Putting the 'role' back in role-playing games since 2002.
Donate to Codex
Good Old Games
  • Welcome to rpgcodex.net, a site dedicated to discussing computer based role-playing games in a free and open fashion. We're less strict than other forums, but please refer to the rules.

    "This message is awaiting moderator approval": All new users must pass through our moderation queue before they will be able to post normally. Until your account has "passed" your posts will only be visible to yourself (and moderators) until they are approved. Give us a week to get around to approving / deleting / ignoring your mundane opinion on crap before hassling us about it. Once you have passed the moderation period (think of it as a test), you will be able to post normally, just like all the other retards.

The Great Christmas 2015 Steam Security Breach

Turjan

Arcane
Joined
Mar 31, 2008
Messages
5,047
Does anyone else have an "browse Steam in Turkish, Hungarian, Romanian or Bulgarian and look at other people's accounts" day? It's annoying.

Edit: It's a total mess. Every link leads to a different account.
 
Last edited:

Alienman

Retro-Fascist
Patron
Joined
Sep 10, 2014
Messages
17,046
Location
Mars
Codex 2016 - The Age of Grimoire Make the Codex Great Again! Grab the Codex by the pussy Codex Year of the Donut Shadorwun: Hong Kong Divinity: Original Sin 2 Steve gets a Kidney but I don't even get a tag.
Something strange is going on. People on reddit are reporting they have been logged in as someone else, with access to their personal information.
 

Infinitron

I post news
Staff Member
Joined
Jan 28, 2011
Messages
97,236
Codex Year of the Donut Serpent in the Staglands Dead State Divinity: Original Sin Project: Eternity Torment: Tides of Numenera Wasteland 2 Shadorwun: Hong Kong Divinity: Original Sin 2 A Beautifully Desolate Campaign Pillars of Eternity 2: Deadfire Pathfinder: Kingmaker Pathfinder: Wrath I'm very into cock and ball torture I helped put crap in Monomyth
:avatard:

Yeah, I see Steam in Russian now, but it still appears to be my account.
 

Trodat

Arcane
Patron
Joined
Dec 17, 2014
Messages
795
Location
Finland
Everything is normal... except when I try to browse the store I always get someone else's wishlist and shit.
 

Turjan

Arcane
Joined
Mar 31, 2008
Messages
5,047
I was shown different people's account transactions and license dates.
 

racofer

Thread Incliner
Joined
Apr 5, 2008
Messages
25,577
Location
Your ignore list.
Apparently is has been hacked. Check here:

https://www.reddit.com/r/Steam/comments/3y7le9/im_logged_in_as_someone_random_on_steam/

http://forums.steampowered.com/forums/showthread.php?t=3299837

Happened to me as well. I was about to purchase some shit and then I was into someone else's wishlist. Logged out, and steam was in another random language. Now I can't even log in anymore, but the Steam application is still working normally, apparently.

This could be huge. People are reporting to be able to access other people's personal details. What the fuck.

Edit: I can't even change the language in the site anymore. Keeps changing to some random one every time I refresh the page.

:x

May this be a reminder to keep pirating shit instead of relying on an online platform.
 

Infinitron

I post news
Staff Member
Joined
Jan 28, 2011
Messages
97,236
Codex Year of the Donut Serpent in the Staglands Dead State Divinity: Original Sin Project: Eternity Torment: Tides of Numenera Wasteland 2 Shadorwun: Hong Kong Divinity: Original Sin 2 A Beautifully Desolate Campaign Pillars of Eternity 2: Deadfire Pathfinder: Kingmaker Pathfinder: Wrath I'm very into cock and ball torture I helped put crap in Monomyth
Something's definitely been going down with Steam today:

Steam down on Christmas Day amid fears of DDoS attack

Steam, the popular online gaming service for PC gamers around the world, was offline for several hours on Christmas Day. The outage followed threats from a hacking collective known as 'SkidNP' that they would take down Steam and Minecraft servers over Christmas.

When attempting to open the Steam client, users were presented with a message detailing that there is an issue connecting to the Steam network:

1_steam-down.jpg


Reports of the outage began to surface earlier this morning (14:50 GMT / 6:50 PST) and continued to grow in number as more people attempted to connect.

