Page 1 of 1

Steam Forums hacked!

Posted: 09 Nov 2011, 13:41
by Anakha56
http://www.techpowerup.com/154776/Steam ... ckers.html
Steam Forums Get Nailed By Hackers
Valve, a company that operates solely online, takes its security pretty seriously and has a good reputation in this area. However, at the time of writing, its Steam forums are down, having suffered a hack attack earlier today. Visit the forums now and you see a message saying "The Steam Forums are temporarily offline for maintenance. Your patience is appreciated." This attack was apparently done by hackers who want to offer free game cheats (but one should be wary of stealthy malware payloads) since before the forums were taken down, they had planted this message:
Ever wanted to dominate the servers you play on with guaranteed results, but you were too afraid to cheat because of ban risks?
The rest of the message then recommends a website where one can obtain all sorts of illegal game cheats, hack tools and porn. Some Steam forum users even received an email with this text, such as this NeoGAF user. There's no indication that any user's account information has been compromised. However, if you haven’t yet set up Steam Guard, now is a good time to do so, along with changing your password when the forums come back online. Also, be sure to use different a password for every login. Of course, many other gaming forums have been hacked in the past and just this year saw many hacks against such big names as Nintendo, Sega, BioWare, Epic Games and of course Sony, which was hacked many times over in protest at their business practices, such as removing the OtherOS feature from their PS3 console.

Re: Steam Forums hacked!

Posted: 09 Nov 2011, 14:04
by RuadRauFlessa
Oh please steal my account.... I beg you...

Re: Steam Forums hacked!

Posted: 09 Nov 2011, 14:22
by StarBound
And here I thought it was because of the MW3 raging that they took it offline.

Re: Steam Forums hacked!

Posted: 09 Nov 2011, 14:28
by senile
RuadRauFlessa wrote:Oh please steal my account.... I beg you...
why

Re: Steam Forums hacked!

Posted: 09 Nov 2011, 14:32
by RuadRauFlessa
There is nothing wrong with the games I have but they constantly want me to download updates for games before I can play them.

One of the games downloaded a patch and all that was in the patch notes was something about localization for an east asian country. And I still had to sit through a 300MB download...

Re: Steam Forums hacked!

Posted: 09 Nov 2011, 14:41
by StarBound
Can't you turn off auto-update?

Re: Steam Forums hacked!

Posted: 09 Nov 2011, 14:45
by Anakha56
StarBound wrote:Can't you turn off auto-update?
I have tried that... For some reason Steam keeps resetting it back to auto download... :?

Re: Steam Forums hacked!

Posted: 09 Nov 2011, 14:45
by RuadRauFlessa
StarBound wrote:Can't you turn off auto-update?
Errrr... no. It is steam we are talking about. You try to launch a game and the first thing it does is check if it has all the updates. If it does not it grabs and installs them. Also the disable button is there but it is broken. Seems someone clicked on it once too many or some such.

Re: Steam Forums hacked!

Posted: 11 Nov 2011, 09:25
by Anakha56
This just became quite huge...

http://arstechnica.com/gaming/news/2011 ... mpaign=rss
Valve confirms Steam hack: credit cards, personal info may be stolen
By Casey Johnston | Published about 8 hours ago

The recent Steam hack may have compromised users' credit card numbers and other personal information, according to a message sent to Steam users from Gabe Newell, head of Valve. The company is certain the hackers gained access to a database with this encrypted information, but don't know if they took it or will be able to crack its encryption.

Earlier this week, the Steam forums were taken offline due to some vandalization by the video game hacks website fkn0wned. A message on the forums noted they were down for maintenance, but it turns they had received uninvited guests ealier after all.

The compromised database held information such as user names, hashed and salted passwords, game purchases, e-mail addresses, billing addresses and encrypted credit card information, according to Newell.

Newell writes that the company does not have evidence that the encrypted credit card numbers or personal info were taken by the intruders, and the company is "still investigating." He goes on to say that there is also no evidence of credit card misuse, but implores Steam users to "watch your credit card activity and statements closely."

The full text of his message:
Dear Steam Users and Steam Forum Users,

Our Steam forums were defaced on the evening of Sunday, November 6. We began investigating and found that the intrusion goes beyond the Steam forums.

We learned that intruders obtained access to a Steam database in addition to the forums. This database contained information including user names, hashed and salted passwords, game purchases, email addresses, billing addresses and encrypted credit card information. We do not have evidence that encrypted credit card numbers or personally identifying information were taken by the intruders, or that the protection on credit card numbers or passwords was cracked. We are still investigating.

We don’t have evidence of credit card misuse at this time. Nonetheless you should watch your credit card activity and statements closely.

While we only know of a few forum accounts that have been compromised, all forum users will be required to change their passwords the next time they login. If you have used your Steam forum password on other accounts you should change those passwords as well.

We do not know of any compromised Steam accounts, so we are not planning to force a change of Steam account passwords (which are separate from forum passwords). However, it wouldn’t be a bad idea to change that as well, especially if it is the same as your Steam forum account password.

We will reopen the forums as soon as we can.

I am truly sorry this happened, and I apologize for the inconvenience.

Gabe.
Time to change CC details... :(

Re: Steam Forums hacked!

Posted: 11 Nov 2011, 09:32
by Tribble
Doing that now - luckily I use paypal

Re: Steam Forums hacked!

Posted: 11 Nov 2011, 11:02
by StarBound
I already changed my CC details with PSN. Now I need to do it with Steam?!

Re: Steam Forums hacked!

Posted: 11 Nov 2011, 11:07
by RuadRauFlessa
Luckily I don't have a CC for them to abuse :P

Re: Steam Forums hacked!

Posted: 11 Nov 2011, 11:10
by StarBound
The thing is I don't save CC details. I use it then enter it the next time. What worries me is I don't know if they save it somewhere after usage for their records or not.

Re: Steam Forums hacked!

Posted: 11 Nov 2011, 11:12
by RuadRauFlessa
That could be an issue. Better to just keep a close eye on your account and report any irregularities as soon as possible.

Re: Steam Forums hacked!

Posted: 11 Nov 2011, 14:49
by Bladerunner
The CC number is surely encrypted/hashed?

Re: Steam Forums hacked!

Posted: 11 Nov 2011, 17:39
by Anakha56
Image

@Blade one would hope they were... :?

Re: Steam Forums hacked!

Posted: 11 Nov 2011, 17:40
by D3PART3D
Are we going to receive two free games :?:

Re: Steam Forums hacked!

Posted: 14 Nov 2011, 04:02
by hamin_aus
D3PART3D wrote:Are we going to receive two free games :?:
No but someone out there may make two or more "free" purchases with your credit card :P