SteamDesktopAuthenticator icon indicating copy to clipboard operation
SteamDesktopAuthenticator copied to clipboard

Prevent account from being stolen! Help!!

Open addee99 opened this issue 1 year ago • 24 comments

Hey. Yesterday I downloaded the ”SDA FIX” that was promoted in the ”issues”.

Now, I’m a bit worried its a scam. I have already traded all of the skins to my main account. But what Can I do to prevent it from being stolen? If I added the maFiles to the Authenticator. Does it help to change password?

I mean if they have the mafiles they can fu*k it up either way, right? Is there someting I can do to ensure it wont get hacked before its to late. Im not even sure if its a scam, but just to be on the safe side.

appreciate all the help!

addee99 avatar Jun 23 '23 19:06 addee99

Yeah it'll help to change your password. There's a reason why it's called "2 factor auth": you need both to log in.

That being said, changing your password doesn't help if they already have your session tokens. You should go into your steam account and deauthorize all the active login sessions: https://help.steampowered.com/en/faqs/view/06B0-26E6-2CF8-254C#deauthorize

dyc3 avatar Jun 23 '23 19:06 dyc3

Yeah it'll help to change your password. There's a reason why it's called "2 factor auth": you need both to log in.

That being said, changing your password doesn't help if they already have your session tokens. You should go into your steam account and deauthorize all the active login sessions: https://help.steampowered.com/en/faqs/view/06B0-26E6-2CF8-254C#deauthorize

So if they have my session tokens, im screwed either way? There is no way to solve that? And how do they get my session tokens?

addee99 avatar Jun 23 '23 20:06 addee99

suggest to also make sure there is no logger on your computer

itay0246 avatar Jun 23 '23 20:06 itay0246

activate the family mode in the accounts that seem important to you or have items, it could save you

xylokia avatar Jun 23 '23 20:06 xylokia

And another problem.. how do I change the password. It says I need to confirm the code sent to the mobile app… and I can’t find it in the original SDA app

addee99 avatar Jun 23 '23 20:06 addee99

activate the family mode in the accounts that seem important to you or have items, it could save you

Yeah, I did that too

addee99 avatar Jun 23 '23 20:06 addee99

So if they have my session tokens, im screwed either way?

No, per my previous reply:

You should go into your steam account and deauthorize all the active login sessions: https://help.steampowered.com/en/faqs/view/06B0-26E6-2CF8-254C#deauthorize

In case this was not clear, this invalidates the session tokens.

dyc3 avatar Jun 23 '23 21:06 dyc3

So if they have my session tokens, im screwed either way?

No, per my previous reply:

You should go into your steam account and deauthorize all the active login sessions: https://help.steampowered.com/en/faqs/view/06B0-26E6-2CF8-254C#deauthorize

In case this was not clear, this invalidates the session tokens.

Oh okay, im noob at all of this. So I deauthorize all devices now.

I Will change password too, but I have a problem. It says ”launch the Steam mobile app on your mobile device, then select the comfirmation menu option. Confirm the account recocery action in the app…”

i dont get any confirmations on my original SDA since its not working…

addee99 avatar Jun 23 '23 21:06 addee99

You can either:

  • transfer the authenticator to your phone (2 day trade ban)
  • use steamguard-cli (which I created and maintain), or some other application to accept the confirmation

dyc3 avatar Jun 23 '23 21:06 dyc3

You can either:

  • transfer the authenticator to your phone (2 day trade ban)
  • use steamguard-cli (which I created and maintain), or some other application to accept the confirmation

can I do one of the options or need to do both?

addee99 avatar Jun 23 '23 21:06 addee99

You can do either one. One or the other.

dyc3 avatar Jun 23 '23 21:06 dyc3

You can do either one. One or the other.

Alright, I will give it a try.

addee99 avatar Jun 23 '23 21:06 addee99

You can do either one. One or the other.

Is there any tutorial how to install and set it up? I have no idea how to do it

addee99 avatar Jun 23 '23 21:06 addee99

For steamguard-cli, there should be sufficient instructions in the README file, which can be read here. If they're unclear, ask your question here: https://github.com/dyc3/steamguard-cli/discussions/new?category=q-a

dyc3 avatar Jun 23 '23 22:06 dyc3

Hey. Yesterday I downloaded the ”SDA FIX” that was promoted in the ”issues”.

Now, I’m a bit worried its a scam. I have already traded all of the skins to my main account. But what Can I do to prevent it from being stolen? If I added the maFiles to the Authenticator. Does it help to change password?

I mean if they have the mafiles they can fu*k it up either way, right? Is there someting I can do to ensure it wont get hacked before its to late. Im not even sure if its a scam, but just to be on the safe side.

appreciate all the help!

if you used the one i posted, it is clean, anyone can check the code, it is open source, i forked it

therepower avatar Jun 23 '23 23:06 therepower

Hey. Yesterday I downloaded the ”SDA FIX” that was promoted in the ”issues”. Now, I’m a bit worried its a scam. I have already traded all of the skins to my main account. But what Can I do to prevent it from being stolen? If I added the maFiles to the Authenticator. Does it help to change password? I mean if they have the mafiles they can fu*k it up either way, right? Is there someting I can do to ensure it wont get hacked before its to late. Im not even sure if its a scam, but just to be on the safe side. appreciate all the help!

if you used the one i posted, it is clean, anyone can check the code, it is open source, i forked it

Alright. But I did not use that one.. I tried makcstudio so I dont know.

I would like to try yours but I dont understand how to set it up

addee99 avatar Jun 23 '23 23:06 addee99

You do not have to worry this much. I've used his trade bots for more than 2 years. Never had an issue even tho i added mafiles. So yeah don't worry to much but still take some actions to feel safer.

Jianchitz avatar Jun 24 '23 01:06 Jianchitz

You do not have to worry this much. I've used his trade bots for more than 2 years. Never had an issue even tho i added mafiles. So yeah don't worry to much but still take some actions to feel safer.

Did you use Makcstudios tradebots without problem?

addee99 avatar Jun 24 '23 08:06 addee99

Yes i used both free and paid versions. Didn't have a security issue ever so don't have to panic, but still take care

Jianchitz avatar Jun 24 '23 08:06 Jianchitz

he already told you you can deauth the session tokens..

dennis0555 avatar Jun 24 '23 17:06 dennis0555

Hey. Yesterday I downloaded the ”SDA FIX” that was promoted in the ”issues”. Now, I’m a bit worried its a scam. I have already traded all of the skins to my main account. But what Can I do to prevent it from being stolen? If I added the maFiles to the Authenticator. Does it help to change password? I mean if they have the mafiles they can fu*k it up either way, right? Is there someting I can do to ensure it wont get hacked before its to late. Im not even sure if its a scam, but just to be on the safe side. appreciate all the help!

if you used the one i posted, it is clean, anyone can check the code, it is open source, i forked it

The thing with that, is I think, most people don't even know how to code, so they can't even compare code between versions and be sure they are clean, so they worry.

pacopepepipo avatar Jun 24 '23 18:06 pacopepepipo

Hey. Yesterday I downloaded the ”SDA FIX” that was promoted in the ”issues”. Now, I’m a bit worried its a scam. I have already traded all of the skins to my main account. But what Can I do to prevent it from being stolen? If I added the maFiles to the Authenticator. Does it help to change password? I mean if they have the mafiles they can fu*k it up either way, right? Is there someting I can do to ensure it wont get hacked before its to late. Im not even sure if its a scam, but just to be on the safe side. appreciate all the help!

if you used the one i posted, it is clean, anyone can check the code, it is open source, i forked it

No it's not clean! My friend tried your "fix", and got all his items stolen in a couple of minutes. He checked his transaction history, and everything was transferred to this bot account : https://steamcommunity.com/profiles/76561199439296569 We contacted Steam Support to ban this bot account, but nothing happened yet. Moreover, Steam claims that : "Steam Support does not restore lost items", so my friend is screwed.

@therepower "anyone can check the code", yes but there is no proof that the "Release2.rar" file is the actual build of the source, and you added a mailicous code that use the user's token to transfer items.

