Live data from Hacker News

Valve accused of ignoring existing RCE vulnerability in Source games for 2 years

twitter.com

91–100 of 122 posts

Re: Valve accused of ignoring existing RCE vulnerability in Source games for 2 years

#91
post #25

Earlier quoted context omitted.

> There are also other reports of Valve not reacting to HackerOne reports appropriately I'll second that. I discovered and reported a vulnerability with the Steam client's Bluetooth pairing process via hackerone. The issue was confirmed but decided "out of scope" as apparently "within bluetooth range" runs afoul of the bug bounty's "require physical access" exclusion. 8 months later (I haven't exactly kept on top of…

How can they demand that you keep it confidential if they've already declared it to be out-of-scope? People need to start releasing these exploits instead of being a slave because they'd no longer get any payouts from HackerOne. Once the exploits are public, I assure you that either Valve will scramble to fix them or people will start looking for safer alternatives.

One of the issues is that it is HackerOne making the demand, not Valve.

I have been involved with other bounties on that site in that time, related to other companies & products.

I suspect if I had "broken their (Hackerone) policy" with this issue in that time, there would have been problems receiving a reward from the other bounty programs relating to different companies...

This isn't the only reason I haven't publicised the issue more widely, I've had other things on my plate, but it is a consideration.

Re: Valve accused of ignoring existing RCE vulnerability in Source games for 2 years

#92
post #67
post #49

Earlier quoted context omitted.

Doubt that. There is this so-called "Steam web API key scam" which is ongoing for years at this point: Scammers create phishing Steam login pages to grab people's credentials. Just with these credentials, the damage an attacker can do is still limited because of 2FA. However, the biggest flaw is that it is possible to automatically create API keys for the phished accounts that allow 24/7 remote access of these Steam…

Valve has been pretty aggressive about rolling out these kinds of policies compared to the rest of the industry. (E.g. they were wery early with requiring 2FA to be enabled for a period of time before doing sensitive actions like trades, adding warning interstitials on links that leave Steam). I don't think the incentives have changed that much. So, here's what makes me confused about your story: 1. I don't see any k…

> Are the users just blindly approving trades worth thousands without even verifying?

People do. Many years ago I started playing an MMOG and the old timers were all discussing some incredibly rare new item. So I said I had one, and someone said he'd give me 100 million credits for it. For comparison, I'd just spent several hours grinding out about 10 credits. So I sent him a formal offer - some random piece of junk for 100 million credits - and he was so excited he clicked OK without reading what he was getting. He was so angry! He spent weeks spewing venom on the forums.

Of course, this wasn't real money, but in terms of time spent earning it he suffered a significant loss.

Re: Valve accused of ignoring existing RCE vulnerability in Source games for 2 years

#93
post #67
post #49

Earlier quoted context omitted.

Doubt that. There is this so-called "Steam web API key scam" which is ongoing for years at this point: Scammers create phishing Steam login pages to grab people's credentials. Just with these credentials, the damage an attacker can do is still limited because of 2FA. However, the biggest flaw is that it is possible to automatically create API keys for the phished accounts that allow 24/7 remote access of these Steam…

Valve has been pretty aggressive about rolling out these kinds of policies compared to the rest of the industry. (E.g. they were wery early with requiring 2FA to be enabled for a period of time before doing sensitive actions like trades, adding warning interstitials on links that leave Steam). I don't think the incentives have changed that much. So, here's what makes me confused about your story: 1. I don't see any k…

> Valve has been pretty aggressive about rolling out these kinds of policies compared to the rest of the industry.

True indeed.

> Are you saying that they're polling all the hijacked accounts at a high frequency to detect trades they could intercept?

Yes.

I have to admit, the "milliseconds before" part was just wrong because I failed when trying to oversimplify for attention.

> it's "a trade with foo (whom you've had as a friend for 20 days), where you give a xyzzy and receive a quux". Are the users just blindly approving trades worth thousands without even verifying?