On Reddit there have been numerous complaints of the outage. Community member komentra said:

I really hope it isn't those script kiddies DDOSing Steam. PSN, and XBL again.

At the time of writing, there has been no comment from Valve regarding the outage. While SkidNP has claimed that they would attack Steam on Christmas Day, it is also just as likely that due to it being the festive season, there's a higher than expected number of people signing in and downloading content. As Reddit user Super_Cyan pointed out:

To be honest, it'd be rough figuring out what's an attack and what's just heavy traffic on a day like today.

The client would occasionally display 'connecting to Steam account' for awhile before throwing users back out. Our attempts to connect to Steam earlier today were unsuccessful, but the service is now back online.
 

Infinitron

I post news
Staff Member
Joined
Jan 28, 2011
Messages
97,236
Codex Year of the Donut Serpent in the Staglands Dead State Divinity: Original Sin Project: Eternity Torment: Tides of Numenera Wasteland 2 Shadorwun: Hong Kong Divinity: Original Sin 2 A Beautifully Desolate Campaign Pillars of Eternity 2: Deadfire Pathfinder: Kingmaker Pathfinder: Wrath I'm very into cock and ball torture I helped put crap in Monomyth
Steam Goes Nuts, Offers Access To Other People's Accounts

lbgbbpzoxqx3ap060smg.png


An apparent malfunction is hitting Steam right now, giving players across the world access to the wallets and buying history of other people’s accounts. It’s not yet clear how this security breach occurred.

Various players across the world are reporting logging into the Steam client and finding that their homepage has changed to Russian or other random languages. When they check the “account info” section of Steam, they find that they have access to another user’s account, complete with e-mail addresses, buying history, and other private information.

Based on some rudimentary testing I’ve done on my own Steam client, it seems like trying to view purchase histories and licenses will switch to other random accounts, too.


ztmaxmbv0hztbpabuisp.png


We’ve reached out to Valve for more information and will keep updating you guys as we learn more.
 

Turjan

Arcane
Joined
Mar 31, 2008
Messages
5,047
I'm not worried about Steam being down - it was twice today - but about the account hopping.
 

Infinitron

I post news
Staff Member
Joined
Jan 28, 2011
Messages
97,236
Codex Year of the Donut Serpent in the Staglands Dead State Divinity: Original Sin Project: Eternity Torment: Tides of Numenera Wasteland 2 Shadorwun: Hong Kong Divinity: Original Sin 2 A Beautifully Desolate Campaign Pillars of Eternity 2: Deadfire Pathfinder: Kingmaker Pathfinder: Wrath I'm very into cock and ball torture I helped put crap in Monomyth
Oh fuuuuuu, there it is. I'm looking at somebody else's account information.

This is so fucked up. Holy crap.
 

Don Peste

Arcane
Joined
Sep 15, 2008
Messages
4,277
Location
||☆||
WHAT IF this is a false flag attack by Valve in order to make everyone use their Steam Guard app so they can record all our mobile information, photos, browsing habits and shit?
 

Infinitron

I post news
Staff Member
Joined
Jan 28, 2011
Messages
97,236
Codex Year of the Donut Serpent in the Staglands Dead State Divinity: Original Sin Project: Eternity Torment: Tides of Numenera Wasteland 2 Shadorwun: Hong Kong Divinity: Original Sin 2 A Beautifully Desolate Campaign Pillars of Eternity 2: Deadfire Pathfinder: Kingmaker Pathfinder: Wrath I'm very into cock and ball torture I helped put crap in Monomyth
Interview from two days ago: http://www.techworm.net/2015/12/int...-the-latest-kids-in-the-hacking-universe.html :avatard:

Beware Steam and Minecraft gamers, SkidNP is out there to bring the servers down

SkidNP : The hacking group that has promised to bring down Minecraft and Steam gaming servers during Christmas holidays

Meet SkidNP the latest gang of hackers to seeking join the esteemed ranks of hacking groups like Syrian Electronic Army, CyberBerkut and infamous ones like Lizard Squad. SkidNP is the latest entrant in the hacking arena and their first deed as hackers was to announce that they will bring down Steam and Minecraft gamings servers during the Christmas holidays.

