TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Valve accused of ignoring existing RCE vulnerability in Source games for 2 years

225 pointsby mxschoabout 4 years ago

13 comments

dafelstabout 4 years ago
I have a friend who used to work at Valve as a software engineer - he mentioned to me that the entire source networking stack is chock full of unchecked buffers and all sorts of potential for fairly trivial RCEs, but due to Valve&#x27;s internal structure (or lack thereof) there really isn&#x27;t any incentive for anyone to fix them.<p>This was 5-6 odd years ago and he no longer works there, so things might have changed, but based on this tweet it seems unlikely.
评论 #26765017 未加载
评论 #26763128 未加载
评论 #26763348 未加载
sodality2about 4 years ago
Dozens of Counter-strike exploits exist and the cheating scene has just grown too rampantly. Valve simply doesn&#x27;t care about the source engine. Any new CSGO player will tell you the anti-cheat doesn&#x27;t work, I know first-hand.<p>The lack of care regarding source engine netcode extends to every part of the source engine, including Valve Anti-cheat.<p>The anti-cheat is trivial to reverse (several PUBLIC bypasses have existed for years on github, with zero patch), the engine source has been leaked, reverse engineered, and fiddled with by thousands of 14 year old kids. It is pathetically easy to bypass, for example, by changing a single byte in memory you can see through walls, see enemy money, etc. See this video I found about how miserably broken it is: <a href="https:&#x2F;&#x2F;files.catbox.moe&#x2F;8e3bxz.mp4" rel="nofollow">https:&#x2F;&#x2F;files.catbox.moe&#x2F;8e3bxz.mp4</a><p>It is in my opinion the greatest loss to gaming that a classic, legendary game like Counter-strike got completely ruined by lack of care by a company that profits millions off of the case unboxings.
评论 #26765301 未加载
评论 #26763870 未加载
评论 #26764710 未加载
评论 #26764973 未加载
评论 #26763772 未加载
评论 #26765817 未加载
评论 #26765652 未加载
guidovrankenabout 4 years ago
There&#x27;s a place for being patient and lenient, but HackerOne consistently seems to not shut down malfunctioning programs that never pay rewards and flat out stop talking to you, yet continue to collect bugs. Such a relationship is commonly called fraud so I suggest reporting HackerOne to the Federal Trade Commission as I have.<p>The premise of bug bounties is that the reward amount is at the discretion of the program host and that the time incurred by developing a fix will influence the moment of payout, but refusing to pay and even communicate (for years!) for clearly eligible submissions is well beyond a reasonable interpretation of the conditions, and to consistently keep facilitating this abuse is simply fraudulent.
评论 #26765858 未加载
xystabout 4 years ago
This is why I have a separate machine for &quot;gaming&quot; and &quot;work&quot;<p>Some game companies (riot games) even install their anti-cheat software so that is loads in the ring 0 space. Even with their best efforts, cheaters will still prosper.<p>Might even go a step further and firewall my gaming machine off from the rest of my network.
评论 #26762988 未加载
评论 #26763034 未加载
评论 #26763209 未加载
评论 #26762842 未加载
评论 #26765345 未加载
评论 #26763825 未加载
评论 #26764024 未加载
mxschoabout 4 years ago
According to a tweet that was also retweeted by the user @floesen_ who was mentioned in the original thread, the initial report 2 years ago was done using HackerOne but has probably not seen any helpful response from Valve [1]. There are also other reports of Valve not reacting to HackerOne reports appropriately [2].<p>It is currently unclear whether there is a publicly available PoC or any exploitation going on in the wild.<p>[1] <a href="https:&#x2F;&#x2F;twitter.com&#x2F;AntiCheatPD&#x2F;status&#x2F;1380873722966503426" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;AntiCheatPD&#x2F;status&#x2F;1380873722966503426</a><p>[2] <a href="https:&#x2F;&#x2F;twitter.com&#x2F;killa&#x2F;status&#x2F;1380872852090540032" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;killa&#x2F;status&#x2F;1380872852090540032</a>
评论 #26762682 未加载
评论 #26765781 未加载
评论 #26762588 未加载
gsichabout 4 years ago
2 years? Just leak it. At some point &quot;responsible&quot; disclose is not worth it.
评论 #26762869 未加载
评论 #26765685 未加载
Aissenabout 4 years ago
Totally believable. Someone I trust in the RE community told me about similar shenanigans when trying to report issues to Valve.
lgatsabout 4 years ago
CVE Assigned <a href="https:&#x2F;&#x2F;cve.report&#x2F;CVE-2021-30481" rel="nofollow">https:&#x2F;&#x2F;cve.report&#x2F;CVE-2021-30481</a>
dkarrasabout 4 years ago
It would be a shame if an &quot;anonymous hacker&quot; &quot;hacked&quot; @floesen_, found their notes about the RCE and released it to public, accidentally of course.
评论 #26765100 未加载
breakingcupsabout 4 years ago
At this point, just leak it to Project Zero anonymously and let them wring Valve&#x27;s hand for you.<p>There&#x27;s a small chance you might still get the bounty, because you reported it first. And if not, because it&#x27;s already disclosed by another party, you can cry foul on social media.
zokierabout 4 years ago
Source engine itself is at least 16 years old, and has pretty direct lineage to the original 21 year old Quake engine (Quake (-&gt; Quake II) -&gt; GoldSrc -&gt; Source). I would be more surprised if there weren&#x27;t lots of RCEs in it.
raszabout 4 years ago
Imagine you are Valve - why would you fix anything? Your money printer goes Brrr regardless, and legal assures you H1 deal prevent participants from leaking anything.
DanAtCabout 4 years ago
Unless you have the clout of Project Zero, &quot;responsible&quot; disclosure is anything but.<p>Full disclosure or no disclosure.