Results 1 to 5 of 5

Thread: Valve patches 'infinite money' Steam client bug

  1. #1
    HEXUS.admin
    Join Date
    Apr 2005
    Posts
    31,709
    Thanks
    0
    Thanked
    2,073 times in 719 posts

    Valve patches 'infinite money' Steam client bug

    The researcher who discovered the bug has been awarded a US$7,500 bounty.
    Read more.

  2. #2
    Registered+
    Join Date
    Aug 2017
    Posts
    20
    Thanks
    0
    Thanked
    0 times in 0 posts

    Re: Valve patches 'infinite money' Steam client bug

    It's simple enough to exploit but that seems like a Smart2Pay bug rather than a Steam bug.

  3. #3
    Registered+
    Join Date
    May 2018
    Posts
    34
    Thanks
    1
    Thanked
    4 times in 4 posts

    Re: Valve patches 'infinite money' Steam client bug

    The user would then have to intercept the corresponding POST request to the Smart2Pay API, where they could edit the credit amount up to $100.

    Step 4 sounds a bit technical, and I'm not sure how simple it would have been to execute.
    Quite easy really. I'm more impressed by them working out the validations checks would be passed by putting the token somewhere else. Something I've seen before though, the mistake might be something like there are two independent checks
    "Is the item code present" it finds a valid value then stops searching.
    "is the messaged signed and valid". It goes to the bottom of the message, skipping over the real item code and reads a valid signature.
    As a result it reports the transaction is good for up to $100 when it was only worth 1$

    As for step 4 you can do that yourself.

    Grab Firefox, Grab Burp Suit (or some other interception proxy). Point Firefox proxy at Burp, add the Burp certificate to Firefox. You can now view and edit all your traffic. Same principle can be applied to any browser, game or the steam client itself.

  4. #4
    IQ: 1.42
    Join Date
    May 2007
    Location
    old trafford
    Posts
    1,340
    Thanks
    132
    Thanked
    94 times in 80 posts
    • Tunnah's system
      • Motherboard:
      • Asus somethingorother
      • CPU:
      • 3700X
      • Memory:
      • 16GB 3600
      • Storage:
      • Various SSDs, 90TB RAID6 HDDs
      • Graphics card(s):
      • 1080Ti
      • PSU:
      • Silverstone 650w
      • Case:
      • Lian-Li PC70B
      • Operating System:
      • Win10
      • Internet:
      • 40mbit Sky Fibre

    Re: Valve patches 'infinite money' Steam client bug

    Quote Originally Posted by AnonAnon View Post
    It's simple enough to exploit but that seems like a Smart2Pay bug rather than a Steam bug.
    It's a bug in how Steam processes Smart2Pay transactions.

  5. #5
    Registered User
    Join Date
    Aug 2021
    Posts
    7
    Thanks
    0
    Thanked
    1 time in 1 post

    Re: Valve patches 'infinite money' Steam client bug

    Surprised that wasn't worth more than $7500 to them.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •