Play AppSec WarGames
Want to skill-up in secure coding and AppSec? Try SecDim Wargames to learn how to find, hack and fix security vulnerabilities inspired by real-world incidents.
Kravets publicly disclosed this vulnerability after Valve initially addressed his previous report inadequately. His disclosure included detailed proof-of-concept videos demonstrating how attackers could exploit the vulnerability, highlighting the serious security implications. The exploit allowed potential attackers to disable system defenses, install rootkits, and steal user data. Valve controversially banned Kravets from its HackerOne bug bounty program after the disclosure, prompting further scrutiny of Valve’s vulnerability management practices.
We made a challenge in C# and Python to replicate this vulnerability:
Read more about the incident:
A new Zero-Day in Steam client impacts over 96 million Windows users - Security Affairs
Expert shows how to bypass a fix for a recently discovered Steam flaw
Want to skill-up in secure coding and AppSec? Try SecDim Wargames to learn how to find, hack and fix security vulnerabilities inspired by real-world incidents.
Join our secure coding and AppSec community. A discussion board to share and discuss all aspects of secure programming, AppSec, DevSecOps, fuzzing, cloudsec, AIsec code review, and more.
Read more