Posts

Showing posts from September, 2018

Linkfilter bypass in Steamcommunity.com (A valve Softwares) company - POC.

Image
Vulnerability in steamcommunity.com which could have landed the victm in decent trouble.   In my Submission i exploited the linkfilter parameter in such a way that even Valveservers are not able to decide if the redirected link is safe for your users or not by taking advantage of www.google.com (google prefix) where they had not put any prompt appearance/checks in place. However due to out of scope i was not paid bounty and the bug was resolved without crediting me which was very unfortunate.      Watch the POC VIDEO below:     link to video HD :  Youtube link to video. Thanks, Stay tuned for more POC's