Jump to content

thedamngod

Backer
  • Posts

    394
  • Joined

Posts posted by thedamngod

  1. From a reply of a mod on the linked reddit post, emphasis mine:

    I'm a web developer, and have investigated and created proofs of concept for this exploit.

     

    With the right know-how a malicious user could do these actions for example, and you only need to view a Steam Profile:

     

    Redirect you to any non-steam page, for example a phishing login page. From a user perspective it is you going to a legitimate Steam profile, then you see a login page. Seems legit right? Pop in your info. You didn't click anything suss so it's no big deal.

     

    Utilize scripting to use your Steam Market funds on any item the malicious user chooses, you wouldn't even need to confirm anything as you're on a valid login session.

     

    Manipulate elements on the page as they see fit.

     

    PLEASE Ensure that you are triple-checking the website URL before doing anything with your sensitive information.

     

    Go into your Steam Settings and enable "Display Steam URL Address Bar When Available", and triple-check. Also try to avoid viewing profiles of anybody you're unfamiliar with.

     

    I've forwarded my proofs of concept to Valve Security and they should be actioning this very rapidly.

  2. UPDATE: Everything seems fixed

     

     

    Currently, there is a risk (i.e. phishing, malicious script execution, etc.) involved when viewing or simply opening PROFILE pages of other steam users as well as your OWN activity feed (both desktop and mobile versions on all browsers including steam browser/chromium). I would advise against viewing suspicious profiles until further notice and disable JavaScript in your browser options. Do NOT click suspicious (real) steam profile links and Disable JavaScript on Browser. Appropriate information has been forward to Valve and this issue should be resolved soon, sorry for any inconvenience.

     

     

    TO THOSE POSSIBLY AFFECTED:

     

    Change your Steam Account password, enable Mobile Authenticator if it's not on already (otherwise deauthorize other computers on Steam Guard on all systems from settings) then restart your modem/change IP. You might want to also consider scanning your system with a malware scanner/anti-virus.

     

    This is copied from the following thread on reddit:

     

    Please don't click any Steam profile links you find on this forum, or anywhere else, until Valve has fixed the issue! It's for the safety of your account.

     

    I will try to update here if there is new information. If any of you know more earlier, feel free to reply with a source here.

  3. Did you update your graphics card drivers?

    Did you try to switch to Borderless Windowed/Fullscreen mode? (Whatever you are not using at the moment)

    Did you use SLI? If so, try it without SLI

    If nothing helps, at least post the client logs. You can find instructions in the sticky post at the top of this forum.

    Also, please add your operating system to the post :)

     

  4. Merged a few topics with suggestions for map filters.

     


    Magiehammer, du solltest wirklich lieber deine Posts in zwei große Teile teilen, wenn du auf Deutsch und Englisch schreiben willst.

    So kann man das sehr schlecht lesen. Lieber erst komplett in der einen und dann komplett in der anderen Sprache schreiben, mit ner erkennbaren Trennung dazwischen ;)

  5. Not sure exactly, but its probably due to the fact that you have added a link to the site of the hoster and not a direct link to the picture. If you right-click on the picture and select "Open image in new tab" or similar, then you should get a link ending in .jpg or .png in your url bar.

     

    For your last picture the resulting link would be http://image.prntscr.com/image/c8650004300346aabd29dcb22c841b90.png

    That would show as follows: 

    c8650004300346aabd29dcb22c841b90.png

  6. Before you post, you should do the following:

    • Check if the problem is not yet answered in the FAQ
    • Make sure in the forum that it has not been reported yet and that your version of the game is actually the latest version.
    • Is it really a bug?
    • Is it reproducable? Can you repeat the steps that led to the unwanted behaviour or crash?
    • Use a separate thread for each bug.

     

    If all these factors are OK, you can post the bug on the board, including whether it was the server or the client that crashed.

    A Server Crash looks like this:

    • Connection Closed: Some Error on your screen
    • AvorionServer has stopped working

    A Client Crash looks like this:

    • Avorion just closes
    • Command windows pop up
    • Avorion has stopped working

     

    Always include the following information in the report:

    • The revision of the the game you are playing. You can find it in the main menu in the form rXXXX behind the version number.
    • A clear description of what happened.
    • Step-by-step instructions on how to reproduce the bug.
    • Your client and server log. Follow the instructions below on where to find them on your system.
    • Your system specs:
      • Operating System
      • CPU
      • GPU (if multiple GPUs, then all of them)

     

    How to find your logs:

    On Windows, you will find them in your %appdata%\AvorionDemo\ folder. Type %appdata% in your windows explorer's address bar to get there.

    On Linux, you will find them in your ~/.avoriondemo folder.

     

    The logs for the client are called clientlog XXXX.txt and the logs for the server are in the AvorionDemo\galaxies\[your galaxy name here]\ folder. They're called server XXXX.txt. XXXX is the timestamp of when you started that server. Look at the timestap, take the one where your game crashed or where you had trouble, and post it.

     

    How to add your logs if they are too big for the forum:

    Please post the contents of the logs on pastebin.com. Then add the link to your post.

    Try to create a new pastepin paste for each log file.

     

    The more information you post in here, the easier you make it for us to fix those bugs!

     

    I know bugs and crashes are annoying, but we're doing our best to keep up with your reports. It might not always be possible to fix everything at once, but we're doing the very best we can.

     

×
×
  • Create New...