• Ever wanted an RSS feed of all your favorite gaming news sites? Go check out our new Gaming Headlines feed! Read more about it here.
  • We have made minor adjustments to how the search bar works on ResetEra. You can read about the changes here.

deadasdisco

Member
Jun 10, 2018
548
Valve has rewarded a man with $20,000 after he discovered a bug which let people generate thousands of free codes at once for any game.

The flaw was rooted out by security researcher Artem Moskowsky who reported it to Valve on August 7.

https://www.gamesindustry.biz/artic...for-discovering-unlimited-free-game-codes-bug


Mod Edit:

https://hackerone.com/reports/391217

Using the /partnercdkeys/assignkeys/ endpoint on partner.steamgames.com with specific parameters, an authenticated user could download previously-generated CD keys for a game which they would not normally have access. Audit logs were not bypassed using this method, and an investigation of those audit logs did not show any prior or ongoing exploitation of this bug.
 
Last edited by a moderator:

Durante

Dark Souls Man
Member
Oct 24, 2017
5,074
That's not particularly unusual for bug bounty programs for larger companies, as far as I know (security isn't really my field).
 

no1

Attempted to circumvent ban with alt account
Banned
Apr 27, 2018
954
That's not particularly unusual for bug bounty programs for larger companies, as far as I know (security isn't really my field).
Yeah google pays around the same.

Mods should change the title to make it more accurate as the bug didn't give you new codes. Only ones that were premade generated, so a good chance all of those keys were already redeemed.
 

mrtl

Banned
Oct 27, 2017
827
AFAIK you needed access to publish games on Steam to abuse this bug/exploit. Sounds like a good reward.
 

OMEGALUL

Banned
Oct 10, 2018
539
Why so low? He could have exploited the system to get generate free keys and sell millions. what a dumbass.
 

Deleted member 8752

User requested account closure
Banned
Oct 26, 2017
10,122
Impressive that he was able to find such a bug. It's amazing how talented some people are with this stuff.
 

Deleted member 36578

Dec 21, 2017
26,561
The article says he previously received $25,000 as well for another thing related to this . I wonder if he does this sort of thing often.
 

Weltall Zero

Game Developer
Banned
Oct 26, 2017
19,343
Madrid
Yeah google pays around the same.

Mods should change the title to make it more accurate as the bug didn't give you new codes. Only ones that were premade generated, so a good chance all of those keys were already redeemed.

Since codes are actually generated when needed, this is quite the huge difference (basically the difference between being able to reading from a database, and being able to write to it: think of the difference that would make if it was your bank account).
 

Deleted member 2618

User requested account closure
Banned
Oct 25, 2017
2,176
Damn...

Now I wonder what secrets this man held that Valve didn't know.
Screenshot_20181113-113002_Chrome.jpg
 

Deleted member 1849

User requested account closure
Banned
Oct 25, 2017
6,986
It look them 3 months to acknowledge this bug, I don't think Valve gives a shit.
I was under the impression that Valve acknowledged and fixed it within a couple of weeks, but asked him to not talk about it publicly for 3 months. Pretty sure Valve do give a shit.

20k is also not bad for a bug bounty. Chrome bounties vary between $1-15k for instance
 

nded

Member
Nov 14, 2017
10,572
I imagine setting up a store to sell stolen keys is quite a hassle, and partnering up with an existing store would cut into profits. Then you'd probably have to limit how much you sell to fly under the radar and even then someone would probably figure out what's going on and fix it plus get your ass sued.

I'd have taken the bounty too, to be honest.

I was under the impression that Valve acknowledged and fixed it within a couple of weeks, but asked him to not talk about it publicly for 3 months. Pretty sure Valve do give a shit.

20k is also not bad for a bug bounty. Chrome bounties vary between $1-15k for instance

Yep.
Moskowsky reported the bug to Valve in August via the company's HackerOne bug bounty platform, and the company fixed it within days but only recently allowed him to go public with his findings.
 

no1

Attempted to circumvent ban with alt account
Banned
Apr 27, 2018
954
Where are you getting this from? It's not in the linked article.
From the actual bug report.
https://hackerone.com/reports/391217
Since codes are actually generated when needed, this is quite the huge difference (basically the difference between being able to reading from a database, and being able to write to it: think of the difference that would make if it was your bank account).

Yup, one is a multi-million dollar problem, one is a lot less expensive.
 

Weltall Zero

Game Developer
Banned
Oct 26, 2017
19,343
Madrid
This guy is sounds like an idiot. A good idiot, but an idiot.

What the fuck prompted you to say such a thing? I mean, nothing says "this guy is an idiot" like "finding a vulnerability that nobody else figured out in the biggest PC game portal, and getting paid five digits for it", right? :P

Edit: Correction, two vulnerabilities:
This is not Moskowsky's largest payout from Valve however; in July he received $25,000 for discovering an SQL Injection bug in the same portal.
 

Deleted member 1849

User requested account closure
Banned
Oct 25, 2017
6,986
I've seen a lot of dumb stuff on this forum, but labeling an obviously intelligent guy an idiot just because he chose to be a white hat hacker instead of a criminal is definitely one of the worst.