Steam forums down after possible hacker attack

General gaming discussions

Steam forums down after possible hacker attack

Postby kugs » 07 Nov 2011, 19:03

http://www.pcgamer.com/2011/11/07/steam-forums-down-after-possible-hacker-attack/
“The Steam Forums are temporarily offline for maintenance. Your patience is appreciated.” That’s the message you’ll get if you’re trying to log into the Steam forums at the moment. They’ve been taken down due to an apparent hack that briefly saw front page text changed to advertise a game hacks site. Eurogamer say that some Steam users have had their email addresses spammed with messages from this site

A screenshot of the Steam forums before the hack shows that the official notices section at the top of the page had been altered to promote a site called Fkn0wned. The hack is a worrying breach of Steam’s usually watertight security, and is especially concerning for users whose Steam login details are the same as their Steam account username and password. Valve haven’t commented on the breach yet.


According to a (unconfirmed) post on Facepunch passwords may have been comprimised. If you use the same login details elsewhere is advisable you change it.
Image
Image
http://stats.gtfogaming.co.uk/actioninfo/471
Hoodlumdan <on TF2#1>: I loved my girlfriend more than life itself, we were together for 3 years since the age of 15. She left me for someone else.
Chanser <on TF2#1>: cos its f2p
User avatar
kugs
GTFO. Donor
GTFO. Donor
 
Posts: 453
Joined: 07 Feb 2010, 10:18
Location: Brighton

Re: Steam forums down after possible hacker attack

Postby GTFO. Gash » 07 Nov 2011, 19:47

hmm what was my password... :/
Image
Image
Image
User avatar
GTFO. Gash
GTFO. Clan Member
GTFO. Clan Member
 
Posts: 4100
Joined: 30 Nov 2005, 01:33
Location: City of Edinburgh

Re: Steam forums down after possible hacker attack

Postby GTFO. Luckyg » 07 Nov 2011, 19:49

GTFO. Gash wrote:hmm what was my password... :/


i believe it was "xXxL33tIrIshK1dxXx"
User avatar
GTFO. Luckyg
Wicked Sick
Wicked Sick
 
Posts: 3632
Joined: 16 Dec 2007, 13:05
Location: Nottingham

Re: Steam forums down after possible hacker attack

Postby GTFO. kk20 » 07 Nov 2011, 20:07

I dont think I ever had a steam forum login.
Breaking news! Scientists create life in the lab.
(faulty condoms blamed)
GTFO. kk20
GTFO. Clan Member
GTFO. Clan Member
 
Posts: 3620
Joined: 17 Jul 2008, 13:33
Location: Cumbria

Re: Steam forums down after possible hacker attack

Postby Getsuga Tensho » 11 Nov 2011, 00:30

Wasn't just the forums apparently. Valve released a message saying that Steam itself was compromised. :(

Here's a link to the message: http://forums.steampowered.com/forums/

Steam wrote:Dear Steam Users and Steam Forum Users:

Our Steam forums were defaced on the evening of Sunday, November 6. We began investigating and found that the intrusion goes beyond the Steam forums.

We learned that intruders obtained access to a Steam database in addition to the forums. This database contained information including user names, hashed and salted passwords, game purchases, email addresses, billing addresses and encrypted credit card information. We do not have evidence that encrypted credit card numbers or personally identifying information were taken by the intruders, or that the protection on credit card numbers or passwords was cracked. We are still investigating.

We don’t have evidence of credit card misuse at this time. Nonetheless you should watch your credit card activity and statements closely.

While we only know of a few forum accounts that have been compromised, all forum users will be required to change their passwords the next time they login. If you have used your Steam forum password on other accounts you should change those passwords as well.

We do not know of any compromised Steam accounts, so we are not planning to force a change of Steam account passwords (which are separate from forum passwords). However, it wouldn’t be a bad idea to change that as well, especially if it is the same as your Steam forum account password.

We will reopen the forums as soon as we can.