Often, the attackers focus on swapping trade offers that are initiated from a 3rd party, e.g., a trusted middleman marketplace site that requests your item (with nothing in return) that you want to offer. 3rd party sites take a lot of blame for "stolen items" because people don't even understand how this scam works.

Here, the few seconds are between the 3rd party offering the trade and the compromised user accepting the trade, not between the user accepting the trade in the browser and on his phone. Since the phished user is not aware of the 3rd party site's account in the first place (it is not one of his friends), it is very easy to clone all the observed account details and transform a scam bot account into looking like it is the one from the 3rd party site. Actually, there are characteristics that cannot be spoofed, but an ordinary user, not even aware that he was phished and that someone has control over his account who can do such things, will not notice this.

Now, you could argue that preventing 3rd party sites from existing could also solve this issue. However, I see a valid use case in these 3rd party sites. The goal of my suggestion is to counter these attacks with minimal effort without disabling automated trading capabilities completely:

> A captcha would be just be minor irritation for the attacker, and anyone who can be phished into logging in can be phished to approve the key generation.

I agree that it would only make the attack harder, not impossible, but considering the usual workflow I still see this as an improvement - as a first step.

The phishing is usually done by setting up a "legit" website, e.g. for skin trading, skin gambling or even any other non-financial purpose that requires authentication via Steam. This "legit" website then spawns a malicious "Login with Steam" OpenID credentials popup, rendered inside (!) the web page. This means, the website itself draws (depending on your OS and browser) a perfectly fine looking Browser popup window inside the legit page. It basically spoofs the browser UI itself. Laypeople get fooled easily by this, they sometimes do not even question why the window cannot be dragged out of the page, if they even try. These web apps are built in top-tier quality because obviously, the profit potential is huge. There is probably even a framework sold to easily recreate such pages at this point.

What I'm trying to say is: Getting the user to login is easy because it's part of the legit workflow. The API key generation - not so much.

Basically, everything I'm asking for is to make it hard to automatically transform a normal user account into a bot account used to automate trade offers. I know that there is a valid use case for automated bot accounts and automated trade offers. But the automation of the action to enable such functionality for an account should be prevented at all cost, and it should be explicitly requested from the user, including a warning.

Probably you are saying something similar with that statement with which I agree:

> the bigger problem here is that the API keys are unscoped

TL;DR: I think that preventing automated Steam web API key generation is the best short-term solution considering effort to make the attack a lot harder for the scammers.

Re: Valve accused of ignoring existing RCE vulnerability in Source games for 2 years

#94

Dozens of Counter-strike exploits exist and the cheating scene has just grown too rampantly. Valve simply doesn't care about the source engine. Any new CSGO player will tell you the anti-cheat doesn't work, I know first-hand. The lack of care regarding source engine netcode extends to every part of the source engine, including Valve Anti-cheat. The anti-cheat is trivial to reverse (several PUBLIC bypasses have existe…

Normally, I can handle some cheating in games, you just kinda deal with it, but holy fuck csgo was just nope. Between foul mouthed children and essentially watching God hackers play against eachother while you just die over and over. Yeah....no not exactly fun.

> foul mouthed children

Luckily you can now report accounts for this, and with enough reports they will be auto-muted now.

Re: Valve accused of ignoring existing RCE vulnerability in Source games for 2 years

#95
post #26

Earlier quoted context omitted.

> Some game companies (riot games) even install their anti-cheat software so that is loads in the ring 0 space. Why are separate machines required, rather than dual-booting? (i.e. Windows for games, Linux for everything else)

You can also run virtual machine with real card attached to it via VFIO if your host has IOMMU support. Guess what this means for anti-cheat.

Some anti-cheats like BattlEye try to detect if they're running in a VM.

Re: Valve accused of ignoring existing RCE vulnerability in Source games for 2 years

#96

Earlier quoted context omitted.

