AOA Forums AOA Forums AOA Forums Folding For Team 45 AOA Files Home Front Page Become an AOA Subscriber! UserCP Calendar Memberlist FAQ Search Forum Home


Go Back   AOA Forums > Software > Data Security

Data Security Viruses, Firewalls and Safe computing


Reply
 
LinkBack Thread Tools Rate Thread
  #1 (permalink)  
Old 19th April, 2007, 05:39 PM
danrok's Avatar
AOA Staff
 
Join Date: March 2003
Location: Great Britain
Posts: 18,917

STEAM hacked, user credit cards may be at risk

Read it on the front page:
http://www.aoaforums.com/frontpage/content/view/2392/1/

Comments?
__________________
Desktop PC: AMD FX-8370E / Asus M5A99X Evo R2.0 Motherboard / 16GB DDR3 RAM / GeForce GTX 970
AOA Team fah
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 19th April, 2007, 05:54 PM
chrisbard's Avatar
Benchmarker
 
Join Date: March 2003
Location: Earth
Posts: 8,252
Send a message via Yahoo to chrisbard

Angry

Hell there are hackers that got into NASA or CIA or whetever you name it, but STEAM beeing hacked...thats too bad ! As a CSS player I say to that guy "hope you'll end up in a USA prison facility!" Steam News hasn't published nothing yet, I just checked. Well I am off to another CSS game ! What??? my account has been deleted??? just kidding
__________________
I've heard that linux community came up with better implemented security in it's latest Linux Mint Gold version, it's actually preventing the user to log in, thus posing 0 risk in contamining the computer with malware! Well done to the open source community!


Last edited by chrisbard; 19th April, 2007 at 05:58 PM.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 19th April, 2007, 07:54 PM
captinhector's Avatar
Member
 
Join Date: September 2006
Location: Norman, ok
Posts: 203
Send a message via MSN to captinhector

ugh..... I like the steam/valve client thingy, it makes keep your games together much easier and less time consumming. O well, I will still buy from a store or something then activate the code on steam, and not use their store.
__________________
The cake is a LIE!!!!!

Diablotek Demon IV
700w Tagan Dual Engine
AMD Athlon 64 3800+ x2 @ 2.7ghz under water
Asus A8N32-SLI Delux
EVGA 9800GT STOCK
2gig of A-Data Viesta DDR 1 @ 516 mhz
Http://www.thepeoplesbookstore.com
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 19th April, 2007, 08:15 PM
GrahamGarside's Avatar
Member/Contributer
 
Join Date: September 2004
Location: England
Posts: 4,572

The jokes on them, I don't have that card any more!!! lol!!
__________________
"Well yes but I'm afraid I prematurely shot my wod on what was supposed to be a dry run if you will, so now I'm afraid I have something of a mess on my hands."

Tobias Fünke, M.D.

AOA Team fah
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5 (permalink)  
Old 19th April, 2007, 08:58 PM
Favu's Avatar
AOA's resident barman
 
Join Date: October 2005
Location: /Wales/Abergavenny
Posts: 4,004
Send a message via ICQ to Favu Send a message via AIM to Favu Send a message via MSN to Favu

I have always bought the physical disc then activated it over steam, guess that makes me one of the lucky ones!
__________________
AOA Team fah
 

Custom 8-bit Sharp Z80 @ 4.194304 MHz
Reflective LCD @ 160 × 144
8 kByte S-RAM






Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6 (permalink)  
Old 19th April, 2007, 10:06 PM
skool h8r's Avatar
Member
 
Join Date: January 2005
Location: Rotherham, UK
Posts: 3,157
Send a message via MSN to skool h8r

Quote:
Originally Posted by Favu
I have always bought the physical disc then activated it over steam, guess that makes me one of the lucky ones!
That's what i do as well. I've never had to use my card with Steam or Valve. And i have heard about this. I've had a look at the rips that were posted and he's either very clever, or he's genuinly hacked Valve. He also managed to get the Particle Benchmark thing as well, which he did post, but it had been deleted from the host.

From what i've seen in the actual files, i'd say he'd been hanging around their servers for a while, probably observing activity before he launched his attack. However, he appears to have installed a popular tool onto their server in order to access not only the files, but also their MySQL.

What i am more worried about is that we will end up seeing our keys banned or available for free to low life pirates. He says that he has root access to their server. However, with the files, he is only into their "Cafe" folder, which is pretty obvious that it is for the Valve Cybercafe program. Whether he actually has root access or not is another subject.

I would just awe on the side of caution for the moment as to me, the evidence is not yet compelling enough to say whether or not it will affect us all (he could be lying through his teeth about the MySQL). For example the credit card number samples (with removed CVV2's for security reasons) could be completely fake. Also, if he does have such access to the root, surely he would be providing copies of individual games files.

