blademaster
I'm moving to Brazil
+2,075|7102
Cafe owners are in trouble, and users who made online purchases may be next

Valve's STEAM content distribution system has been the target of no small share of bad press since it was created, with complaints ranging from apathetic customer service to the inability to play legitimately purchased games online. Some users have had their accounts locked, deleted, or hijacked - but a hacker known only as "MaddoxX" has just opened a rather sizeable can of worms.

According to a posting made on an anti-STEAM website, MaddoxX has bypassed Valve's security system and accessed a significant chunk of data, including:

    * Screenshots of internal Valve web pages
    * A portion of Valve's Cafe directory
    * Error logs
    * Credit card information of customers
    * Financial information on Valve

While only the Cafe owners appear to be in immediate danger, MaddoxX claims to "have shell access everywhere," and has posted a list of login details for accounts on the Valve servers.  In addition, Maddox also reveals that private certificates for "People with a little bit of (sic) experience ... create their own 'fake' but working cafe / certificate."

It's not currently known how far-reaching the credit card breach is, but STEAM users who have purchased products online for electronic delivery would do well to keep an eye on their credit card statements for the next while, especially if MaddoxX makes good on a promise to release a "spreadsheet."

STEAM cafe owners worldwide are more than a little upset with the information already leaked. MaddoxX has posted emails received from cafe owners and operators:

    Believe me, nobody wants to 'stick it to Valve' more than those currently in the cafe program. We're rubbing pennies together trying to make it from month to month, while Valve is making millions off of us ... All I ask is that you make some effort to edit cafe numerical details from any future release.

    Please don't release the CC information, for the sake of the centers who are less informed.

MaddoxX does make one thing quite clear in his electronic manifesto:

    If you want me to remove these files you can e-mail me at (address removed) and I prefer you come with something good unless you want me to expose ALL of the customers their information.

It seems that Valve is being held for ransom. If this is true, Valve may be in trouble, as California Senate Bill 1386 requires that credit card holders be informed of any breach of their information, and MaddoxX already knows exactly how much money they have available.



Screenshots posted by MaddoxX reveal the extent of the breach

https://images.dailytech.com/nimage/4497_large_nublets.JPG

https://images.dailytech.com/nimage/4498_large_screenshot2_clip.JPG

Source

Last edited by blademaster (2007-04-20 22:35:56)

Fenix14
scout rush kekeke ^___^
+116|7014|Brisbane, Aus

another excuse to delay HL2 episode 2 Again lol.
Cybargs
Moderated
+2,285|7173
He's bluffing me thinks. Why would a Russian use German language?
https://cache.www.gametracker.com/server_info/203.46.105.23:21300/b_350_20_692108_381007_FFFFFF_000000.png
{M5}Sniper3
Typical white person.
+389|7217|San Antonio, Texas
I just knew that STEAM would drive someone off the deep end... And it just so happened to be a hacker...
Havok
Nymphomaniac Treatment Specialist
+302|7132|Florida, United States

Can we say OWNED?  But seriously, this is kinda major.  I don't have a Valve account, so I'm safe, but I'd be pissed as hell if a hacker got my info from a supposedly trustworthy source.  I hope they catch the fucker and charge him on a count of credit card theft for every card in the Valve database.
blademaster
I'm moving to Brazil
+2,075|7102
yeah not sure if he bluffing or not

Last edited by blademaster (2007-04-20 22:40:53)

{M5}Sniper3
Typical white person.
+389|7217|San Antonio, Texas
Update 04/19/2007: Doug Lombardi, director of marketing at Valve, contacted DailyTech with the following statement:

There has been no security breach of Steam. The alleged hacker gained access to a third-party site that Valve uses to manage the commercial partners in its Cyber Café program. This Cyber Café billing system is not connected to Steam. We are working with law enforcement agencies on this matter, and encourage anyone with more information to e-mail us at Catch_A_Thief@valvesoftware.com.

--------------------------------------------------------------------------------
agent146
Member
+127|6844|Jesus Land aka Canada

Havok wrote:

Can we say OWNED?  But seriously, this is kinda major.  I don't have a Valve account, so I'm safe, but I'd be pissed as hell if a hacker got my info from a supposedly trustworthy source.  I hope they catch the fucker and charge him on a count of credit card theft for every card in the Valve database.
but its not the the internet cafes that are screwed? not individual players with their own steam accounts.
maniacmattie
Karma Whore.. LOL
+27|6758
Old Haha

I bought CS:S online, but I believe theres nothing to worry about.

