Watch Out For This Source Engine Exploit

If for any reason you find yourself playing a multiplayer Source Engine game DO NOT accept any invites from strangers.

Secret Club are a not-for-profit reverse engineering group who’ve found a number of exploits with Valve’s software, which they explain in a series of posts on Twitter. Each of these exploits are remote code execution flaws, which Secret Club told me via email gives a hacker “full control over the victim’s system, which can be used to steal passwords, banking information, and more.”

If what is being reported in the article is true then Valve has been aware of this exploit for two years. This is a serious exploit to have open in the wild, and hopefully the exposure encourages them to get off their duffs to 86 it from their code! Be very careful when playing Source games until this gets resolved.

It’s ironic reading this a day after playing around in GMod with Yutram! Fortunately, it was just the both of us goofing around on maps that would probably be unappealing to twelve year olds Fortnite enthusiasts.

Valve, you’ve gone too far.

Some of you might remember awhile back when I wrote about the pro’s and con’s of Steam, where I pointed out the good and bad with their recent choices. Probably one of the biggest points I touched on was the Steam Mobile Authenticator. I went into detail about how dependent Steam is on having your account tethered to a cell phone at the client level. But what about people who run dedicated servers for TF2, CS:GO, etc? I’m one of those people, and you want to know what the status is? Fucking stupid.

Last year I had to close down my CS:GO server when I discovered that I had to have a phone number attached to my account in order for it to function in anything but LAN mode. I decided to say screw it since it was the least popular server that I ran. Today however I noticed that for whatever reason my MvM Quickplay server was running insecure despite being set otherwise. Upon doing some research I discovered that a phone number must be associated with the Steam account the server is running off of. Oh, it’ll run. But in insecure mode, great huh? I feel like I’m being blackmailed… Either give us your phone number or your quickplay servers will never be secure again.

Fuck you Valve, and fuck the lowest common denominator for being stupid enough to get scammed, and practically forcing server owners like me to suffer the consequences of their stupid fucking actions. What the hell is the point of having a phone number tied to a server? I can at least kind of sort of see the point in clients having a phone number tied to their account for security reasons and VAC banning users who hack on an alt account tied to the same phone number, but why servers?!?!?!?!

The server software Valve provides for their Source Dedicated Servers is free, creating Steam accounts is free. It doesn’t take much to make an alt account with a cheap cellphone and a small game purchase on your account. So what fucking point are they trying to make?

Now I’m in a position where I’m contemplating if it’ll be worth it to get a cheap android to prevent this from happening to my other servers, or if I should just shut down when their time eventually comes. My MvM server was one of the more popular TF2 servers in my collection and I hate seeing it go because of Valve wanting a fucking cell number. If I do get an android though I’ll only use it for my alt server account. I’ll remove the battery and shove it in the drawer when I’m done. I fucking hate this.

Thoughts on the CS:GO comp scene

The talk about female CS:GO pro teams and tournaments has been picking up a bit lately. Which has sparked some controversy because ladies can participate in most tournaments, and if men made their own male only tournaments it would be considered sexist. Considering this isn’t a physical sport it wouldn’t make sense to segregate the genders, yet at the same time I can see why women would like the option of having their own tourney.

Competitive events (like most gaming events) have assholes, no doubt there are lots of asshats that will have no problem trying to find anything about said person or persons. I can understand trash talking to a certain point, and I myself don’t have any qualms about returning the favor as I have done so on multiple occasions 😛 . But women, and even some guys see the comp scene as a big turn off because they just want to play the damned game without having to deal with the manchildren! Perhaps some rules need to be made similar to men’s wrestling. No hitting below the belt. 😛 Any gender discrimination and you’re out, that would include both sides. Though I don’t see that becoming a thing.

So, perhaps female tourneys are a necessary evil. It should be known though that if it does take off it’ll most likely become it’s own thing like most women’s sports.

5 seconds of fame.

Aside from all the weirdness there was one cool thing that happened today. One of my steam buddies congratulated me about making the front page of Rock Paper Shotgun, this article to be exact. My map review of de_cyberwar was one of their choices. To be honest I was a bit blown away by it (and still am), because I never would have expected it. Still, pretty awesome. 😀