My advice is to just be careful. He doesn't have access to your computer, so it's not likely that he'll ban your account. Just be careful.
__________________
i7 2600K (4.3Ghz 1.34v) | GTX580 | 16GB (4x4GB) Patriot Viper Sec. 5 Ser. 2 (1866 - 9-11-9-27) | P67A-UD4-B3
Corsair AX1200 | Vertex II 240GB SSD | 4TB RAID0 (Samsung HD204UI) | Logitech G930 Wireless Headset

YouTube - Benchmark Results (Coming Soon!)
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #7 (permalink)  
Old 19th April, 2007, 11:37 PM
danrok's Avatar
AOA Staff
 
Join Date: March 2003
Location: Great Britain
Posts: 18,917

Quote:
Originally Posted by Favu
I have always bought the physical disc then activated it over steam, guess that makes me one of the lucky ones!
Bear in mind, fraudsters don't just target online services. Using you card in a regular shop has risks as well.

Today it was Steam. Who will they target next time?

The pain is, even if you have fraud protection, it can be weeks before you get that money back. If they emptied your bank account, that can leave you with a big problem!
__________________
Desktop PC: AMD FX-8370E / Asus M5A99X Evo R2.0 Motherboard / 16GB DDR3 RAM / GeForce GTX 970
AOA Team fah
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #8 (permalink)  
Old 20th April, 2007, 12:23 AM
Pitch's Avatar
AOA Staff
Asteroids Champion, Maeda Path Champion, Disco Racer Champion, Alpha Bravo Charlie Champion, Van Champion
 
Join Date: February 2004
Location: The cake is a lie.
Posts: 5,025
Send a message via MSN to Pitch

Update from VAVLe.

Quote:
"There has been no security breach of Steam," Valve director of marketing Doug Lombardi told 1UP. "The alleged hacker gained access to a third-party site that Valve uses to manage the commercial partners in its Cyber Cafe program. This Cyber Cafe billing system is not connected to Steam. We are working with law enforcement agencies on this matter, and encourage anyone with more information to e-mail us at Catch_A_Thief@valvesoftware.com."
__________________


XBL/PNS = neolad
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #9 (permalink)  
Old 20th April, 2007, 12:16 PM
Chief Systems Administrator
 
Join Date: September 2001
Location: Europe
Posts: 13,075

Quote:
The alleged hacker gained access to a third-party site that Valve uses to manage the commercial partners in its Cyber Cafe program.
If I translate this correctly, are Valve saying "It's not our fault we didn't bother to check that our suppliers are properly secured"? If so, Valve should be shot for such a lax attitude towards customers' data. Valve are providing this service, and have responsibility that every link in the chain is sufficiently secure.
__________________
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #10 (permalink)  
Old 20th April, 2007, 02:14 PM
Wolf2000me's Avatar
Member
 
Join Date: September 2004
Location: Belgium
Posts: 1,238

From the update on the article it would seem that Valve denies that they themselves have been hacked.
Wheather they are just trying to save their a$$ or face, basically the same thing, is yet to be seen.
__________________
Asus Maximus Formula (X38)
Intel Q6600 3720Mhz
TT Mozart Tx
2x WD Raptors 74gb R0
2x Maxtor 300gb
Asus Geforce EN8800GT
Windoors XP Pro sp2

Download here OcBible 1.55 & Guidemania v1.21
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #11 (permalink)  
Old 20th April, 2007, 04:17 PM
skool h8r's Avatar
Member
 
Join Date: January 2005
Location: Rotherham, UK
Posts: 3,157
Send a message via MSN to skool h8r

Well, it looks as though the site where the hacker is usually found has been suspended yesterday. And today, it's escalated to a 403 instead of a "Site Suspended" message. We're still not safe as this information is still out there. Valve have let a clanger be dropped here by not setting security standards for partners. If that's their best excuse...
__________________
i7 2600K (4.3Ghz 1.34v) | GTX580 | 16GB (4x4GB) Patriot Viper Sec. 5 Ser. 2 (1866 - 9-11-9-27) | P67A-UD4-B3
Corsair AX1200 | Vertex II 240GB SSD | 4TB RAID0 (Samsung HD204UI) | Logitech G930 Wireless Headset

YouTube - Benchmark Results (Coming Soon!)
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
P 257 - Credit Given: 0.00 RussianMissile1 ThunderRd's AOA FOLDING@HOME Team 2 12th May, 2004 01:00 PM
Not getting credit?? dimmreaper ThunderRd's AOA FOLDING@HOME Team 9 7th July, 2002 07:48 AM
Not receiving credit Pinky ThunderRd's AOA FOLDING@HOME Team 11 2nd March, 2002 01:44 AM
Reckon I should risk... Winkie Random Nonsense! 6 20th November, 2001 04:09 AM
2.0 - Are You Getting Credit ? Southern Man ThunderRd's AOA FOLDING@HOME Team 15 17th October, 2001 08:39 PM


All times are GMT +1. The time now is 09:16 AM.


Copyright ©2001 - 2010, AOA Forums
Don't Click Here Don't Click Here Either

Search Engine Friendly URLs by vBSEO 3.3.0