With Christmas just two days far, we caught up with SkidNP’s member who goes by the name of K and asked him what SkidNP’s goals were. Here is the full interview :

TW : Who are you guys and what is the aim of SkidNP?

K (@Obstructable) : The leaders are me and @Stazexor we aim to break “Skids” Like @PhantomSeccand stop them from taking other peoples credits. we attack services to make them know what attacks are like so they can fix them

TW : What are your targets for Christmas holidays?

K : Minecraft and Steam. Steam will be a hard target as they are smart unlike Mojang, Xbox and PlayStation.

TW : No PSN Network and Xbox Live?

K : I think @LizardLands will be attacking xbox and PSN enough.

One of the exploits of SkidNP is that they hacked Phantom Squad’s website. Phantom Squad have promised that they will DDoS PlayStation Networks and Xbox gaming servers during the Christmas holidays. SkidNP considers Phantom Squad as skids, a Internet slang for script kids. Here is why?

TW : Why do you think @PhantomSec are skids?

K : They use a old attack method “PMA” this is a method from around 2013 that is bad

TW : And you will be using?

K : We will be using a botnet and a few dedicated servers.

SkidNP fulfill their promise, bring down Steam servers, read hereto know more.
TW : Arent you worried about the backlash from Minecraft and Steam gamers? Lizard Squad was harangued by them for last years attacks..

K : Well not really as all they will be doing is giving us more publicity. Making videos and tweets about how outraged they are about us.

TW : You are connected in anyways to Lizards?

K : We are not

TW : Next years targets if any?

K : We will be attacking Minecraft & Steam again, and maybe a few more as we do not know yet as its a year away

TW : And what time will the Minecraft and Steam attack start?

K : Around 1AM 25Th

TW : Any message to the young wannabe hackers?

K : Watch out.. we’re coming for you

K signed off with a ominous warning to tech companies which provide poor service to users and have very poor security. He said that they want to bring down such services to alert the tech companies about their vulnerabilities so that they can prepare for the same.

It remains to be seen whether SkidNP is successful in bringing down the Minecraft and Steam servers on the 25th December. But, taking them lightly could cost serious loss as Sony and Microsoft realised last year when they preferred to disregard Lizard Squad’s promise of disrupting Xbox Live and PlayStation Network servers during the Christmas holidays.

What happened during those holidays to both the gaming servers is known to all.
 

Turjan

Arcane
Joined
Mar 31, 2008
Messages
5,047
By the way, all accounts I had seen had "Steam Guard" turned off. I would like to see my own account, but alas...
 

Infinitron

I post news
Staff Member
Joined
Jan 28, 2011
Messages
97,236
Codex Year of the Donut Serpent in the Staglands Dead State Divinity: Original Sin Project: Eternity Torment: Tides of Numenera Wasteland 2 Shadorwun: Hong Kong Divinity: Original Sin 2 A Beautifully Desolate Campaign Pillars of Eternity 2: Deadfire Pathfinder: Kingmaker Pathfinder: Wrath I'm very into cock and ball torture I helped put crap in Monomyth
By the way, all accounts I had seen had "Steam Guard" turned off. I would like to see my own account, but alas...

I'm looking at one right now that has it enabled. I don't think that has anything to do with this.
 

Trodat

Arcane
Patron
Joined
Dec 17, 2014
Messages
795
Location
Finland
I've been using Steam Guard for a long time already. :M Maybe it was a wise decision.

EDIT. Ok maybe not.
 

Anthedon

Arcane
Patron
Joined
Jan 1, 2015
Messages
4,499
Shadorwun: Hong Kong Divinity: Original Sin 2 Pillars of Eternity 2: Deadfire
By the way, all accounts I had seen had "Steam Guard" turned off. I would like to see my own account, but alas...

The one I'm looking at has it on.

Edit: The next one has it also activated.
 

racofer

Thread Incliner
Joined
Apr 5, 2008
Messages
25,577
Location
Your ignore list.
By the way, all accounts I had seen had "Steam Guard" turned off. I would like to see my own account, but alas...

I'm looking at one right now that has it enabled. I don't think that has anything to do with this.
Same here. Looking at someone else's account that has Steam Guard email turned on.
 

As an Amazon Associate, rpgcodex.net earns from qualifying purchases.
Back
Top Bottom