Just 2 days ago on prime I ran into a string of cheaters. At one point we had 2 on the enemy team and it caused someone on my team to go toggle. 3 cheaters in one match. On old accounts with everything. I know he couldn't be an expert but the person on my team says he can he blatant every game and never get banned because we're on prime. I don't want to believe that but then he had a lot of items and didn't mind spin…

From my understanding the CS:GO matchmaking basically ranks how likely of a cheater it thinks you are, and matches you with people of a similar ranking. If you're queuing with people that are bragging about blatantly cheating you're probably in the "likely cheater" group. This is all really just anecdotes, but here's my counter anecdote. I play csgo on and off with friends. None of us have ever cheated in csgo (or an…

Exactly! I get blamed for cheating and reported (trust me I don't) so I whenever I play matchmaking I'm also in the "likely cheater" group. That's why I play on third party server with their own anti cheat system.

Re: Valve accused of ignoring existing RCE vulnerability in Source games for 2 years

#97
post #26

Earlier quoted context omitted.

> Some game companies (riot games) even install their anti-cheat software so that is loads in the ring 0 space. Why are separate machines required, rather than dual-booting? (i.e. Windows for games, Linux for everything else)

You can also run virtual machine with real card attached to it via VFIO if your host has IOMMU support. Guess what this means for anti-cheat.

As the other user said, BattleEye now bans for this. I used a VFIO set up for a number of years but had to switch because of it.

Re: Valve accused of ignoring existing RCE vulnerability in Source games for 2 years

#98
post #64

Dozens of Counter-strike exploits exist and the cheating scene has just grown too rampantly. Valve simply doesn't care about the source engine. Any new CSGO player will tell you the anti-cheat doesn't work, I know first-hand. The lack of care regarding source engine netcode extends to every part of the source engine, including Valve Anti-cheat. The anti-cheat is trivial to reverse (several PUBLIC bypasses have existe…

> CSGO player will tell you the anti-cheat doesn't work, I know first-hand. > It is in my opinion the greatest loss to gaming that a classic, legendary game like Counter-strike got completely ruined by lack of care by a company that profits millions off of the case unboxings. have you played the game in recent years? this has not been the case for me or the people I play with at all. when playing on high trust-factor…

If you play on Asia region there’s 8/10 chance you will be matched with a hacker from China. The hacking industry there is making serious money.

Re: Valve accused of ignoring existing RCE vulnerability in Source games for 2 years

#99
post #7

I have a friend who used to work at Valve as a software engineer - he mentioned to me that the entire source networking stack is chock full of unchecked buffers and all sorts of potential for fairly trivial RCEs, but due to Valve's internal structure (or lack thereof) there really isn't any incentive for anyone to fix them. This was 5-6 odd years ago and he no longer works there, so things might have changed, but bas…

> due to Valve's internal structure (or lack thereof) there really isn't any incentive for anyone to fix them This seems to be a common theme with problems at Valve.

This seems common in the industry at large. At my job it's impossible to fix an issue unless someone specifically puts in a ticket for it. I look at all the bugs in the code taunting me. Little landmines either nobody has stepped on yet or was too lazy to write a ticket for. Some tickets languish for years in the tracking system we use until the almighty scrum master doles it out. I am in hell.

Re: Valve accused of ignoring existing RCE vulnerability in Source games for 2 years

#100

Earlier quoted context omitted.

Just 2 days ago on prime I ran into a string of cheaters. At one point we had 2 on the enemy team and it caused someone on my team to go toggle. 3 cheaters in one match. On old accounts with everything. I know he couldn't be an expert but the person on my team says he can he blatant every game and never get banned because we're on prime. I don't want to believe that but then he had a lot of items and didn't mind spin…

From my understanding the CS:GO matchmaking basically ranks how likely of a cheater it thinks you are, and matches you with people of a similar ranking. If you're queuing with people that are bragging about blatantly cheating you're probably in the "likely cheater" group. This is all really just anecdotes, but here's my counter anecdote. I play csgo on and off with friends. None of us have ever cheated in csgo (or an…

I didn't queue with the cheater. He was a random on my team who happened to turn the cheats on when we were losing to a cheater. He left the game and everything to launch them.

The rest of us aren't cheaters. We have old steam accounts with lots of games, items, and play time. We have prime. We still got put into that lobby. I'm not good enough to look like a cheater on my playing alone either.

Post reply on HN