Live data from Hacker News

Valve accused of ignoring existing RCE vulnerability in Source games for 2 years

twitter.com

1–10 of 122 posts

Re: Valve accused of ignoring existing RCE vulnerability in Source games for 2 years

#2
This is why I have a separate machine for "gaming" and "work"

Some game companies (riot games) even install their anti-cheat software so that is loads in the ring 0 space. Even with their best efforts, cheaters will still prosper.

Might even go a step further and firewall my gaming machine off from the rest of my network.

Re: Valve accused of ignoring existing RCE vulnerability in Source games for 2 years

#3
According to a tweet that was also retweeted by the user @floesen_ who was mentioned in the original thread, the initial report 2 years ago was done using HackerOne but has probably not seen any helpful response from Valve [1]. There are also other reports of Valve not reacting to HackerOne reports appropriately [2].

It is currently unclear whether there is a publicly available PoC or any exploitation going on in the wild.

[1] https://twitter.com/AntiCheatPD/status/1380873722966503426

[2] https://twitter.com/killa/status/1380872852090540032

Re: Valve accused of ignoring existing RCE vulnerability in Source games for 2 years

#4
post #3

According to a tweet that was also retweeted by the user @floesen_ who was mentioned in the original thread, the initial report 2 years ago was done using HackerOne but has probably not seen any helpful response from Valve [1]. There are also other reports of Valve not reacting to HackerOne reports appropriately [2]. It is currently unclear whether there is a publicly available PoC or any exploitation going on in the…

floesen has posted a screenshot of the open ticket back in December. [1]

[1]: https://twitter.com/floesen_/status/1337107178096881666

Re: Valve accused of ignoring existing RCE vulnerability in Source games for 2 years

#6
post #3

According to a tweet that was also retweeted by the user @floesen_ who was mentioned in the original thread, the initial report 2 years ago was done using HackerOne but has probably not seen any helpful response from Valve [1]. There are also other reports of Valve not reacting to HackerOne reports appropriately [2]. It is currently unclear whether there is a publicly available PoC or any exploitation going on in the…

> There are also other reports of Valve not reacting to HackerOne reports appropriately

I'll second that.

I discovered and reported a vulnerability with the Steam client's Bluetooth pairing process via hackerone.

The issue was confirmed but decided "out of scope" as apparently "within bluetooth range" runs afoul of the bug bounty's "require physical access" exclusion.

8 months later (I haven't exactly kept on top of this) they're still demanding I keep it confidential. I'll follow it up...

Re: Valve accused of ignoring existing RCE vulnerability in Source games for 2 years

#7
I have a friend who used to work at Valve as a software engineer - he mentioned to me that the entire source networking stack is chock full of unchecked buffers and all sorts of potential for fairly trivial RCEs, but due to Valve's internal structure (or lack thereof) there really isn't any incentive for anyone to fix them.

This was 5-6 odd years ago and he no longer works there, so things might have changed, but based on this tweet it seems unlikely.

Re: Valve accused of ignoring existing RCE vulnerability in Source games for 2 years

#8
post #2

This is why I have a separate machine for "gaming" and "work" Some game companies (riot games) even install their anti-cheat software so that is loads in the ring 0 space. Even with their best efforts, cheaters will still prosper. Might even go a step further and firewall my gaming machine off from the rest of my network.

This is one of the reasons I like gaming on GeForce NOW. I can use my primary laptop, play any game without having to install anything, instantly alt-tab back to the desktop between rounds without any weird bugs or crashes, etc.

Re: Valve accused of ignoring existing RCE vulnerability in Source games for 2 years

#9
post #5

2 years? Just leak it. At some point "responsible" disclose is not worth it.

Moreso, at some point it may be more responsible to exert real pressure and a time concern on them to fix it by revealing the flaw.

It depends on whether you think there's a reasonable chance that someone may be using that exploit by now. Carrot and stick approaches do not work without a reliable stick.

Edit: I suppose it also depends on how much you value going through the exact same process with valve for other bugs in the future. But in a situation like this it seems like little would be lost.

Re: Valve accused of ignoring existing RCE vulnerability in Source games for 2 years

#10
post #3

According to a tweet that was also retweeted by the user @floesen_ who was mentioned in the original thread, the initial report 2 years ago was done using HackerOne but has probably not seen any helpful response from Valve [1]. There are also other reports of Valve not reacting to HackerOne reports appropriately [2]. It is currently unclear whether there is a publicly available PoC or any exploitation going on in the…

> There are also other reports of Valve not reacting to HackerOne reports appropriately I'll second that. I discovered and reported a vulnerability with the Steam client's Bluetooth pairing process via hackerone. The issue was confirmed but decided "out of scope" as apparently "within bluetooth range" runs afoul of the bug bounty's "require physical access" exclusion. 8 months later (I haven't exactly kept on top of…

Surely that's a contradiction? Either it's a security problem by their criteria, or it isn't; if it is, then they should pay up and fix it, if it isn't then they have no legitimate reason to care if you put full details on the front page of $MAJOR_NEWS_SITE.
Post reply on HN