I am truly sorry this happened, and I apologize for the inconvenience.

Gabe.
Image
Image
Image

Image
User avatar
Getsuga Tensho
Addicted to GTFO
Addicted to GTFO
 
Posts: 193
Joined: 12 Jul 2010, 00:12
Location: Glasgow, Scotland

Re: Steam forums down after possible hacker attack

Postby Russian Guyovich » 11 Nov 2011, 12:04

Image

Image
User avatar
Russian Guyovich
24/7 GTFO
24/7 GTFO
 
Posts: 968
Joined: 22 Aug 2010, 12:42

Re: Steam forums down after possible hacker attack

Postby GTFO. Loser » 11 Nov 2011, 12:07

Interesting Russian lol
GTFO. Loser
Unstoppable!
Unstoppable!
 
Posts: 1013
Joined: 06 May 2010, 12:43
Location: London

Re: Steam forums down after possible hacker attack

Postby Bleed » 11 Nov 2011, 12:23

Logged into my steam forums account, didn't find any way to change my password. So the being forced to change password thing doesn't apply yet...

Logged into steam itself via browser, but can't find any way to change my password here either. Need the steam application for that?
Image

Image
User avatar
Bleed
Uber Poster
Uber Poster
 
Posts: 79
Joined: 20 Nov 2009, 11:56

Re: Steam forums down after possible hacker attack

Postby kugs » 11 Nov 2011, 12:44

Bleed wrote:Logged into my steam forums account, didn't find any way to change my password. So the being forced to change password thing doesn't apply yet...

Doesn't look like you can do anything until the forums are unlocked.

Kinda annoyed it took them 5 days to even acknowledge there was a hack, and so far they've only released this info on the forums. The people most at risk are the ones who use the same name/password for every account, and they're unlikely to check the forums or gaming websites. A mass email/im/accouncement on steam would be a better choice.

Email addresses and passwords being leaked are a bit worrying. The post didn't mention if they had any access to the salt used for the passwords. Your email address is the key to your online life, so make sure to revisit your security practices if you use that password anywhere else.

That's the negatives though. On the positive side the encryption used for credit cards is the same one used by the US Government, and though there have been attempts made to attack the encryption method, it's still pretty secure so not worried there.
Image
Image
http://stats.gtfogaming.co.uk/actioninfo/471
Hoodlumdan <on TF2#1>: I loved my girlfriend more than life itself, we were together for 3 years since the age of 15. She left me for someone else.
Chanser <on TF2#1>: cos its f2p
User avatar
kugs
GTFO. Donor
GTFO. Donor
 
Posts: 453
Joined: 07 Feb 2010, 10:18
Location: Brighton

Re: Steam forums down after possible hacker attack

Postby GTFO. KARR » 11 Nov 2011, 13:43

kugs wrote:
Bleed wrote:Logged into my steam forums account, didn't find any way to change my password. So the being forced to change password thing doesn't apply yet...


Kinda annoyed it took them 5 days to even acknowledge there was a hack, and so far they've only released this info on the forums. The people most at risk are the ones who use the same name/password for every account, and they're unlikely to check the forums or gaming websites. A mass email/im/accouncement on steam would be a better choice.


Logged two accounts in this morning to the Steam client , both had a full page popup with the same message that is/was on the forums stating the issues.
Image
User avatar
GTFO. KARR
GTFO. Clan Member
GTFO. Clan Member
 
Posts: 651
Joined: 09 Jan 2010, 00:44
Location: Worcester

Re: Steam forums down after possible hacker attack

Postby kugs » 11 Nov 2011, 13:56

Oh. Disregard that bit then :P.
Image
Image
http://stats.gtfogaming.co.uk/actioninfo/471
Hoodlumdan <on TF2#1>: I loved my girlfriend more than life itself, we were together for 3 years since the age of 15. She left me for someone else.
Chanser <on TF2#1>: cos its f2p
User avatar
kugs
GTFO. Donor
GTFO. Donor
 
