The writeup for the hack was posted on white-hat hacking bug bounty site HackerOne by the handle drbrix. Valve and drbrix later made the exchange public, once a fix was implemented. Drbrix first posted the bug as "medium" priority, saying "I think impact is pretty obvious, attacker can generate money and break steam market, sell game keys for cheap etc."
Valve, after testing the exploit and trying a fix, subsequently upgraded the bug to "Critical" severity and the corresponding payout to $7,500 USD "reflecting the potential cost to the business."
"We hope to hear more from you in the future," the Valve staff said.
Yes, I'm sure they would.
Valve told The Daily Swig that "Thanks to the person who reported this bug we were able to work with the payment provider to resolve the issues without any impact on customers." Valve did not say whether anyone had actually abused the potential exploit.
Posted:
Related Forum: PC Gaming Forum
Source: https://www.pcgamer.com/uk/security-flaw-for-unlimited-steam-wallet-funds-found-fixed/
"Security flaw for unlimited Steam Wallet funds found, fixed" :: Login/Create an Account :: 1 comment