

Yeah, that was Timmy, the PR guy from SCS Software aka the Euro Truck devs.

9 years ago
Permalink

Comment has been collapsed.

So that's why these invites keep popping up now. And I did check one of them because of a higher lvl :(
Hope it was clean...

9 years ago
Permalink

Comment has been collapsed.

Would this apply to steam groups as well maybe?

9 years ago
Permalink

Comment has been collapsed.

Really hope not... :(

9 years ago
Permalink

Comment has been collapsed.

Not at all.

9 years ago
Permalink

Comment has been collapsed.

Surprised it would not affect groups but would affect profiles.

9 years ago
Permalink

Comment has been collapsed.

My own profile should be safe as long as i keep comments private and dont talk, friend, chat or trade with anyone or watch their profile?

9 years ago
Permalink

Comment has been collapsed.

As long as you don't visit a profile, you should be fine.

9 years ago
Permalink

Comment has been collapsed.

Imagine this happening on facebook, there would be ALOT of pissed off stalkers ...
Anyways this problem didn't just apear out of thin air, why did they take their sweet time fixing in?

9 years ago
Permalink

Comment has been collapsed.

Because they dont lose any money on it and because it will either be forgotten quickly or make people who are unaware of them aware.

9 years ago
Permalink

Comment has been collapsed.

Using steam client is like walking on a minefield atm. Thanks for the heads up.

9 years ago
Permalink

Comment has been collapsed.

I just visited a bunch of profiles recently D:

Thanks for the heads up.

9 years ago
Permalink

Comment has been collapsed.

The XSS issue on Steam Community has been resolved.
https://twitter.com/SteamDB

9 years ago
Permalink

Comment has been collapsed.

That was quick. But I am afraid to find out for sure. I think I might stay off profiles for the rest of the day just in case they forgot something. lol

9 years ago
Permalink

Comment has been collapsed.

yeah,i think it's better to wait for a response from valve (if there's going to be any :| )

9 years ago
Permalink

Comment has been collapsed.

They could just be saying that to stop people from panicking.

Also check the comments to that tweet, either there is some serious blackmailing and funny stuff going on, or someone didn't read the "list" with those few times when trolling should not be done, no matter how inviting.

9 years ago
Permalink

Comment has been collapsed.

They are not, SteamDB is a third party not affiliated with Steam, and I can confirm that the issue is fixed.

9 years ago
Permalink

Comment has been collapsed.

+1

9 years ago
Permalink

Comment has been collapsed.

And how do YOU confirm it? You have something else than the third-party "probably to prevent panic" SteamDB tweet we others do?

Not trying to sound like an asshole, but blowing the "all clear" too early have been done numerous times before.

9 years ago
Permalink

Comment has been collapsed.

Well, for one, SteamDB have literally no reason to "Prevent panic", considering they also posted an announcement similar to mine. For another, I'm friends with a lot of the SteamDB guys, I trust their work, and they've shown enough to me that I can see it is fixed.

9 years ago
Permalink

Comment has been collapsed.

SteamB have no reason to report the issue in the first place either then.

You are friends with them you say, doesn't mean much to me since i dont know you, but i have no reason not to trust you. I will keep my hand on my gun and my eyes open though.

9 years ago
Permalink

Comment has been collapsed.

SteamDB may be a third party, but honestly? They are the best community relations that Steam has. They report on things before I see them on Steam most times, and I have never been misled by them. Exercising caution is always a good idea, but I put my money on profiles being safe again now.

9 years ago
Permalink

Comment has been collapsed.

I didnt even know about SteamDB until now.

9 years ago
Permalink

Comment has been collapsed.

Also, have anyone noticed that Twitch has kind of acted up today? (It has for a lot of people). Possible link?

(Not trying to make conspiracy theories, i'm just throwing it out there, just in case.)

9 years ago
Permalink

Comment has been collapsed.

Twitch always acts up :P No link whatsoever.

9 years ago
Permalink

Comment has been collapsed.

Deleted

This comment was deleted 9 years ago.

9 years ago
Permalink

Comment has been collapsed.

Already posted 16 minutes ago

9 years ago
Permalink

Comment has been collapsed.

Fixed

9 years ago
Permalink

Comment has been collapsed.

Sign in through Steam to add a comment.