Install Steam
login
|
language
简体中文 (Simplified Chinese)
繁體中文 (Traditional Chinese)
日本語 (Japanese)
한국어 (Korean)
ไทย (Thai)
Български (Bulgarian)
Čeština (Czech)
Dansk (Danish)
Deutsch (German)
Español - España (Spanish - Spain)
Español - Latinoamérica (Spanish - Latin America)
Ελληνικά (Greek)
Français (French)
Italiano (Italian)
Bahasa Indonesia (Indonesian)
Magyar (Hungarian)
Nederlands (Dutch)
Norsk (Norwegian)
Polski (Polish)
Português (Portuguese - Portugal)
Português - Brasil (Portuguese - Brazil)
Română (Romanian)
Русский (Russian)
Suomi (Finnish)
Svenska (Swedish)
Türkçe (Turkish)
Tiếng Việt (Vietnamese)
Українська (Ukrainian)
Report a translation problem
No, only competitive
If you're such a good developer and hacker, you should know that a full XSS exploit could do way more than just 'grabbing the IP'. That was just a use case. They could execute code in your context on your machine via the game (logged in), which could theoretically lead to an API hack in-game, depending on a lot of factors. But not impossible, depending on valves mess....
Pirate Software explain it well enough for the guys here: https://www.tiktok.com/@cazegaming/video/7311541798592122154
There are also clips showing the XSS exploit loading a gif, and then the guy's inventory gets emptied, but it could be two different videos cut together.
https://www.tiktok.com/@rosiol01/video/7311498709664156961
Edit:
My personal guess is that the video shows the XSS hack, and the inventory gets cleared due to the workshop map exploit and is from a different clip, but I could be wrong. Also, the XSS hack had some kind of character limit, but the Workshop exploit didn't. But i dont find a lot of stuff on that, Heck, I don't even play Counter-Strike anymore :)
Edit 2:
In 2019, it was definitely possible to run JavaScript through such an XSS exploit. And "An attacker could achieve full system access to the victims computer." which also can lead to loss of inventory. (always depending on some factors..)
https://hackerone.com/reports/631956
But it seems this time it was not the case with the Javascript, or it's just not publicly known. Not a lot of info out there.
We probably will never know, since Valve won't tell.
Two exploits within a short timeframe, both really bad ones.
liltte monkey with IP u can do whatever u want cs2 was not safe