Video Games

PC, Sony PSP, Playstation, PS 2, PS 3, Nintendo GBA, Gamecube, Revolution, Microsoft xBox, xBox 2 Console and Gaming News

Valve Hacked: Cafe Credit Cards Compromised

Posted in Hacks, Security, Half Life, Half Life 2 by Elliott Back on April 23rd, 2007. [Del.icio.us]

MaddoxX, a member of hacking group no-steam recently cracked one of VALVe’s file servers and obtained strange bits of confidential information, including credit card numbers, Valve software assets, and private security keys. Steam-review claims that because a Steam server was not compromised, there is no danger. Doug Lombardi, director of marketing at Valve, issued a statement with a similar sentiment:

There has been no security breach of Steam. The alleged hacker gained access to a third-party site that Valve uses to manage the commercial partners in its Cyber Cafe program. This Cyber Cafe billing system is not connected to Steam. We are working with law enforcement agencies on this matter, and encourage anyone with more information to e-mail us at Catch_A_Thief@valvesoftware.com .

Is this an authentic break-in at Valve, or just hype spun out of proportion by the blogosphere? Our favorite gaming site, 1Up, sheds a bit more light:

We ran all of MaddoxX’s proof by a software security expert who requested anonymity. “This looks real to me. He found a way into [Valve’s] Cyber Café software,” the security expert confirms, “but what I’ve seen — the files pulled down — don’t indicate whether or not he breached Valve itself.”

hl2.jpg

The data MaddoxX released includes:

- Screenshots of internal Valve web pages
- A portion of Valve’s Cafe directory
- Error logs
- Credit card information of customers
- Financial information on Valve

It’s our opinion that the hack is legit, and that Valve’s security model is flawed. If one file-server can be compromised, they all can. If they can’t, then Valve is deploying servers haphazardly, leading to the possibility that flaws will sporadically exist which can be used to exploit their customer base. If you play Counterstrike or Half-life, be scared.

This entry was posted on Monday, April 23rd, 2007 at 8:27 pm and is tagged with doug lombardi, credit card numbers, strange bits, software assets, security breach, error logs, hacking group, directory error, file servers, security keys, 1up, s cafe, law enforcement agencies, commercial partners, valve software, security expert, security model, director of marketing, cyber cafe, billing system. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback.

Leave a Reply

Please take time to enjoy the archives: June 2008 (1) May 2008 (1) April 2008 (1) March 2008 (1) January 2008 (1) December 2007 (1) November 2007 (3) October 2007 (5) September 2007 (2) August 2007 (2) July 2007 (2) June 2007 (4) May 2007 (9) April 2007 (3) March 2007 (1) February 2007 (8) January 2007 (16) December 2006 (10) November 2006 (7) October 2006 (4) September 2006 (6) August 2006 (12) July 2006 (24) June 2006 (26) May 2006 (6) April 2006 (23) March 2006 (14) February 2006 (10) January 2006 (18) December 2005 (34) November 2005 (46) October 2005 (36)

Fresh, related resources:

Supplied by Google Blog Search
  • Data Dysprotection: breaches reported last week
    Dutch police arrested a 20-year-old man known by the online handle “MaddoxX,” who is suspected of hacking into a third party Valve file server and stealing 50000 credit card numbers of Steam Cyber Cafe users. ...
  • Valve Hacked: Cafe Credit Cards Compromised
    ... including credit card numbers, Valve software assets, and private security keys. Steam-review claims that because a Steam server was not compromised, there is no danger. Doug Lombardi, director of marketing at Valve, [...]
  • Valve Hacked: Cafe Credit Cards Compromised
    mail, 1up, maddoxx, security breach, sporadically, steam, haphazardly, blogosphere, file servers, cyber cafe, security expert, credit card, valve software, s cafe, requested anonymity, hacking group, strange bits, doug lombardi, ...
  • Steam “Hacked” Update
    Furthermore, the site explains that only the credit cards of Cyber Cafe subscribers were compromised. "The numbers in danger are all held by cybercafe owners, who have recurring subscriptions to their Steam games and have probably all ...