ValveSoftware / Source-1-Games

Source 1 based games such as TF2 and Counter-Strike: Source
634 stars 74 forks source link

[All source games] Steam auth exploit/harvest by scammers #3857

Open Zeitgesit opened 2 years ago

Zeitgesit commented 2 years ago

Since now 1 year, there is an en-masse scam operation taking place on all Source based games platforms. The server is called Fastpath

They have found a way to exploit players steam auth tickets, keeping them long after the players have disconnected. Making their servers look packed. On each game platform they have created about 15 fake silent redirect servers. Rendering this a mass scale operation. This on repeat is emptying all legitimate servers. Making the few real ones impossible to find, lost in a sea of fake servers.

This operation has many facets, I will list a few here:

Could the exploit of steam auth tickets be patched. (I guess an extra timeout method must be added) Could the scammer's IP addresses be banned from Source games

stolenservernames

website

Zeitgesit commented 2 years ago

Today on the HL2DM platform, a total of 300 stolen steam auth tickets distributed over 30 fake servers and many players trapped. Legitimate servers are now completely empty for most. It is now official that fastpath has completely destroyed years of work for server owners on HL2DM and the platform itself. I am saddened that this topic has not been picked up.

Combine900 commented 2 years ago

@kisak-valve Can this thread get attension?

worMatty commented 2 years ago

@Combine900 can you please stop bumping issues. It won't bring fixes any sooner. All you are doing is annoying those of us who are subscribed to this repository.

Zeitgesit commented 1 year ago

@kisak-valve I am sorry to do this, but I have been trying to get this resolved since now over two years. Apologies if this annoyes you, but our game has been destroyed since two years and not a finger was lifted to help fixing it. The servers with 7 players are all fake redirect servers. The server on top is the scammer server with all these fake servers farming all possible new players into the abyss. This is now a desperate call for help.

Thank you

scamcontinues

kisak-valve commented 1 year ago

Hello @Zeitgesit, friendly reminder that I'm a moderator for Valve's issue trackers on Github, and not a Valve developer myself. We'll need to hear from a relevant dev for any insight into this issue.

Zeitgesit commented 1 year ago

@kisak-valve Thank you for taking the time to reply to me I really appreciate it. Do you think we even stand a chance of anyone at Valve considering to pick up this issue? Do you think someone has seen it?

ioa1994 commented 1 year ago

Sorry to continue bumping this per the comments above, but I reached this post from Google after booting up HL2DM having not played in many years. I accidentally joined a Fastpath server by attempting to join what I thought was a legitimate server, but got redirected. I played there for a few days and slowly realized the level of manipulation taking place at the player/bot level.

I noticed some players who I knew to be legitimate players, were somedays acting like bots. Sure enough, the "bots" as Zeitgeist explains, are really the names and auth tokens of users who had played on the server previously. The server operator has also overloaded the "status" command in the console so that it is not possible to list SteamIDs of bots on the server. Not only that, but I saw one of them post a message to the chat that I had posted the day prior. They are taking user's messages and "replaying" them in the chat as bots in order to appear more authentic. So you have bots saying "ggs" and "has anyone gone trick or treating" and various other messages - it took me until I saw my own message "replayed" that this is what was happening. I am sure my own username is appearing as a user well after I log off, too.

Valve's failure to respond to this issue through community channels and official (github) channels is a tacit confession that they are ready to kill the game, because that's exactly what's going to happen if legitimate server hosts' traffic is redirected to these scummy servers. Just thought I should put in my 2 cents.

Zeitgesit commented 1 year ago

I could not agree more with everything you say ioa. It gets worse and worse all the time. Lately the servers have over 24 fake players in, Each! Since more than 2 years, the player amount of HL2DM has been reduces drasticlly! There are now more players on HL1DM which is unthinkable. In anycase, id you look for a good place to play, you know where to find us.

Zeitgesit commented 1 year ago

Crickets

Zeitgesit commented 1 year ago

Look at the amount of hacking reports on that IP address, and still nothing is done by Steam or anyone else. https://www.abuseipdb.com/check/164.132.202.2

Zeitgesit commented 1 year ago

Good day everyone, and a wonderful start in 2023 I was just wondering if anyone at Valve were going to lift a finger about this devastating problem we have encountered for now 3 years ?

Zeitgesit commented 1 year ago

158.69.22.27 - The scam continues, years down the line, will anything be done?

Ashetf2 commented 1 year ago

I think the best you can do to make the issue more visible for now is to create a "community fix" in the tf2 workshop

Zeitgesit commented 1 year ago

Hey there Ashetf2, thanks for your comment. Would you be willing to help out with this? Could you otherwise point me to it? Many thanks!

Ashetf2 commented 1 year ago

Just create a submission in the Workshop. There are tutorials in the internet. However, you'll need to give your tax info for your submission to be public.

Zeitgesit commented 8 months ago

@kisak-valve Sorry to bombard you today! But this issue will soon be 2 years old. Would you have the capacity to poke a developer about this? Thanks again!

ioa1994 commented 8 months ago

@kisak-valve Sorry to bombard you today! But this issue will soon be 2 years old. Would you have the capacity to poke a developer about this? Thanks again!

Pinging @kisak-valve as well - The game is an absolute graveyard at this point. If Half Life Deathmatch can get the 25 year anniversary update, Half Life 2 Deathmatch should get it too. The details of this issue render the game basically unusable. Would really appreciate your escalating this to the dev team.

Zeitgesit commented 8 months ago

Just adding the updated blacklist here useful if you want to find games in your browser. server_blacklistDEC2023.zip

Zeitgesit commented 7 months ago

Adding one of many community discussions. https://steamcommunity.com/app/320/discussions/0/3114781060460063768/ Apparently they are scamming since 10 years! - we've been affected for 4 years. I woner how long it can take for this to be resolved.

dabcodmap commented 6 months ago

it looks like counter strike source has the same problem (i.e., infected by scummy fastpath servers). Any time i want to join another server i get redirected to their servers. is there any way to solve this issue? i'm a bit worried about safety of my own account since they duplicated it to create a bot

Zeitgesit commented 6 months ago

@dabcodmap - Quite bad yes. They also steal all the chats which they use in their bots! So if someone said something with sensitive information, it will be repeated to everyone on a regular basis. Crazy. If one day something is done about it, I will light up a candle.

dabcodmap commented 6 months ago

yes I noticed the chat thing too! imo, if valve and steam don't take action is because they want the source games to slowly die... quite sad. Still hope to light up that candle too though

Zeitgesit commented 6 months ago

@dabcodmap I am of the same opinion. Yes, let's hope they do something.

f-o commented 4 months ago

These guys have now spread to TF2 as well. Exactly same behaviour as described above.

I have had to resort to using community block-lists to fix this issue. Maybe this will be useful for other players as well.

https://steamcommunity.com/sharedfiles/filedetails/?id=2502626384

Zeitgesit commented 4 months ago

@f-o This is the blacklist I made which I always update. https://gamebanana.com/mods/289337

Zeitgesit commented 2 weeks ago

Over 2 years later and still nothing