Share this: Facebook81 Twitter Google+ Reddit By Tom Phillips Published 07/02/2017
Steam users have today been warned to be careful browsing Steam - an XSS exploit has been discovered which could threaten your account's security.
1 The issue's existence was made public by a mod on Steam's official Reddit, and Steamdb has also confirmed the exploit to be worth taking note of - at least until Valve wakes up and fixes it.
Steam users are warned to be careful opening any profile pages on the service, and to ignore any suspicious links.
The exploit takes advantage of Steam's XSS (cross-site scripting) code which can be exploited to let others inject their own code. Anyone with the right know-how could harness your profile to perform actions on your behalf.
Anyone who thinks they may have been affected should change their password, enable a mobile authenticator - and scan their system for malware.
My PlayStation 4™ computer entertainment system doesn't have this issue.
Nolan Roberts
go trust sony with your credit card again or something
Jaxson Adams
Is this why steam has been offline the past couple hours?
Kayden Powell
You can just not use any of Steam's community features and use it just as a digital storefront.
Zachary Allen
Sticky this please Mods. OP implores you to keep this information relevant
Changed my Password in the steam client and I went above and beyond to create a new email. I changed my debit/payment info and more so..
Christopher Peterson
>mfw I clicked it
Cameron Robinson
You should be fine as long as you have the mobile authenticator.
Jack White
>make embarrassing post on steam forums, screencap it and share on Sup Forums >Sup Forums finds out your profile and bullies you >you get the last laugh as Sup Forums is fucked because your profile is boobytrapped with this exploit
Leo Gomez
MODS STICKY THIS
Oliver Martinez
I don't think I've clicked on anyone's profile today, so I should be fine.
Camden Scott
>tfw I have two step authentication on everything and no need to worry
Why wouldn't you?
Elijah Sullivan
1. First of all if you use the steam client browser (chromium) for any reason, you are a complete fucking idiot, you can not control the steam client browser it is locked down for retards, no adblock or noscript available
2. if you don't have adblock or noscript for your desktop browser and are browsing XSS sites you are a fucking idiot and deserved to be hacked.
Caleb Garcia
Wait, did anyone else have to log into Steam and authenticate again this morning? Also, all my Steam settings reset. I thought it was strange. Was that just a security precaution Valve took or did I get rekt?
Bentley Long
dont have a cell phone
Aiden Reyes
>Steam's official Reddit Uninstall.exe
Brody Brown
>csgo.gif
Leo Hernandez
LOL
Liam Wood
Restarted steam a while ago to update siege and that didnt happen to me.
Landon Young
reddit cancerous community aside is the best site for keeping up with devs since they only use twitter and reddit but hey you are probably a turboautist shitposter and I'm just easting my time talking to you so whatever
Jason White
You are fucked, good knowing you.
Cameron Rodriguez
You got rekt
Carter Hill
You might want to stop visiting Sup Forums, playing vidya, eating food and breathing air too.
Gavin Perry
>giving valve your phone number >giving psn/xbl your CC >Not using prepaid cards to purchase digitally
Dylan Sanders
>im poor >im retarded >i live in a third world country >im a backwards-ass high school dropout beta male >my parents hate me
jeez user say it dont spray it
Thomas Cox
>Was that just a security precaution Valve took or did I get rekt? Yes and no. It was me. I'm your biggest fan.
Adrian Hernandez
welp >clicked it then my steam client crashed >tries to log back in but fails >open up keepass to put in password manually, says it's incorrect >cool beans i guess
Levi Phillips
Memes aside, I wonder if there really was an attempt on my account and Steam guard simply prevented it and made me re-authenticate and shit.
Wonder why all my settings reset too though, it acted like a fresh Steam install.
Bentley Cox
clicking on the links here in your desktop browser will do nothing if you have noscript since it detects XSS
if you were dumb enough to browse Sup Forums on steams browser and click the links you are fucked.
Eli Torres
>Steam's official Reddit Jesus christ
Luis Gutierrez
Why would they need Reddit of all things? How is it better than twitter/facebook/their on user forums?
Elijah Davis
whats the point of owning a cell phone, user?
Luis Reyes
Nigger you got rekt Just wait a month or 2
Hunter Bennett
>tfw WP
Xavier Thompson
then use e-mail with different password, duh
Joseph Richardson
So? What's the problem?
Steam isn't DRM, remember? You don't need it or your account to play your games, right?
Camden Walker
Two-step verification lel
Nathan Myers
There is really no reason to piss away $500 plus contract fees for no real reason when I have a home PC and landline.
Parker Parker
To keep in touch with your friends of course! ;_;
Austin Adams
>be me >yesterday >click profiles >router clogging and slow as hell suddenly >get 'suspicious amount of traffic' notice >cant open any webpage >reset router over and over >nothing opens when i click it even after restarting >internet still slow >come to campus today and see this >mfw
passwords C H A N G E D
Christian Sanders
Nah, I've never lost an account in my life except my World of Warcraft one ten years ago, and that was only because I let my friend borrow it. Already quit the game anyway, otherwise I probably would have worked harder to get it back.
And this Steam account predates even that account.
Aiden Gonzalez
to call mummy to see what time she's getting home so you can eat din din
Nathaniel Kelly
I've no idea honestly
Ryder Campbell
kek, people unironically stay in contact with their """"friends""""?
Jonathan Jenkins
Can someone explain it for a lazy retard please? What does this mean if I don't use the browser in steam nor click on random faggot's profiles? I just changed my password for the hell of it.
Aaron Myers
>never check profiles because no friends >fight against a really good player yesterday >curious how many hours he has put into the game >search his name >10,000 results >start clicking down the line
Fuck's sake
Xavier Williams
...
Andrew Rivera
Do people realize phone authentication for steam for a while now ?