Update 04/19/2007: Doug Lombardi, director of marketing at Valve, contacted DailyTech with the following statement:

There has been no security breach of Steam. The alleged hacker gained access to a third-party site that Valve uses to manage the commercial partners in its Cyber Café program. This Cyber Café billing system is not connected to Steam. We are working with law enforcement agencies on this matter, and encourage anyone with more information to e-mail us at Catch_A_Thief@valvesoftware.com.
some_random_panda
Flamesuit essential
+454|6847

That guy needs to go outside and get a job.
DooM
Member
+28|6764
Steam suck anyway. No one should HAVE to have a Internet connection in order to play their games and HAVE to connect to an account server to play them. Valve are pathetic, no wonder they get hacked so easily, they are too busy drooling over the big bucks they forget about that, I would have thought they would have learned after the 03 incident of HL2 theft. Now this, idiots tbh, many who put their money and trust into Valve are now compromised, bad company imo.
Sarrk
O-O-O A-O A
+788|7112|Brisbane, Australia

DooM wrote:

Steam suck anyway. No one should HAVE to have a Internet connection in order to play their games and HAVE to connect to an account server to play them. Valve are pathetic, no wonder they get hacked so easily, they are too busy drooling over the big bucks they forget about that, I would have thought they would have learned after the 03 incident of HL2 theft. Now this, idiots tbh, many who put their money and trust into Valve are now compromised, bad company imo.
The reason why you need an internet connection and an account server is so that people cant hack the games to play them offline.
DeathHasDualPistols
Member
+10|6761|Karrinyup, W.A.
Bah, I think its all shit. I have a steam account (dowlingt) and I'm not particularly worried because the only game I have on it is CS:S and it wasnt my Credit card (too young for one). A mate set up the account for me. Either way, I doubt hes gonna pick an account to steal from and its gonna be you'res or any one you know
RoosterCantrell
Goodbye :)
+399|6937|Somewhere else

Sarrk wrote:

DooM wrote:

Steam suck anyway. No one should HAVE to have a Internet connection in order to play their games and HAVE to connect to an account server to play them. Valve are pathetic, no wonder they get hacked so easily, they are too busy drooling over the big bucks they forget about that, I would have thought they would have learned after the 03 incident of HL2 theft. Now this, idiots tbh, many who put their money and trust into Valve are now compromised, bad company imo.
The reason why you need an internet connection and an account server is so that people cant hack the games to play them offline.
I agreee with DooM.  I bought HL2 E1 and have never played it.  See, I have this little notebook that I write all my codes, credit card numbers, and passwords.  Everytime I get a new password I write what the password is used for and what the password is.

My handwriting is so horrible even I cant read it at times, so when I write down a code I write it very carefully and very legibly.  Since I have this password WRITTEN DOWN, the answer to my secret question, "what was your pet's name" I just went swiped my hand on the keyboard real quick.

Big mistake.  Turns out, the password I had written down, which I typed in several times before because I never commit any codes to system memory, no longer worked.  I had not logged onto steam in a few weeks, i beat HL2, so when I bought E1.  Password no longer worked, I didn't have the answer to the "pet" question, and an e-mail to valve said to go to this section of our site, fill this out, send this email blah blah blah. I did. And here I sit with no results.   

I was so pissed at first, now, meh, I got burned, I got over it. But, anytime I look into buying a game and I see the good ol valve logo, I put that shit right back down.
DeathHasDualPistols
Member
+10|6761|Karrinyup, W.A.

RoosterCantrell wrote:

I agreee with DooM.  I bought HL2 E1 and have never played it.  See, I have this little notebook that I write all my codes, credit card numbers, and passwords.  Everytime I get a new password I write what the password is used for and what the password is.

My handwriting is so horrible even I cant read it at times, so when I write down a code I write it very carefully and very legibly.  Since I have this password WRITTEN DOWN, the answer to my secret question, "what was your pet's name" I just went swiped my hand on the keyboard real quick.

Big mistake.  Turns out, the password I had written down, which I typed in several times before because I never commit any codes to system memory, no longer worked.  I had not logged onto steam in a few weeks, i beat HL2, so when I bought E1.  Password no longer worked, I didn't have the answer to the "pet" question, and an e-mail to valve said to go to this section of our site, fill this out, send this email blah blah blah. I did. And here I sit with no results.   

