Install Steam
login
|
language
简体中文 (Simplified Chinese)
繁體中文 (Traditional Chinese)
日本語 (Japanese)
한국어 (Korean)
ไทย (Thai)
Български (Bulgarian)
Čeština (Czech)
Dansk (Danish)
Deutsch (German)
Español - España (Spanish - Spain)
Español - Latinoamérica (Spanish - Latin America)
Ελληνικά (Greek)
Français (French)
Italiano (Italian)
Bahasa Indonesia (Indonesian)
Magyar (Hungarian)
Nederlands (Dutch)
Norsk (Norwegian)
Polski (Polish)
Português (Portuguese - Portugal)
Português - Brasil (Portuguese - Brazil)
Română (Romanian)
Русский (Russian)
Suomi (Finnish)
Svenska (Swedish)
Türkçe (Turkish)
Tiếng Việt (Vietnamese)
Українська (Ukrainian)
Report a translation problem
theres no real harm that can be done here,
the most you could do was IP lookup teammates
but even then
it would not ever return the actual address of the player just whatever routing node they are going through
even better the one vid showing IPs had a few that are complete nonsense and just pulled off the internet to make it look legit
- Valve ignored security researches working on their bounty program, blocking them from it or downright revoking their access completely from it for reporting very critical security vulnerabilities which are still unfixed
- Remote code execution attacks after joining a server or before even joining a server were present since CS:GO days and were abused out in the wild to the point where security researches had to publicly warn people about it (was never fixed to my knowledge)
- If valve fixed a issue from bounty program, they didn't pay out the security researches their bounties for finding the security vulnarybility
- Valve nearly always rejected security researcher's proposals on a fix
...and to remind you guys of what happened in cs:go:
- CS:GO still executed malicious files if given the chance after joining a server
- Remote code execution just by pinging a server from Server Browser, or connecting to one that allowed attackers to do basically anything they want (ex. open calculator, run cmd/ps with payload) - this is still affecting Source games like Team Fortress 2 (afaik, maybe they finally fixed it lol but clearly not I guess)
+ there was even more which I forgot about, i'm pretty sure it's still on their hacker bounty board which they left in a ditch or completely scrapped after losing all trust from talented security researchers.
This company isn't perfect and shouldn't be held in such a high praise, unsanitized user input in UI is just a tip of the iceberg, the lower you descend, the more you start noticing how painfully unsecure this game is to the point where it feels like walking on thin ice on anything that isn't a valve server.
I also told you that the source 2 engine leak is the biggest issue in this problem from a few years ago.