Just a major heads up, but there's a huge security flaw that was just exposed, allowing people to execute code on profiles. So far I've only seen one profile that can do this, but it can comment for you, it can load iframes, and it can play youtube videos. It will fuck up your notifications.

DO NOT LINK THESE PROFILES IN THE FORUMS, IN CHAT, OR ANYWHERE.

Issue has been fixed. Profiles are now safe again.

9 years ago*

Comment has been collapsed.

they didn't release any official info (because there's probably none with valve in charge), so i'll go safe and wait a few days before going back to trading and stuff.

9 years ago
Permalink

Comment has been collapsed.

It's safe as normal now though, confirmed by SteamDB and others.

9 years ago
Permalink

Comment has been collapsed.

Ok, so emoticons on Summary don't work anymore?

9 years ago
Permalink

Comment has been collapsed.

Yup, it appears that way. Emoticons were part of what was causing the exploit, so removing them from profile summaries means the exploit can't be done anymore.

9 years ago
Permalink

Comment has been collapsed.

What part exactly is considered the profile summary? Because ...

View attached image.
9 years ago
Permalink

Comment has been collapsed.

After you edit your profile showcase and click save, emoticons will be gone, and will be shown like :skyelaugh:

9 years ago
Permalink

Comment has been collapsed.

Here's the catch: The first emoticon (:squirtheh:) was in there for months, the second one (:squirtyay:) was just edited in after I read the messages above.

9 years ago
Permalink

Comment has been collapsed.

Well yeah seems that, my :borderlands2: emoticon is not showing, but the :vault: still does, didn't notice before. I only noticed that my showcase description was no longer showing emoticons after edit, so I supposed all emoticons are affected, but seems not, maybe there is a character number limitation?

9 years ago
Permalink

Comment has been collapsed.

Guess we just have to wait and see how this will end. ;)

9 years ago
Permalink

Comment has been collapsed.

My emoticons work again :P

9 years ago
Permalink

Comment has been collapsed.

as sviat basically said, it's only on edit that the emotes will no longer show up. For an example, view my profile, you can see that :B1: is not parsed as an emote.

9 years ago
Permalink

Comment has been collapsed.

i just checked my profile. surgeon simulator emoticons are not showing up but goat simulator emoticon is still there. how come? any idea? :|

9 years ago
Permalink

Comment has been collapsed.

I actually can't say for certain, I don't know myself, but if I had to guess? It could be to do with the :ss13brain: emotes being within formatting tags, while the Goat Simulator one is not.

9 years ago
Permalink

Comment has been collapsed.

Probably, it hasn't been fixed all. I've found other bugs on a page created by him. Don't be too relaxed. Strange thing happened, it reminded me when I was young and beautiful.

9 years ago
Permalink

Comment has been collapsed.

It has been fixed. Any other bugs, might not have been. Any other bugs, are not as serious, unless you can show me why they are. The emotes were key to causing this exploit, and aren't in place on forums or profiles anymore.

9 years ago
Permalink

Comment has been collapsed.

What do you know about other bugs? don't be conceited. I can tell you that a page created by him is bugged and visibly bugged. Bugs are bugs and Steam can tell you if they are serious or not not me. I have no interest to investigate about this to tell you it.

PS. In the meantime seems it has been fixed too.

9 years ago*
Permalink

Comment has been collapsed.

I don't know about other bugs, hence "not as serious, unless you can show me where they are". I was asking you to impart your information if you had any. I know there aren't any other major ones that are public knowledge right now, and that's all I can tell anyone.

9 years ago
Permalink

Comment has been collapsed.

Ops, mistyped, I meant I can* tell...

9 years ago
Permalink

Comment has been collapsed.

Wow... that's heavy. No virus or fake links needed, just your own profile.
Good it's fixed now.

9 years ago
Permalink

Comment has been collapsed.

Happy Cake Day!!

9 years ago
Permalink

Comment has been collapsed.

Happy Cake Day!

9 years ago
Permalink

Comment has been collapsed.

Caaaaaaake!

9 years ago
Permalink

Comment has been collapsed.

I think if you add a ~~ it does the strikethrough on your message.

let's test

9 years ago
Permalink

Comment has been collapsed.

...Thanks. I was using Steam's markup, not Steamgifts, I didn't even notice until now.

9 years ago
Permalink

Comment has been collapsed.

No worries. I had to look it up to be sure. Thought it was single ~ at first, but apparently that's how you spoiler things.

9 years ago
Permalink

Comment has been collapsed.

Good to ear that this issue was fixed since i read your post i keep away from chechking any profile link :?

9 years ago
Permalink

Comment has been collapsed.

Sign in through Steam to add a comment.