Valve fixes critical remote code execution exploit
South Africa LustedSilli - 
According to Secret Club, Valve has finally fixed the critical remote code execution exploit for Source engine games, including CS:GO. Source: This exploit has reportedly been around for two years, which could allow some people to gain control of another's PC via a Steam invite, in the most basic of terms. Florian first found this exploit and reported it to Valve roughly two years ago, in case you haven't been following these developments. Thoughts?
2021-04-21 09:06
2021-04-21 09:06
2021-04-21 09:07
took a while
2021-04-21 09:06
How did this work essentially? Was this a sort of XSS attack and did I have to interact with the invite in order to be affected?
2021-04-21 09:07
As far as I can tell you needed to interact with the invite yeh. There's a while detailed technical explanation which was released after Valve fixed it
2021-04-21 09:13
Gave it a quick skim, basically Steam invites need to be able to launch the game when you do not already have it started. You can pass parameters along which can modify someones game or even establish a connection into the host machine. Very interesting.
2021-04-21 09:18
Ahhh I see, yeh quite interesting. I'm going to give it a good detailed read a bit later today
2021-04-21 09:43
Europe Ezmoneymens
>Valve fixes critical.. <2years >remember it's valve >woah_thatwasfast.jpg
2021-04-21 09:09
these 2 interns had hard work to do
2021-04-21 09:16
oh ok cool
2021-04-21 09:14
ropz | 
Netherlands ONGix
Riot developers been real quite since this dropped... Only 2 years to fix huge exploit? #Riot_Devs_Need_New_Jobs
2021-04-21 09:17
2021-04-21 09:21
I remember there was also a classic buffer overflow on CS 1.6's source code disclosed on Hackerone last year or so. At least they're being patched before causing any notable harm
2021-04-21 09:21
I guess the old rule of not trusting unexpected links still works.
2021-04-21 09:50
