Dismiss Notice
Wynncraft, the Minecraft MMORPG. Play it now on your Minecraft client at (IP): play.wynncraft.com. No mods required! Click here for more info...

Scary Vulnerability In Steam!!

Discussion in 'Nemract's Bar' started by DatDraggy, Feb 7, 2017.

Thread Status:
Not open for further replies.
  1. DatDraggy

    DatDraggy Untouchable HERO

    Messages:
    401
    Likes Received:
    1,653
    Trophy Points:
    89
    Minecraft:
    First of all, do not click ANY steam profile links.
    If you wanna know why, here is a harmless example: http://steamcommunity.com/id/YiffInHell/

    An exploit inside steam allows users to put HTML/JS code on their PROFILE PAGE.
    That means they can execute code on your PC.

    That includes making purchases on YOUR account, change your password, much more.

    Be careful around steam until this is fixed.

    THIS ALSO WORKS INSIDE THE STEAM BROWSER
    ________________________________
    [​IMG]
     
    Malkavian, SpadenadeZ1 and Pokextreme like this.
  2. memethyl

    memethyl the king of shitposting VIP+

    Messages:
    404
    Likes Received:
    2,242
    Trophy Points:
    71
    Guild:
    Minecraft:
    specifically, steam doesn't seem to sanitize guide titles when showing them on profiles.

    this means someone can put an <iframe> tag, or god forbid a <script> tag, in a guide title, and when their profile loads, the title is run as code.

    it's code injection 101, basically.
     
  3. DatDraggy

    DatDraggy Untouchable HERO

    Messages:
    401
    Likes Received:
    1,653
    Trophy Points:
    89
    Minecraft:
    Rip in pieces steam
     
  4. captainganon

    captainganon God of k | Derpalope VIP+

    Messages:
    11,319
    Likes Received:
    33,289
    Trophy Points:
    227
    Minecraft:
    Well now how am I gonna sell my CSGO skins? I'll go out of business!
     
    DatDraggy likes this.
  5. DatDraggy

    DatDraggy Untouchable HERO

    Messages:
    401
    Likes Received:
    1,653
    Trophy Points:
    89
    Minecraft:
    Okay steam fixed it. You can browse steam again
     
Thread Status:
Not open for further replies.