Jump to content
Forumu Destekleyenlere Katılın ×
Paticik Forumları
2000 lerden beri faal olan, çok şukela bir paylaşım platformuyuz. Hoşgeldiniz.

Steam Hesap Sorunları - 25/12/15


Sam

Öne çıkan mesajlar

Thankfully,
no new purchases could be made - despite users being able to see the amount of funds in another users' Steam wallet, as well as censored information on linked credit cards such as the last few digits. Account details could not be changed, either.

But the information linked to accounts could still be used to compromise other services

At present it appears to been a caching error on Valve's part, which ended up serving the wrong pages to the wrong people.

eurogamer
Link to comment
Sosyal ağlarda paylaş

said:


It's a problem with their caching-server (varnish), caching pages that should not be cached (such as Account-Details, Cart, etc.). It invalidates after some time and is re-cached when the next user visits the page with their profile. You are not actually logged in (as in, you take over the session of the user), you just see pages rendered for others than yourself. This is why different parts of steam appear as different users.

Which page you see is probably dependent on the edge node (first server you connect to) closest to you, hence why different users see different profiles.

My guess to how this could've happened is that an untested configuration got activated when steam went down earlier, e.g. due to an auto-conf service (puppet, chef) pulling an untested config or some of their live servers being replaced by staging / development servers. It's also possible that they were under heavy load and the engineer on duty reconfigured all their edge nodes to cache more aggressively.

Let's hope they fix this fast, because this is a major data leak. I can see private E-Mail and account names. Let's hope their cache server is not delivering internal pages.

Credit to: /u/mrallon
Link to comment
Sosyal ağlarda paylaş

×
×
  • Yeni Oluştur...