Our glorious leader (and giver of bot) Archi found an exploit in the points system. In order to ensure that support sees the issue as quickly as possible, please bump the thread so that support users can see the ticket about this issue! No details about the exploit will be posted here, but it's in the ticket that only support members can see (even I haven't seen it).

Proof
Support ticket
Bribe so you bump the thread
Archi's comment

Please note: I am just the messenger; please don't shoot me. I have never used the exploit myself. The exploit requires quite a few resources, so it should be difficult to reproduce, and hopefully support can shut down the loophole before the actual mechanism gets leaked. Our intention in creating this thread is to make it as visible as possible so that it can be fixed as quickly as possible.

8 years ago*

Comment has been collapsed.

oh no!
BUMP

8 years ago
Permalink

Comment has been collapsed.

sneezes

8 years ago
Permalink

Comment has been collapsed.

Bump bump bump

8 years ago
Permalink

Comment has been collapsed.

an exploitative bump

8 years ago
Permalink

Comment has been collapsed.

bump

8 years ago
Permalink

Comment has been collapsed.

BUMP

8 years ago
Permalink

Comment has been collapsed.

And bot users...

View attached image.
8 years ago
Permalink

Comment has been collapsed.

bump because Zed salt delicious today :3

8 years ago
Permalink

Comment has been collapsed.

write a script to bank your points at the giveaways ending last. of course you'll need a command to withdraw your points when you need them, and there, you have technically-not-infinite-but-might-as-well-call-it-infinite points. EZ-PeeZ. not that i'm capable to write a script but this shouldn't be that hard to do. am i on the dark side now, or did i just point out the obvious?

8 years ago
Permalink

Comment has been collapsed.

The exploit actually creates infinite amount of points out of nowhere, I wouldn't create a support ticket adressed to cg if I found out the obvious.

And yes, you did point out the obvious, at least for smarter users, I'm sorry ;_;.

8 years ago*
Permalink

Comment has been collapsed.

i was referring to my comment. i didn't mean i found out your way.

edit:

And yes, you did point out the obvious, at least for smarter users.

;_;

8 years ago
Permalink

Comment has been collapsed.

It would still require a bot/script that would do the stashing, I can't see a point in that, if I wanted to write something like that I'd most likely just create a script that joins highest-chances-giveaways when my points are near 250, instead of stashing them somewhere. I mean, if you are writing a bot, the primary objective is to automate something and operate 24/7. You don't need a script to stash points at given time, you can do it manually considering all of your points are usually being stashed in 5-10 giveaways.

8 years ago
Permalink

Comment has been collapsed.

i don't really know how scripts work but wouldn't it run while steamgifts is open on a tab? if you keep steamgifts tab open for a couple of hours a day, it would be enough. you don't really need it to operate 24/7. until you go for a long vacation of course.

8 years ago
Permalink

Comment has been collapsed.

That's the difference between bot and a script.

Bot is supposed to be independent and autonomous. ArchiBoT is a good example, because it handles my Touhou Giveaways 24/7 regardless of what I'm doing, or if my PC is even turned on, because it's working on my server.

Script is supposed to help user automate some tasks, making it easier to achieve particular thing. It can't operate on it's own, it's an extension to already existing mechanism, such as Chrome browser.

What you suggest is making a script. And even if it'd operate like you described, you'd need to do the stashing only 3 times per day, because 300P limit is enough for around 8h of inactivity.

As I said, if you'd be up for writing something like that, I'd just suggest writing something better - automatic giveaway joining instead.

Thing is, noone of this is really fair towards other users.

8 years ago
Permalink

Comment has been collapsed.

then write a bot instead of a script. like i said i'm not capable of writing these (thus i don't know much about them.). i didn't think this through, neither i want to exploit the system. i just saw the thread, read it, thought for a second and came up with this. why? i guess i don't have anything better to do. i don't get why you took it so serious.

8 years ago
Permalink

Comment has been collapsed.

Yeah, and I spotted some little flaws in your logic, and corrected them by suggesting writing something better instead, I don't know why you took my reply so serious, I guess I forgot to post :3.

8 years ago
Permalink

Comment has been collapsed.

well done sounding obnoxious and mean > :P

8 years ago
Permalink

Comment has been collapsed.

Holy crapsies X_X
Bumpitty

8 years ago
Permalink

Comment has been collapsed.

Our intention in creating this thread is to make it as visible as possible so that it can be fixed as quickly as possible.

I hate to sound like a jackass, but this is kind of a silly idea. Support will get to the ticket, usually quickly enough when it isn't a user report. Doesn't this thread just let anyone browsing the forum KNOW that there's an exploit "available"? Basically, wouldn't it have been wiser to keep quiet about it until the issue is resolved?

