Page 1 of 5

Steam Forums hacked.

Unread postPosted: Tue Nov 08, 2011 12:11 am
by LoneWolfDon
Some of you that frequent the Steam Forums may have noticed that the forums are currently unavailable for the last day or so and still currently unavailable as I type this post. "The Steam Forums are temporarily offline for maintenance. Your patience is appreciated." is the message seen if trying to visit the Steam-forums.

Apparently some Hacker-group has targeted the Steam forums and managed to change some of the forums front-pages with text changed to advertise a Hacker's-site with game-hacks, game-cheats and porn, as well apparently some Steam users have had their email addresses spammed with messages from this Hacker's-site.

You could do a Google search with search-terms like "Steam Forums are temporarily offline" or "Steam forums hacked" to find out more info and news sources on this event, but I didn't post any links in this message as it seems some of those sources are providing a link to the Hackers-group site that was seen advertised on the Steam-Forums after the hack (which I highly recommend to NOT visit the Hacker's site).
-----

So, though from what I gather, it was only just the bulletin-board that Steam uses for it's forums that some part of it, or perhaps an Admin's account there, got hacked. And supposedly all Users passwords for the Steam-Forums are encrypted anyways, I would still suggest that anyone who has an account on the Steam-Forums to change their Steam-Forum accounts password when their forums are back online and you're able to.

Also, from what I understand, the Steam-Forum accounts and Steam-Client accounts are completely different / separate, and also having the Steam-Guard feature enabled is a good idea too, but I might still suggest as an extra precaution to also consider changing your Steam-Client's Account password too (especially if you un-wisely used the same password for your Steam-Forum account and Steam-Client account, which I imagine a lot of Users do).

Chances are our Steam-Forum passwords are encrypted well-enough that they won't be easily decrypted (or it would take considerable computer resources, manpower and time to do so, and most likely not even feasible to attempt to do so), but still, better safe than sorry and I'm still planning on changing my Steam-Forum and Steam-Support-Account passwords when their forums are back up.

It's really sad that Hacker-groups like this even exists and can cause such grief and trouble for some companies like Steam and all it's Users (can't these "hackers" have something better and more productive to do with their time and skills?), but hopefully after the dust has settled that Steam/ Valve will take steps to prevent similar unfortunate events from happening in future.

Best regards,
--Don.

Re: Steam Forums hacked.

Unread postPosted: Tue Nov 08, 2011 12:32 am
by arizonachris
Thanks for the heads up, Don. I was wondering what happened. Hope no one's gaming account gets hacked. I had that happen once already, it wasn't fun. Hackers are worse than pond scum. !*not-ok*!

Re: Steam Forums hacked.

Unread postPosted: Tue Nov 08, 2011 1:36 am
by Chessie8638
There's no indication of user's passwords being compromised. If they wanted that info they would get it without changing anything to the site itself. Looks like they just hacked the vBulletin forum software. Still, good idea to change password AFTER it's back to normal.

About time Steam / Valve got hacked. After Nintendo, the Play Station Network, CodeMasters, Minecraft, etc, was only a matter of time.

EDIT: Anyhoo, they are down while they do damage assessment:

Image


EDIT #2: The Steam Forums are no way connected to Valve / Steam software. Your account passwords and whatnot are safe.
Hacking Valve's Vbulletin based forums isn't all that hard. I'll be impressed if they get into Steam's servers/Steamguard.

Re: Steam Forums hacked.

Unread postPosted: Tue Nov 08, 2011 2:04 am
by g_nash
LoneWolfDon wrote: but hopefully after the dust has settled that Steam/ Valve will take steps to prevent similar unfortunate events from happening in future.


Maybe learning that a security notice is issued for a reason and that patching vB exploits on Friday and not waiting till Monday is sound policy and won't make some companies look like amatuers .

LoneWolfDon wrote:can't these "hackers" have something better and more productive to do with their time and skills


Educating sloppy companies is a good thing .

*!lol!*

Re: Steam Forums hacked.

Unread postPosted: Tue Nov 08, 2011 4:52 am
by thecanadianrail
g_nash wrote:
Educating sloppy companies is a good thing .

*!lol!*


not when its an inconvenence to ME

Re: Steam Forums hacked.

Unread postPosted: Tue Nov 08, 2011 2:56 pm
by SMMDigital
Unfortunately, more ammunition for those who disagree with the having Railworks slaved to a Steam account this is, even though the forum hack had nothing to do with the gaming side of the operation.

Re: Steam Forums hacked.

Unread postPosted: Tue Nov 08, 2011 8:15 pm
by arizonachris
I love Steam. And their store and gaming end of things is very secure. Guess the Forums were not. But that was always the place to go for help with any game you got from Steam.

Not sure why it's taking them so long. I think I'm going into withdrawls. Gotta have my daily Steam/ RW Forum insults! !*roll-laugh*!

Re: Steam Forums hacked.

Unread postPosted: Tue Nov 08, 2011 10:28 pm
by Chessie8638
arizonachris wrote:But that was always the place to go for help with any game you got from Steam.


After you wade through the trolls and whatnot that infest those forums. !*roll-laugh*!

Re: Steam Forums hacked.

Unread postPosted: Thu Nov 10, 2011 6:35 pm
by Chessie8638
Statement from Gabe Newell. You should see it when you start Steam:


Image

If you haven't enabled Steam Guard do it:


→ Click Steam
→ Go to Settings
→ Manage Steam Guard Account Security...
→ Deauthorize all other computers now.

Re: Steam Forums hacked.

Unread postPosted: Thu Nov 10, 2011 7:48 pm
by Rich_S
This is another reason I like to pay for all DLC using PayPal, It adds another layer of protection. Now everyone with a credit card registered with Steam will have to watch their account to insure no one is using their information to make unauthorized purchases.

Re: Steam Forums hacked.

Unread postPosted: Thu Nov 10, 2011 8:09 pm
by MontanaRails
I dont see this notification anywhere, nor did it pop up upon opening steam for the first time today (just a few minutes ago).

And...It wont let me change my password. Its possible I've forgotten it, but the message I'm getting doesnt say its incorrect, just that "steam is unable to process my request"...

Edit: Just noticed it says users are required to change forum passwords only. Wonder why it wont let me change my account password....

Re: Steam Forums hacked.

Unread postPosted: Thu Nov 10, 2011 8:12 pm
by styckx
I really have zero concern over this still.

Re: Steam Forums hacked.

Unread postPosted: Thu Nov 10, 2011 10:04 pm
by LoneWolfDon
They were hacked a lot worse than I originally thought.

Re: Steam Forums hacked.

Unread postPosted: Thu Nov 10, 2011 11:01 pm
by g_nash
LoneWolfDon wrote:They were hacked a lot worse than I originally thought.


Any source code missing this time ?

:D

Re: Steam Forums hacked.

Unread postPosted: Fri Nov 11, 2011 8:00 am
by styckx
Image