I was so pissed at first, now, meh, I got burned, I got over it. But, anytime I look into buying a game and I see the good ol valve logo, I put that shit right back down.
I disagree with you. It was youre own stupidity and failing that you lost it, not Valve. You may have typed it incorrectly, and you should have kept your recovery question good, TARD.

Last edited by DeathHasDualPistols (2007-04-21 05:48:29)

Lucien
Fantasma Parastasie
+1,451|7110
Be quiet you fucking morons.

Valve support is fine, if you do what the fuck they tell you to do. spend two minutes reading up on your problem and you can send them the info they need to fix it. just two weeks ago I lost my password, the e-mail I used was gone so I couldnt retrieve it, so I just e-mailed steam support telling them what happened along with a scan of my CD-keys and voila, less than 24 hours later they'd reset the password for me and updated my e-mail adress. And that's not the only time they've been happy to help someone with a little common sense.

Rooster, you don't deserve support.

I'll save you all the rant as to why DooM needs to go and shoot himself in the head as well.

utter. bullshit.
https://i.imgur.com/HTmoH.jpg
{M5}Sniper3
Typical white person.
+389|7217|San Antonio, Texas

Sarrk wrote:

DooM wrote:

Steam suck anyway. No one should HAVE to have a Internet connection in order to play their games and HAVE to connect to an account server to play them. Valve are pathetic, no wonder they get hacked so easily, they are too busy drooling over the big bucks they forget about that, I would have thought they would have learned after the 03 incident of HL2 theft. Now this, idiots tbh, many who put their money and trust into Valve are now compromised, bad company imo.
The reason why you need an internet connection and an account server is so that people cant hack the games to play them offline.
I play CS offline at school, my whole Computer Maintance class plays on a LAN offline.
Hurricane
Banned
+1,153|7087|Washington, DC

Whatever this hacker's ultimatum is, it should be responded to with a surgical bomb strike on his house. By a B-2. Honestly, do people like this even know what a person of the opposite gender looks like?

edit: Never heard of a gay hacker, but I suppose my question could also say "a person of the same gender" =p

Last edited by Hurricane (2007-04-21 07:49:22)

kylef
Gone
+1,352|6950|N. Ireland

SargeV1.4 wrote:

Be quiet you fucking morons.

Valve support is fine, if you do what the fuck they tell you to do. spend two minutes reading up on your problem and you can send them the info they need to fix it. just two weeks ago I lost my password, the e-mail I used was gone so I couldnt retrieve it, so I just e-mailed steam support telling them what happened along with a scan of my CD-keys and voila, less than 24 hours later they'd reset the password for me and updated my e-mail adress. And that's not the only time they've been happy to help someone with a little common sense.

Rooster, you don't deserve support.

I'll save you all the rant as to why DooM needs to go and shoot himself in the head as well.

utter. bullshit.
Agreed. STEAM is the best platform I have ever used for gaming. If I can buy a game through STEAM or somewhere else, I buy it through STEAM.
David.P
Banned
+649|6731

DooM wrote:

Steam suck anyway. No one should HAVE to have a Internet connection in order to play their games and HAVE to connect to an account server to play them. Valve are pathetic, no wonder they get hacked so easily, they are too busy drooling over the big bucks they forget about that, I would have thought they would have learned after the 03 incident of HL2 theft. Now this, idiots tbh, many who put their money and trust into Valve are now compromised, bad company imo.
Hit the Nail on the head.

Steam sucks Period. I agree with doom and rooster i hate having to put up with all this BS just to play a game. And just 2 weeks ago my steam account started acting funny i could'nt play any games.(It said that this account was in use in another location, Funny i only have it on one pc) Valve could'nt help me, Their forums could'nt help(Fucken mods locked it) The only people that helped we're on Gamespot forums.


Fuck Steam The download times are a bitch(I bought all my games at the store but i downloaded that lost coast map from steam) With all the shit i had to put up with to play HL2 deathmatch made that 50$ i spent,
I would've gladly bought 10 my little pony games instead!

Last edited by David.Podedworny (2007-04-21 08:19:17)

DooM
Member
+28|6764
OKAY well put it this way, I'd accept Steam maybe if Valve could code a fucking program correctly, poor security poor programming. No I can't code one as its not something I have learned, but you'd think a multi-million dollar making company would get a fucking clue.
StokoE
Losers-Server
+51|7297|UK
get a life ! fuck me.. who cares ?

Board footer

Privacy Policy - © 2025 Jeff Minard