Wyniki wyszukiwania

Wyświetlanie 1-10 z 294,767,426 pozycji
0
Custom missions
W tej chwili
ぺろりん
2
How to change language?
W tej chwili
edwarlord27
Na forum „Off Topic
92
Why do you care about politics?
W tej chwili
Paratech2008
3
extremely choppy/frame rate late game
W tej chwili
Thomas Goblinz
4
Girl Boss Characters
W tej chwili
Shlone
1
First Person view
W tej chwili
Lucius
18
EOMM wasnt real all along in marvel rivals
W tej chwili
Rauf
1
anyone want to play and also mic is requierd i need like 2 or 3 people with me
W tej chwili
Diruk
0
【A Lesson Learned in Blood】Your Steam Mobile Authenticator Is Useless! How I Watched Helplessly as My Balance Was Wiped Out.
W tej chwili
Matoi Ryuuko
I believe 99% of you, like me, thought that enabling the Steam Mobile Authenticator would make everything completely secure. We believed that as long as we had the authenticator, any transaction or login would require our confirmation, making our accounts impenetrable fortresses.

I was wrong. Dead wrong.

Just yesterday, over 100 dollars in my Steam wallet was drained within minutes as the hacker purchased DOTA2 low-value items worth just a few cents or dimes. The most terrifying part, the one that sent chills down my spine, was that throughout the entire process, my mobile authenticator did not receive a single verification prompt! Not one!

Yes, you read that right. The hackers used a method called "API Hijacking" to completely bypass the mobile authenticator, which was supposed to be the last line of defense. They didn’t need your authenticator to approve logins, nor did they require you to confirm transactions. Like ghosts, they carried this out from within your account.▌ How did the scam happen? (My speculated replay)

1. Infected: I might have inadvertently used my Steam account to log in to a fake third-party phishing website (e.g., a fake giveaway or trading site).
2. Leaked: This website stole my account’s API Key. This was like handing the scammer a backdoor key to spy on and interfere with my account, though they still couldn’t directly take anything.
3. Hijacked: When I subsequently performed normal operations, the scammer used the API key to monitor my account. The moment I initiated a legitimate transaction, they quickly canceled my real transaction and immediately exploited Steam’s market mechanism to send me an almost identical "fake trade offer."
4. Success: The recipient of this fake offer was actually another account controlled by the scammer. The "transaction" I confirmed on my mobile authenticator was actually authorizing the "purchase" of overpriced junk items listed on the market by them! My balance was thus legally transferred into the scammer’s pocket under the "protection" of the authenticator.

The authenticator’s function is to confirm "whether you want to perform this action," but it cannot help you judge "whether the action itself is a trap"!
19,497
31
The Coffee Pod
W tej chwili
HeyYou
Wyświetlanie 1-10 z 294,767,426 pozycji