Posts: 453
Joined: 07 Feb 2010, 10:18
Location: Brighton

Re: Steam forums down after possible hacker attack

Postby r3loaded » 11 Nov 2011, 15:07

As an aside, if you're using Gmail and have an Android/iOS device, now would be a good time to enable two-factor authentication. The security is worth having to whip out your phone each time you log in imo.
New Desktop: Core i5 2500K @ 4.6Ghz | Asus P8P67-M Pro | 8GB Corsair Vengeance | CM Hyper 212 Plus | KFA2 GTX 560 Ti | 128GB Crucial C300 + 1TB Samsung F3 | CM Silent Pro Gold 600W | Silverstone FT03-B | Samsung XL2270HD | Windows 7 x64 SP1
Image
User avatar
r3loaded
GTFO. Donor
GTFO. Donor
 
Posts: 2037
Joined: 27 Aug 2008, 12:32
Location: Manchester

Re: Steam forums down after possible hacker attack

Postby -NanoCorp- CyberPower » 12 Nov 2011, 00:17

Image
-NanoCorp- CyberPower
GTFO. Donor
GTFO. Donor
 
Posts: 684
Joined: 13 Sep 2008, 15:48
Location: Telford

Re: Steam forums down after possible hacker attack

Postby Crazyman » 12 Nov 2011, 11:47

Yeah the Gabe mail is a fake :(

Do wonder what sort of encryption they use on CC data tho.
Last edited by Crazyman on 12 Nov 2011, 12:00, edited 1 time in total.
21:15 - [FaB?]Coffin Stuffer: because i watch you sleep at night
21:15 - [FaB?]Crazyman: That's going on my GTFO sig

I KNEW IT
User avatar
Crazyman
Uber Poster
Uber Poster
 
Posts: 78
Joined: 18 Feb 2010, 00:09

Re: Steam forums down after possible hacker attack

Postby GTFO. Loser » 12 Nov 2011, 11:48

I hope we never find out what encryption they use. Makes it harder for the idiots to crack it!
GTFO. Loser
Unstoppable!
Unstoppable!
 
Posts: 1013
Joined: 06 May 2010, 12:43
Location: London

Re: Steam forums down after possible hacker attack

Postby r3loaded » 12 Nov 2011, 12:08

If they're using SHA and AES with a decent word size, we don't have much to worry about :)
New Desktop: Core i5 2500K @ 4.6Ghz | Asus P8P67-M Pro | 8GB Corsair Vengeance | CM Hyper 212 Plus | KFA2 GTX 560 Ti | 128GB Crucial C300 + 1TB Samsung F3 | CM Silent Pro Gold 600W | Silverstone FT03-B | Samsung XL2270HD | Windows 7 x64 SP1
Image
User avatar
r3loaded
GTFO. Donor
GTFO. Donor
 
Posts: 2037
Joined: 27 Aug 2008, 12:32
Location: Manchester

Re: Steam forums down after possible hacker attack

Postby GTFO. kk20 » 13 Nov 2011, 12:25

means nothing if you have the IV and key. Probably stored it in plain PHP for the taking...
Breaking news! Scientists create life in the lab.
(faulty condoms blamed)
GTFO. kk20
GTFO. Clan Member
GTFO. Clan Member
 
Posts: 3620
Joined: 17 Jul 2008, 13:33
Location: Cumbria

Re: Steam forums down after possible hacker attack

Postby GTFO. al » 14 Nov 2011, 00:51

not a single fuck given about the forum account...don't care about it.

changed my steam password anyway. not that it would matter much...it'll ask you to put in a code if you use it from a new computer anyway with that steam guard thing. and my email password isn't the same as steam...not a rookie.
Image
GTFO. al
GTFO. Founder
GTFO. Founder
 
Posts: 3080
Joined: 29 Nov 2005, 00:19
Location: Northern Ireland


Return to General



Who is online

Users browsing this forum: No registered users and 0 guests