Wszystkie dyskusje > Fora Steam > Help and Tips > Szczegóły wątku
My Friend Account Hacked and Can't get it back because Re Capctha
Hello, my friend account was hacked and ca't get it back, yesterday we want to play but he can't sign in to steam, we just realise that his account was hijacked, we try to reset a password from steam support but we can't send a request because a Capctha error. It says, "Your response to the CAPCTHA appears to be invalid, Please verify again you are not robot". Any idea to resolve it? Thank you
< >
Wyświetlanie 1-8 z 8 komentarzy
Your friend gave away his login credentials for free. He was not hacked.

https://steamcommunity.com/sharedfiles/filedetails/?id=1126288560
Vins0504 2 maja 2022 o 19:04 
No he was hacked, because when his computer was off at 10pm but his steam was online and playing a Lost Ark, how you know my friend give his login credential for free? Is it because the Captcha error?
Ostatnio edytowany przez: Vins0504; 2 maja 2022 o 19:07
I know it is very irritating to admit your own wrongdoing. The least I can offer you is "phishing" and I only say that because "randomly logging into sites" sounds too pretentious ...

Because the narrative of a "hacker" who simply steals your login data is ... unfortunately only a sometimes well-told story. But nothing more.

The guide above should answer all his questions.
Vins0504 2 maja 2022 o 19:13 
Ahh okay thank you, i will info to him
Vins0504 2 maja 2022 o 19:24 
Anyway, the step 2 from the guide you share still same the re-Captcha still error, and the guide said to comment it with the reference id, should we share the reference ID too?
It's all written in the guide. All you need to do is reading it ...
Teksura 2 maja 2022 o 20:39 
Początkowo opublikowane przez Vins0504:
No he was hacked, because when his computer was off at 10pm but his steam was online and playing a Lost Ark, how you know my friend give his login credential for free? Is it because the Captcha error?
We know because of two major points:

1: Hijacking like this is common enough that we see threads exactly like this every day. and they all have the exact same cause. Every. Single. One.

2: If someone were to hack Valve's servers (which is an extraordinary feat I don't think you understand, by the way), why the hell would they decide to go after your friends account in specific instead of, I dunno, all that juicy payment and user data which is worth actual money and is actually worth their time and effort?



Let me explain how these things work.


Phishing is a crazy easy way to get control of people's accounts because you're relying on the weakest link in account security: The user themselves. It basically boils down to just asking the user to provide information they need by just telling you that they are someone they are not. Watch this video for more info on that: https://www.youtube.com/watch?v=BnmneAjVrM4


So, now that you know what Phishing is, let's talk about how this happens on Steam. There are a few common ways this happens. The most common methods involve asking you to log into a third party website through your Steam account. But, they ask you to give *them* your login information, rather than using Steam's system which redirects you to Steam for this. Some of these sites will generate a fake popup window that is designed to look like Steam's login window and they will try and get your credentials that way. Others will redirect you to a similar sounding domain which also mimics Steam's website. Still others will simply display a small image they made which claims to be some sort of evidence that they are in fact legitimate or authorized by Steam and here is a cheap .jpg anyone could create, copy, and display anywhere to prove the legitimacy.

What sort of sites do this? Very often, we see this happen from trading or gambling sites. these sort of sites usually look to hijack your account in a way to steal your items, as after you give them access they establish a web API so they can have a bot initiate trades to their own throwaway bot accounts to replace the trades you try and make with your friends. Sometimes this will accompany claims that your account is about to be banned and you have a limited time to send all your items away. Another common site that does this is the "vote for my team" scam, where you get approached by someone who tries to get you to vote for their team in some game or tournament or something. The site will give you fake login info, and then you'll lose access to the account when you enter the details. Usually these sites are trying to make money on your account by selling access to the account to people. Whoever buys access to the account could play any game in the library they like, and can even use whatever cheats they like since hey, not their account so what do they care if you get VAC banned?

So, no. Nobody sat down in a coffee shop wearing a hoodie and sunglasses while they type on their laptop until they pull out a flipphone, call someone, and say "I'm in". That only happens in movies.
$nÒÓp DoGG 15 kwietnia 2023 o 23:06 
This happened to me to on a smurf account. And no the guide doesn’t cover this because I had this run in with Facebook too when that was hacked.

When I sent the Facebook guy video (i recorded my screen for 8 hours that day before and during the hack) they actually uncovered a huge vulrnability that has to do with overloading the reset code Facebook sent me.

This is how it worked: I would request a new password from Facebook or request an email change. Now here is the vulnrability: the hacker also receives an alert that ‘someone is trying to change your password’.

IMMEDIATELY as the hacker receive this mail he pings Facebook with hundreds of WRONG codes in milliseconds. Now what happens when I enter my code? ‘You tried too many times, try again in 24h’

This is EXACTLY the same scenario here only the text is ‘re-captcha error’

So basically the hack works like this - hacker will go into your account and change email to his. This is so that his email recieves a notification when account info is being changed. As soon as you try to enter your reset code, he has already automatically flodded the reset page with hundreds of random codes in milliseconds causing your attempt to fail. Here it seems like the hacker is intentionally failing the captcha = making it 100% impossible to regain your account without contacting support. You can’t beat it once they are in, which is why this particular hack reminds me so much of my hacked facebook. The facebook guy I showed the video to was stunned that no one caught it earlier but guess what? All these websites refer to help pages where you can’t find and solve NEW hacks

When support reaches you to manually give you the a account it’s already too late. You cs:go skins are already cashed out into their paypal and they transfer and buy gifts to themselves that are immediately exchanged to Dollars.
< >
Wyświetlanie 1-8 z 8 komentarzy
Na stronę: 1530 50

Wszystkie dyskusje > Fora Steam > Help and Tips > Szczegóły wątku
Data napisania: 2 maja 2022 o 18:54
Posty: 8