此主题已被锁定
Orthopaktis 2023 年 6 月 18 日 下午 2:58
Steam Account Hacked Despite 2FA, Inventory Stolen
I recently had my account compromised due to a Steam-unrelated PC compromise (a trusted website was hacked, and delivered a RAT that infected my end).

All of my accounts remained secure, and safe, with the exception of Steam. Said hacker pulled the login "cookie" file that Steam uses to save login information, and used that to bypass 2FA. Somehow, they then — despite not having my password, email, or Steam Guard, posted hundreds of market sales and pawned off hundreds of dollars worth of inventory I had accumulated. I had not received a single notification or email to any of the postings until they actually sold.

Again, the hacker never had access to Steam Guard, my email, or password, and managed to wipe my inventory due to a shoddy security flaw in Steam's login system.

The hack came from an unrelated Minecraft based trusted website, not from me logging into a third party Steam one. At no point did my email (Proton) get compromised, nor did my phone/Steam Guard. And out of hundreds of accounts, ranging from lax security like Netflix to things like Microsoft — only Steam fell victim. It's a blatant security issue, and Valve as of yet refuses to even consider rectifying/restoring the losses, nor do they acknowledge the flaw exists at all.

While I acknowledge my failure in trusting the source of the PC hack, this particular issue is on Valve. Stealing account information by grabbing one unsecured file is a horrendous mismanagement of security, from someone who works in security. I'm just glad I didn't save payment info on Steam for them to do more reaching damage.
< >
正在显示第 121 - 125 条,共 125 条留言
RebelStreamers 2023 年 10 月 15 日 下午 7:56 
引用自 RebelStreamers

this is why the password managers have auto-fill and the password manager is doing the copy paste not the user aka the infected computer

if you want to see how watch this small video
https://youtu.be/SPru0GChf8E?feature=shared


but i am sure the common users will hate password managers if they try auto-fil and fail and this is why i didn't mention it before.
A malware that is aiming for a password manager could still grab the database password and the database and also the keyfile.
Just saying, so that its not forgotten to keep the computer safe.

One question, how do you sequence login pages that ask on one page for username, and then on another for password?

UPDATE ANSWER

the best way to avoid any hacker (including remote desktop hack) to steal your passwords with password managers is this.

1. key-file or usb device as security option on opening of the database file and use more than one by categorizing the activities. it is not the same if you lose the game account with email account. better use different databases.

2. perform auto-type with right mouse click on ALL LOGINS (if the password page is different than the login page like it is on gmail or twitter, you can create 2 auto-perform entries if you can't handle how to do it with one entry and do 2 actions with right click on entry or entries. one auto-perform action for login and one for password page). keepass has this page as auto-perform help[keepass.info] and as i know all of its variants have this option or maybe better, like having 2 expandable auto perform actions. one auto-perform action for both entries and one for each one of the entries separately.

3. disable remote desktop services or remote desktop redirector device bus of windows (gamers literally no need them!)

4. block with firewall the access from and to internet of the keepass application executable and its dlls to prevent or make it harder any exploitation.


and maybe the most important...

5. use a good 2nd Software Firewall that adds another one layer of protection to your files. unlike the antiviruses extra software firewall is not problem for the PC but for the... end user or the hacker :steammocking:
最后由 RebelStreamers 编辑于; 2023 年 10 月 15 日 下午 8:05
Dr.Shadowds 🐉 2023 年 10 月 15 日 下午 9:16 
Here how account can be hijacked.

A) User logs into scam site. This site can look real as that the point to fooling the victim. There tons, and tons of fake sites, with embedded browsers for your browser hence the fake page, as user be logging from their server, not your device hence why it fools you into confirming the login without realizing your not logging in from your device but from theirs instead.

B) Logging on device that is not theirs, and didn't actually log out, such as school library, cyber cafe, or etc...

C) Compromising their devices by downloading a virus, or giving scam backdoor access to the device. Even if you secure the account the device isn't safe due to the fact virus/backdoor still remains on device means user must find away to removing it, or wiping their whole system before they're in the actual clear.

D) Falling got scam that someone impersonate support, making up fake claims like you been ban, or have pending ban, or you own us money, you're in trouble, or whatever the story may be to trick victim into handing all the login info to them in some kind of email, or live chat like discord, and such.



Most common response people that rather not admit to their faults are people that refuse to believe anything, and think they were solo hacked compare to all other accounts on this platform, thinking they're special, or because they hate the thought they can be wrong, or think things don't apply to them for whatever the reason.
最后由 Dr.Shadowds 🐉 编辑于; 2023 年 10 月 15 日 下午 9:18
Hijacked n Robbed :'( 2024 年 12 月 4 日 上午 10:06 
I think my previous comment about specifically how the hack occurred was scrubbed? or this stuff is just broken AF. Either way I'm not typing it out again. Don't trust steam guard.
eram 2024 年 12 月 4 日 上午 10:07 
引用自 Hacked n Robbed :(
I think my previous comment about specifically how the hack occurred was scrubbed? or this stuff is just broken AF. Either way I'm not typing it out again. Don't trust steam guard.
no one got hacked
Eli 2024 年 12 月 4 日 上午 10:09 
This thread was quite old before the recent post, so we're locking it to prevent confusion.
< >
正在显示第 121 - 125 条,共 125 条留言
每页显示数: 1530 50

发帖日期: 2023 年 6 月 18 日 下午 2:58
回复数: 125