STEAM HACKED - CHANGE YOUR PASSWORD !

Associate
Joined
9 Jul 2015
Posts
71
Location
Inside Your Computer
So I snoop around the internet why my account wasn't working and I have found that there was the exploit which allowed anyone knowing your account name on steam to restart the password without using the e-mail. The bug is fixed from what I can tell.

So guys change your passwords and additionally set-up 2-way factor authentication by using smartphone app.
 
Last edited:
If my password still works why would I need to change it?

This..

But yeah, everybody should be using 2-step for everything that supports it anyway.

NO PASSWORD CHANGE REQUIRED. JUST MAKE SURE YOU HAVE STEAM GUARD ENABLED.


Unless you've been received Steam Guard authentication emails in which case, yeah, you do need to change your password.
 
Last edited:
If you've got steam guard enabled wouldn't that have stopped them?

From what I know that they still were able to change your password regardless if you had steam guard turned on or off as password recovery is done by e-mail anyway so if they changed your password and you have steam guard turned on they couldn't simply login into your account as they needed the code sent by SMS.

I imagine it would have, but then I question why these big streamers would have steam guard disabled.

Most of the Celebrities either on Internet (KSI for instance) or real life like Taylor Swift etc needs to be educated more towards computer security as they don't give a damn about it at all I would say.
 
I imagine it would have, but then I question why these big streamers would have steam guard disabled.

Such as? But I'm guessing it's because they are stupid.

From what I know that they still were able to change your password regardless if you had steam guard turned on or off as password recovery is done by e-mail anyway so if they changed your password and you have steam guard turned on they couldn't simply login into your account as they needed the code sent by SMS.

So they still couldn't login, so Steam Guard did it's job?
 
Last edited:
I'm sick of changing my passwords for things. It seems like it's almost a weekly occurrence that something gets hacked or leaked.

I won't be doing it this time seen as everything seems to be in order and I have the steam guard thing set up anyway.

Very odd how such a simple exploit was allowed to slip through the net though lol.
 
so why do I need to change my password? and how was valve hacked?

can he op has a temp ban for misleading daily mail thread topic?
 
So they still couldn't login, so Steam Guard did it's job?
Yes, since you have turned 2 way verification via Steam Guard you should be alright. They shouldn't be able to login into your account even if they change the password as two way verification sends you short code via SMS which later on you must input into textbox field to get access to your account. Here it is how does it actually works:

https://blogs.zoho.com/wp-content/uploads/2013/12/zoho-two-factor-authentication1.png

No hotlinking of images, if you want to post an image please rehost on your own webspace. Thank you.

but if you didn't had two way verification and someone knows your steam account name and try to hack your account you are basically ****ed just like the streamers, lol.

I'm sick of changing my passwords for things. It seems like it's almost a weekly occurrence that something gets hacked or leaked.
I still laugh at Ashley Madison hack from few days back, it's funny as hell, lol. I guess it's how does technology goes, someone makes a system with pretty good security or screw up a simple thing like the one with Steam and hacks goes from left to right. The one witch good security usually got fixed immediately tho.

can he op has a temp ban for misleading daily mail thread topic?

LMFAO ...

