Critical Valve Bug Lets Gamers Add Unlimited Funds to Steam Wallets
#1
Information 
Quote:A security researcher helped Valve, the makers of the gaming platform Steam, plug an easy-to-exploit hole that allowed users to add unlimited funds to their digital wallet. Simply by changing the account’s email address, the exploit allowed anyone to artificially boost their digital billfold to anything they wanted.
 
Steam Wallet funds are exclusive to the Steam platform and are used to purchase in-game merchandise, subscriptions and Steam-related content. Valve restricts Steam credits (or money) from being transferred outside its network for purchase or trading. However, there are several unsanctioned ways to convert wallet funds into actual dollars.
 
Working for the HackerOne bug-bounty program, security researcher DrBrix, reported the bug last Monday. By Wednesday, Valve plugged the hole and paid DrBrix $7,500 for identifying the bug.

The Hack: Turning $1 into $100 or $1M

The bug, which has since been patched, was exploited by abusing Valve’s own application programming interface (API) used to communicate with the third-party web payment firm Smart2Pay, owned by Nuvei.
 
According to DrBrix, the hack allowed an attacker to intercept the POST request sent from Valve to Smart2Pay. This was done via modifying the Steam user’s email address used by Smart2Pay as it passed through the Valve API.

Read more: Critical Valve Bug Lets Gamers Add Unlimited Funds to Steam Wallets | Threatpost
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Messages In This Thread
Critical Valve Bug Lets Gamers Add Unlimited Funds to Steam Wallets - by silversurfer - 17 August 21, 12:08

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Google Updates Wear OS to Deliver Earthq...
Google is updating...harlan4096 — 12:28
HWiNFO v8.42
HWiNFO v8.42 Re...harlan4096 — 11:04
Mozilla Firefox Browser 148.0
Mozilla Firefox Br...harlan4096 — 08:24
Revo Uninstaller Freeware Version 2.6.8
Revo Uninstaller Fr...harlan4096 — 08:19
AV-Comparatives - Operational Technology...
Every year, AV-Com...harlan4096 — 08:18

[-]
Birthdays
Today's Birthdays
avatar (44)Baihu
Upcoming Birthdays
No upcoming birthdays.

[-]
Online Staff
There are no staff members currently online.

>