Just my two cents.

8 years ago
Permalink

Comment has been collapsed.

I suppose that, yes, creating the thread lets people know that there are ways to exploit the point system. However, this exploit is neither new (it seems to have been extant since at least SGv2, if not longer, and Archi thinks that the exploit has been used by some people even before it was leaked) nor does our leak provide enough information to narrow it down to the point where it could be easier to exploit. While some idiot users might take this leak as an excuse to go hunting for an exploit, hopefully support can lock it down before they could, with how ambiguous our leak is, figure out what we are alluding to. Also, I will be closing the thread as soon as support gets back to us.

8 years ago
Permalink

Comment has been collapsed.

I still fail to see how creating this thread will help the situation in any way. If, like you say, the exploit has been around since SGv2, then it doesn't really make the issue so important that there is an urgent need for it to be resolved as fast as possible. It has been around for months, it can wait a few more days. :P

Then again, I don't suppose creating a thread will affect anything. Seems pointless, but I guess it's also harmless.

8 years ago
Permalink

Comment has been collapsed.

Support is flooded by tickets, and our logic was that it's faster if we keep the thread up near the top so support actually sees the ticket and it doesn't slip through the cracks. That's all; it's as much visibility as urgency, though getting it fixed quicker would probably be best.

8 years ago
Permalink

Comment has been collapsed.

I don't agree with you here. Jatan pushed my ticket to admin's queue like 30 minutes before, while my ArchiBoT ticket has already 3 days, and it's same category, adressed to same guy (cg).

So yes, that thread made it easier for me, even if I didn't ask for it.

8 years ago*
Permalink

Comment has been collapsed.

My point was that the issue does not necessarily need to be taken care of immediately. Sure, it's a major issue, but I kinda feel, based on the pros vs the cons of creating this thread, that it would have been better to keep this to support ticket, rather than public. But heck, like I said, this is only my personal opinion. I don't really mind the thread myself.

8 years ago
Permalink

Comment has been collapsed.

making public "i found a bug" helps no one and it's pointless... unless you want to shame cg for not fixing it.

8 years ago
Permalink

Comment has been collapsed.

how i can make to have same steamgift ..like on video black and in easy mod

8 years ago
Permalink

Comment has been collapsed.

http://www.steamgifts.com/discussion/1SCgV/sg-add-ons-registry-updated-31-december-2015 has some themes that reskin the site. I don't know what exact extensions Archi is using.

8 years ago
Permalink

Comment has been collapsed.

Zed pointed above. I'm using:

  • SteamGifts v2 Dark Userstyle
  • SG++
  • EasySteamgifts for comment panel on top
8 years ago
Permalink

Comment has been collapsed.

Bump for support

8 years ago
Permalink

Comment has been collapsed.

Deleted

This comment was deleted 5 years ago.

8 years ago
Permalink

Comment has been collapsed.

View attached image.
8 years ago
Permalink

Comment has been collapsed.

led monitor is a deadly combination with white back ground

8 years ago
Permalink

Comment has been collapsed.

bumm

8 years ago
Permalink

Comment has been collapsed.

8 years ago
Permalink

Comment has been collapsed.

Bump!!

8 years ago
Permalink

Comment has been collapsed.

Thank you for the bribe, bump!

8 years ago
Permalink

Comment has been collapsed.

Dammit, now I have to find out how this works so I can sit on thousands of points without spending any.
(Seriously though, I can't recall the last time I was under 220. What do people spend the points on?)

8 years ago
Permalink

Comment has been collapsed.

bump

8 years ago
Permalink

Comment has been collapsed.

View attached image.
8 years ago
Permalink

Comment has been collapsed.

Try to join to the SG chat, sometimes supports are there semi-afk (i would, but i got banned because boobs)

8 years ago
Permalink

Comment has been collapsed.

You'll get told "submit a support ticket". The chat isn't for support reason and they really hate it when someone does that.

8 years ago
Permalink

Comment has been collapsed.

Well, i think that a massive exploit like this could be a exception, its not like, hey, this user won the same game twice, ban pls

8 years ago
Permalink

Comment has been collapsed.

From what I've seen, there aren't exceptions to this rule. They're pretty strict about the "Don't contact support member outside of support ticket" thing.

8 years ago
Permalink

Comment has been collapsed.

Well, then lets bump this :p

8 years ago
Permalink

Comment has been collapsed.

Bump

8 years ago
Permalink

Comment has been collapsed.

Bump!

8 years ago
Permalink

Comment has been collapsed.

bumpsy

8 years ago
Permalink

Comment has been collapsed.

Closed 8 years ago by bobofatt.