Grayson Baker
I you've been on the steam main page in the last 36 hours, you're fucked Doesn't matter which browser
Ethan Fisher
I think it was bothersome for everyone and everyone welcomed the chaotic facebook feed. I would honestly stop using a phone if it wasn't a huge red flag on the CVs. Just use the fucking e-mails.
Nathaniel Phillips
not that guy but what's the point of a smartphone? My phone is some 15 year old Nokia and it does what it's supposed to, text and call Smartphone users should just KYS, would make the world a better place
Jonathan Bell
They've actually made an official one now
William Russell
Steamguard without phone authentication has also existed for a long time, normie
Michael Peterson
how do you do it without a phone?
Cooper Lewis
Steam Store is fine, its the user editable profiles that arent
Wyatt Davis
>KYS Are you twelve?
Alexander Phillips
>using javascript botnet >not using noscript
Wew lad I thought you were smarter than this Sup Forums
Oh wait.
Ryder Cruz
Why the fuck did do it and continue when even because though it was fucked?"
Cameron Jones
You're either my grandmother or a contrarian if you don't see the benefit of having a small computer with constant internet access with you all the time. Of course if you don't leave your room it may seem like a toy. Still doesn't make you less wrong.
Dominic Gray
I do SSH to my client's servers, Browse the web including 4chins, watch some youtube and chat.
Kayden King
Not sure if you're fucking around or what? The reddit post suggests it's strictly a chance from looking at the feed shite or profiles which I do neither of. If the store were fucked everyone would be.
Jack Edwards
E-mail with the security code if someone logs in from a new IP Back to Plebbit you go
Dylan Fisher
This happens to me occasionally too. I don't know why it happens but it's just a minor annoyance. I don't think I've had my account stolen considering how I never got a notification about some other IP trying to access my account.
Elijah Fisher
People got around for thousands of years without having to have constant internet access. Treat your addiction, Millennial.
Sebastian Hughes
Wew, I though they would never do that, because WP is not that popular.
Jaxson Hughes
I think it's happened to me once before. but I've been on Steam for twelve years so quite a coincidence that this happened when this supposed security problem did.
Alexander Mitchell
Oh I thought you meant something else. I've been doing the email thing for years.
Gabriel Reed
Okay, you're baiting.
Gavin Brooks
>tfw i dont care anymore
Mason Parker
>Not blocking XSS requests I guess it could still work in the Steam client? Then again, fuck the whole community bullshit of Steam, just play the fucking games.
Brody Hill
>using 90s internet >ads everywhere >never had an Anti-virus scanner >scan PC in 2000s, i had 500+ viruses, trojans, keyloggers etc.
no personal details were stolen because back then modern social media sites didn't exist and everyone relied on alias, everyone knew to not input personal information of any kind
and that still blows my mind
Adrian Garcia
This is some low quality trolling right here.
Asher Morales
oh nooo people will steal my account that i never use with a total of 6 games
Sebastian Hernandez
Does anyone actually use the steam browser? It feels like fucking using a browser from 12 years ago with none of the improvements or features since then If I want to open a link a friend sends me, I'd rather fucking alt+tab out of the game to open it in my proper browser than opening it in the steam browser
Jaxson Ross
>using the steam browser ever >not having noscript and umatrix have your back >looking at other people's steam profiles >not using 2-step authentification >saving passwords on your pc or using password managers instead of memorizing them >giving steam, psn, xbl and payment info you deserve every bit of trouble coming your way
Xavier Hernandez
> fuck the whole community bullshit of Steam true, the only thing worth a damn is the community market and workshop
Leo Sullivan
fucking THIS
The amount of people i see freely giving away their personal data just because it ask them to is seriously fucked.
Logan Martin
It's okay when a game refuses to alt+tab and I quickly need to look something up. Otherwise, no. It's terrible.
Mason Reyes
people have been complaining to fat shit gabe to fix the browser since 2009 and even prior to that.
Cooper Stewart
Most of Steam is displayed in the browser.
Julian Sullivan
Can I have it? :^)
Adam Rogers
perhaps Valve should implement Webkit into Steam or something.
Luke Rogers
>everyone knew to not input personal information of any kind Social Media is so fucking stupid I sometimes read youtube comments (it's a guilty pleasure shut up) and there's fucking 11 year old kids throwing tantrums or having stupid arguments, and they all have their real name attached to their account
Jace Sanchez
Yeah, I use it almost every time I start Steam in fact.
Robert Gray
Oh right, that's another thing One time, a friend offhandedly mentioned something about the store interface or somesuch, and I realized he's actually using the fucking steam browser to look at sales The only thing I ever look at is my library, all the looking at profiles or buying games I do in a real browser
Andrew James
>you made a comment using your real name in 2003 on some derelict website >manage to contact someone in charge and they take down the WHOLE website what have I done
Jason Fisher
but what about my stteam bf
Michael Collins
God's work, user. Purge the filth.
Angel Gutierrez
They already have.
They used to use IE.
Aaron Jones
I don't get it so if I just use my account to only play games and not erp with homos or furfags as usual I'm unaffected?
Jayden Wood
Shit works off nearly every steam page btw. Your activity feed, boards, even fucking reviews.
Just stay the fuck off steam until it's fixed.
Nolan Foster
basically, remove all russians from your friends list.
Samuel Garcia
>tfw recently remember i had a myspace full of cringey shit, using my real name >tfw my avatar was starscream from the bayformers >tfw i had a three days grace backround >tfw i had pics of me in a fedora
ive never been so driven to eradicate something so quickly as i was then
Dominic Jones
I use it to look up shit about games that am playing, especially trivia about things I've done on repeat playthroughs of a game.
Matthew Walker
Gabe, if you haven't already, STOP STUFFING YOUR FACE AND FIX THIS