5 ms·
According to a tweet that was also retweeted by the user @floesen_ who was mentioned in the original thread, the initial report 2 years ago was done using Hacke
by mxscho 5y ago
According to a tweet that was also retweeted by the user @floesen_ who was mentioned in the original thread, the initial report 2 years ago was done using HackerOne but has probably not seen any helpful response from Valve [1].
There are also other reports of Valve not reacting to HackerOne reports appropriately [2].
It is currently unclear whether there is a publicly available PoC or any exploitation going on in the wild.
[1] https://twitter.com/AntiCheatPD/status/1380873722966503426 https://twitter.com/AntiCheatPD/status/1380873722966503426
[2] https://twitter.com/killa/status/1380872852090540032 https://twitter.com/killa/status/1380872852090540032
- pityJuke 5y agofloesen has posted a screenshot of the open ticket back in December. [1] [1]: https://twitter.com/floesen_/status/1337107178096881666 https://twitter.com/floesen_/status/1337107178096881666
- pricechild 5y ago> There are also other reports of Valve not reacting to HackerOne reports appropriately I'll second that. I discovered and reported a vulnerability with the Steam client's Bluetooth pairing process via hackerone. The issue was confirmed but decided "out of scope" as apparently "within bluetooth range" runs afoul of the bug bounty's "require physical access" exclusion. 8 months later (I haven't exactly kept on top of this) they're still demanding I keep it confidential. I'll follow it up...
- yjftsjthsd-h 5y agoSurely that's a contradiction? Either it's a security problem by their criteria, or it isn't; if it is, then they should pay up and fix it, if it isn't then they have no legitimate reason to care if you put full details on the front page of $MAJOR_NEWS_SITE.
- veeti 5y agoJust release it. Maybe Valve will have to do something once folks start losing their precious CS:GO skins?
- mxscho 5y agoDoubt that. There is this so-called "Steam web API key scam" which is ongoing for years at this point: Scammers create phishing Steam login pages to grab people's credentials. Just with these credentials, the damage an attacker can do is still limited because of 2FA. However, the biggest flaw is that it is possible to automatically create API keys for the phished accounts that allow 24/7 remote access of these Steam accounts without the user even noticing. With this access, scammers then automatically modify and alter trades at will and at any time in the future, milliseconds before people confirm them using their mobile device (2FA), e.g., by declining the original trade and setting up a new trade with a scammer's bot account that has changed its profile data to the one of the actually intended trading partner. This attack is mostly based on phishing, spoofing and confusion, but it could at least be made much harder by preventing automated API key generation and therefore indefinite access to an account (e.g., by implementing email confirmations or captchas for API key generation). Each day lots of children or laypeople are losing in-game items worth thousands of dollars. I'm admin on a popular CS:GO and gaming Discord server with ~30k members and we see such reports multiple times a week. Valve has no incentive to fix this as long as it's not their money or regulators start applying pressure.
- jsnell 5y agoValve has been pretty aggressive about rolling out these kinds of policies compared to the rest of the industry. (E.g. they were wery early with requiring 2FA to be enabled for a period of time before doing sensitive actions like trades, adding warning interstitials on links that leave Steam). I don't think the incentives have changed that much. So, here's what makes me confused about your story: 1. I don't see any kind of activity hooks in IEconService, that would let the attackers know via a callback that. Are you saying that they're polling all the hijacked accounts at a high frequency to detect trades they could intercept? That seems like a highly divergent use case from normal uses of the API, and one that an abuse team would be motivated to prevent. 2. I thought the Steam trade confirmation dialog showed very specific information about just what was being traded for what. I.e. it's not just that you're approving "a trade with foo", it's "a trade with foo (whom you've had as a friend for 20 days), where you give a xyzzy and receive a quux". Are the users just blindly approving trades worth thousands without even verifying? I don't like either of your solutions though. A captcha would be just be minor irritation for the attacker, and anyone who can be phished into logging in can be phished to approve the key generation. It seems that the bigger problem here is that the API keys are unscoped. Once you have that, it's easier to inform the user in the approval flow about just what they're approving, and viable to nag the users into revoking access for apps with dangerous permissions.
- ziml77 5y agoHow can they demand that you keep it confidential if they've already declared it to be out-of-scope? People need to start releasing these exploits instead of being a slave because they'd no longer get any payouts from HackerOne. Once the exploits are public, I assure you that either Valve will scramble to fix them or people will start looking for safer alternatives.
- pricechild 5y agoOne of the issues is that it is HackerOne making the demand, not Valve. I have been involved with other bounties on that site in that time, related to other companies & products. I suspect if I had "broken their (Hackerone) policy" with this issue in that time, there would have been problems receiving a reward from the other bounty programs relating to different companies... This isn't the only reason I haven't publicised the issue more widely, I've had other things on my plate, but it is a consideration.
- tgsovlerkhgsel 5y agoHackerOne also at least strongly discourages publishing your findings if the developers refuse to take action. https://www.hackerone.com/disclosure-guidelines https://www.hackerone.com/disclosure-guidelines states that "After the Report has been closed, Public disclosure may be requested by either the Finder or the Security Team." - so if the report just doesn't get closed, you can't disclose through the platform, and https://www.hackerone.com/policies/code-of-conduct https://www.hackerone.com/policies/code-of-conduct says "Disclosing report information without previous authorization is not permitted." To me, that seems that you're not permitted to disclose the issue at all until the report has been closed and either 1) 30 days have passed and the security team hasn't requested an extension, or 2) "180 days have elapsed with the Security Team being unable or unwilling to provide a vulnerability disclosure timeline". Due to this, I refuse to report through HackerOne.