. . . . . . . . . . . . . . . . . . . ________
. . . . . .. . . . . . . . . . . ,.-‘”. . . . . . . . . .``~.,
. . . . . . . .. . . . . .,.-”. . . . . . . . . . . . . . . . . .“-.,
. . . . .. . . . . . ..,/. . . . . . . . . . . . . . . . . . . . . . . ”:,
. . . . . . . .. .,?. . . . . . . . . . . . . . . . . . . . . . . . . . .\,
. . . . . . . . . /. . . . . . . . . . . . . . . . . . . . . . . . . . . . ,}
. . . . . . . . ./. . . . . . . . . . . . . . . . . . . . . . . . . . ,:`^`.}
. . . . . . . ./. . . . . . . . . . . . . . . . . . . . . . . . . ,:”. . . ./
. . . . . . .?. . . __. . . . . . . . . . . . . . . . . . . . :`. . . ./
. . . . . . . /__.(. . .“~-,_. . . . . . . . . . . . . . ,:`. . . .. ./
. . . . . . /(_. . ”~,_. . . ..“~,_. . . . . . . . . .,:`. . . . _/
. . . .. .{.._$;_. . .”=,_. . . .“-,_. . . ,.-~-,}, .~”; /. .. .}
. . .. . .((. . .*~_. . . .”=-._. . .“;,,./`. . /” . . . ./. .. ../
. . . .. . .\`~,. . ..“~.,. . . . . . . . . ..`. . .}. . . . . . ../
. . . . . .(. ..`=-,,. . . .`. . . . . . . . . . . ..(. . . ;_,,-”
. . . . . ../.`~,. . ..`-.. . . . . . . . . . . . . . ..\. . /\
. . . . . . \`~.*-,. . . . . . . . . . . . . . . . . ..|,./.....\,__
,,_. . . . . }.>-._\. . . . . . . . . . . . . . . . . .|. . . . . . ..`=~-,
. .. `=~-,_\_. . . `\,. . . . . . . . . . . . . . . . .\
. . . . . . . . . .`=~-,,.\,. . . . . . . . . . . . . . . .\
. . . . . . . . . . . . . . . . `:,, . . . . . . . . . . . . . `\. . . . . . ..__
. . . . . . . . . . . . . . . . . . .`=-,. . . . . . . . . .,%`>--==``
. . . . . . . . . . . . . . . . . . . . _\. . . . . ._,-%. . . ..`\
 
Last edited:
So I snoop around the internet why my account wasn't working and I have found that there was the exploit which allowed anyone knowing your account name on steam to restart the password without using the e-mail. The bug is fixed from what I can tell.

So guys change your passwords and additionally set-up 2-way factor authentication by using smartphone app.
so why do I need to change my password? and how was valve hacked?

can he op has a temp ban for misleading daily mail thread topic?
exactly this^^

There was/is a 0day which allows a hijacker to bypass steamguard (I contacted steam regarding it in April with full malware analysis & links to the source)
This however required the client to install malware (which in this case was a teamspeak installer with the malware)

So the whole "STEAM HACKED - CHANGE YOUR PASSWORD !" seems a bit wrong

"allowed anyone knowing your account name on steam to restart the password without using the e-mail"
Also seems unlikely (without first infecting the target machine)

update: just wanted to add that the malware found was also sent to antivirus vendors and is now detected by most (22 / 56 on virustotal)
 
Last edited:
People who wonder how they get infected with this sort of **** and how there ID's get robbed.


vryHGx6.png



This is how they get hacked.

10/10 LEGIT no hacks promise XD
 
exactly this^^

There was/is a 0day which allows a hijacker to bypass steamguard (I contacted steam regarding it in April with full malware analysis & links to the source)
This however required the client to install malware (which in this case was a teamspeak installer with the malware)

So the whole "STEAM HACKED - CHANGE YOUR PASSWORD !" seems a bit wrong

"allowed anyone knowing your account name on steam to restart the password without using the e-mail"
Also seems unlikely (without first infecting the target machine)

According to a youtube video I looked at it was true, just google "steam hacked" and it should be the youtube video at the top under the "in the news" section.

I'd explain it, since it only takes one sentence to do, but the mods removed it from the OP already :p.

All you needed was the account name.
 
According to a youtube video I looked at it was true, just google "steam hacked" and it should be the youtube video at the top under the "in the news" section.

I'd explain it, since it only takes one sentence to do, but the mods removed it from the OP already :p.

All you needed was the account name.
The video looks fake

Good way to get views/likes tho I guess.

If the thread was about that video, how does a pw reset bug equate to "STEAM HACKED" and also how would changing your password help anything? :confused:
 
Last edited:
LMFAO ...

Why are you laughing at him? He's completely right. Passwords were never leaked so they do not need changing, unless you cannot login in.

Valve have enough security in place to take advantage of. If someone has gained access to your account, it's your fault.

Also you're talking about Steam Guard Mobile Authenticator, Steam Guard sends an e-mail, not SMS.
 
Last edited:
Back
Top Bottom