It seems that you're using an outdated browser. Some things may not work as they should (or don't work at all).
We suggest you upgrade newer and better browser like: Chrome, Firefox, Internet Explorer or Opera

×
Don't visit ANY profiles, even your. An exploited was found and it can compromise your account my sending fake trade request, phishing links etc.

http://i.imgur.com/eUVqvCt.jpg
Thanks for the info! Seems to be for profiles only for now. Best to be careful and go off-the radar for a few days and stay offline I think...........
avatar
Shadowstalker16: Thanks for the info! Seems to be for profiles only for now. Best to be careful and go off-the radar for a few days and stay offline I think...........
I don't know how the exploit works, dunno if going offline can solve the problem or it would be ininfluent.
Only after clicking on the link it occurred to me that I totally should have checked who posted this and if the URL the link leads to is actually the one seen in the text. Anyway, thanks for the warning. I saw this post just as I launched Steam.
avatar
ThePunishedSnake: Don't visit ANY profiles, even your. An exploited was found and it can compromise your account my sending fake trade request, phishing links etc.

http://i.imgur.com/eUVqvCt.jpg
https://twitter.com/SteamDB/status/574270315070668800
Nothing to worry about if you're careful. This has been a thing for ages.
Post edited March 07, 2015 by darthspudius
One would think steam could affrod better programmers/coders.

Even if someone edits their steam profile to include an exploit, steam should of never phrased/ran the exploit.
...it is not very hard to program/code this either!. Just make it not phrase/runscripts.



There was a php exploit in steam recently aswell. (didn't that euro truck simulator dev/pub bring it to light? <even got banned, and then unbanned cause he warned us all>)


This is what you get when you run everything users/pubs input into their profiles/accouncements.
Oh good, yet another vulnerability. Hopefully it gets patched quickly with no unexpected things arising from that.
low rated
See, i had been telling you. Steam is the worst scam ever, indeed...
Post edited March 07, 2015 by KiNgBrAdLeY7
avatar
KiNgBrAdLeY7: See, i had been telling you. Steam is the worst scam ever, indeed...
It got better.
avatar
gbaz69: One would think steam could affrod better programmers/coders.

Even if someone edits their steam profile to include an exploit, steam should of never phrased/ran the exploit.
...it is not very hard to program/code this either!. Just make it not phrase/runscripts.

There was a php exploit in steam recently aswell. (didn't that euro truck simulator dev/pub bring it to light? <even got banned, and then unbanned cause he warned us all>)

This is what you get when you run everything users/pubs input into their profiles/accouncements.
i am not a coder, not technician, i do know that if you could keep a site simple and stupid no shitty tricks would be able to be made by exploiters other then stealing a password login info thats all.

The more you want your account or client be able to do the more code it involves the more prone the whole thing will be to exploits and other mishappens.


Keep it simple and stupid, this way they can only get your login info, but if they are good enough they get all the info from the server themselves.

i remember a old quote i forgot the link so i googled on it:

quote: A chain is no stronger than its weakest link, and life is after all a chain.


i googled to find where it came from cause i forgot it:

Read more at
brainyquote DOT com/quotes/keywords/weakest_link.html#MDwO3RgMgjiDZTVG.99
avatar
gamesfreak64: Keep it simple and stupid, this way they can only get your login info, but if they are good enough they get all the info from the server themselves.
Let's disable the internet while we're at it, surely that'll solve all these security vulnerabilities for good :-P
Supposedly fixed now.

https://twitter.com/SteamDB/status/574283584120451072

[EDIT]
Oops, didn't see that post earlier.
Post edited March 07, 2015 by Accoun
avatar
gamesfreak64: Keep it simple and stupid, this way they can only get your login info, but if they are good enough they get all the info from the server themselves.
avatar
Fenixp: Let's disable the internet while we're at it, surely that'll solve all these security vulnerabilities for good :-P
Disable the internet? Noooooo! Hahaha in all fairness it's a necessity to have the internet in our modern society.
avatar
sxnc: Disable the internet? Noooooo! Hahaha in all fairness it's a necessity to have the internet in our modern society.
Well yes, that was the point - with the mindset of "Let's keep it simple, it's safe that way!" we'd probably still be living in caves as surely, nature can hold a roof above our heads much better than a product of our labour can.