STEAM GROUP
TF2 Outpost by Fanbyte
Membership by invitation only
STEAM GROUP
TF2 Outpost by Fanbyte
3,975
IN-GAME
32,137
ONLINE
Founded
7 August, 2011
Language
English
Showing 1-10 of 222 entries
11
too many scanners !!!
15
Regarding Anti-phishing measures
Sneeza posted recently that we had implemented some measures to mitigate phishing attacks launched on our users via TF2 Outpost, and many of you have seen reduced phishing attempts since it was implemented.

The mode of operation for these phishing bots is pretty simple:

  1. Load front page of tf2outpost.com et al
  2. Scan for 64 bit steamIDs (just 17 digit numbers -- /\d{17}/g)
  3. Add these people -- some bots do this by loading steam://addfriend[...] URLs, others (I hope) are more sophisticated than this.
  4. Bot periodically, or someone manually copies and pastes (yes really) some kind of link that looks like steamhost.cn/steamcommunity_com but isn't.
  5. The not-really-steamcommunity website records your login details when you type them in.
  6. They do what they want with your account.

After some discussion we isolated that phishing on Steam is difficult to solve because we don't have data on the activities on users like Valve do.

Solving this problem, then means we need to measure how many people someone is attempting to add.

Our solution works like this:

  • Where we would normally have SteamIDs, we have URLs that pass through to the steamID, for example my steamcommunity link now goes to: http://www.tf2outpost.com/user/4/resolve/community which uses my Outpost user ID and not my 64 bit SteamID. The actual redirect is done through a Location header, which shouldn't confuse any good HTTP client and shouldn't impact our SEO.
  • We record hits on a per-IP basis on these pass-through links.
  • If someone makes too many requests for SteamIDs, we lock them out.

If any other website want to pick up the baton and implement these measures, I'm sure we'd see a reduction in phishing activity.
7
Can you add an option to search for items by name?
7
Colored text
3
My tf2 outpost avatar changed ?! o.O
3
Bans.
3
I did a bad thing.
Showing 1-10 of 222 entries