TL;DR : DON'T USE THIS SDA FIX, IT WILL STEAL YOUR ITEMS

tour1st avatar Jun 27 '23 05:06 tour1st

Hey. Yesterday I downloaded the ”SDA FIX” that was promoted in the ”issues”. Now, I’m a bit worried its a scam. I have already traded all of the skins to my main account. But what Can I do to prevent it from being stolen? If I added the maFiles to the Authenticator. Does it help to change password? I mean if they have the mafiles they can fu*k it up either way, right? Is there someting I can do to ensure it wont get hacked before its to late. Im not even sure if its a scam, but just to be on the safe side. appreciate all the help!

if you used the one i posted, it is clean, anyone can check the code, it is open source, i forked it

Hello, does your version solve the problem of adding accounts? I'd like to give it a try.

allendaydayup avatar Jun 27 '23 06:06 allendaydayup

Hey. Yesterday I downloaded the ”SDA FIX” that was promoted in the ”issues”. Now, I’m a bit worried its a scam. I have already traded all of the skins to my main account. But what Can I do to prevent it from being stolen? If I added the maFiles to the Authenticator. Does it help to change password? I mean if they have the mafiles they can fu*k it up either way, right? Is there someting I can do to ensure it wont get hacked before its to late. Im not even sure if its a scam, but just to be on the safe side. appreciate all the help!

if you used the one i posted, it is clean, anyone can check the code, it is open source, i forked it

No it's not clean! My friend tried your "fix", and got all his items stolen in a couple of minutes. He checked his transaction history, and everything was transferred to this bot account : https://steamcommunity.com/profiles/76561199439296569 We contacted Steam Support to ban this bot account, but nothing happened yet. Moreover, Steam claims that : "Steam Support does not restore lost items", so my friend is screwed.

@therepower "anyone can check the code", yes but there is no proof that the "Release2.rar" file is the actual build of the source, and you added a mailicous code that use the user's token to transfer items.

TL;DR : DON'T USE THIS SDA FIX, IT WILL STEAL YOUR ITEMS

I've used it and a friend also, and no one scammed anything from us.

pacopepepipo avatar Jun 27 '23 12:06 pacopepepipo

FKK this russian guy he banned my main account etc! problaly couldnt steal shit because i changed encryption!

dennis0555 avatar Jul 05 '23 06:07 dennis0555

Hey. Yesterday I downloaded the ”SDA FIX” that was promoted in the ”issues”. Now, I’m a bit worried its a scam. I have already traded all of the skins to my main account. But what Can I do to prevent it from being stolen? If I added the maFiles to the Authenticator. Does it help to change password? I mean if they have the mafiles they can fu*k it up either way, right? Is there someting I can do to ensure it wont get hacked before its to late. Im not even sure if its a scam, but just to be on the safe side. appreciate all the help!

if you used the one i posted, it is clean, anyone can check the code, it is open source, i forked it

No it's not clean! My friend tried your "fix", and got all his items stolen in a couple of minutes. He checked his transaction history, and everything was transferred to this bot account : https://steamcommunity.com/profiles/76561199439296569 We contacted Steam Support to ban this bot account, but nothing happened yet. Moreover, Steam claims that : "Steam Support does not restore lost items", so my friend is screwed.

@therepower "anyone can check the code", yes but there is no proof that the "Release2.rar" file is the actual build of the source, and you added a mailicous code that use the user's token to transfer items.

TL;DR : DON'T USE THIS SDA FIX, IT WILL STEAL YOUR ITEMS

You don't need to use my fix anymore, Jessecar fixed the original version, If you think my version is malicious just change your pw.

-- Update the account you posted is the official account of tradeit.gg, contact them

therepower avatar Jul 08 '23 19:07 therepower

Hey. Yesterday I downloaded the ”SDA FIX” that was promoted in the ”issues”. Now, I’m a bit worried its a scam. I have already traded all of the skins to my main account. But what Can I do to prevent it from being stolen? If I added the maFiles to the Authenticator. Does it help to change password? I mean if they have the mafiles they can fu*k it up either way, right? Is there someting I can do to ensure it wont get hacked before its to late. Im not even sure if its a scam, but just to be on the safe side. appreciate all the help!

if you used the one i posted, it is clean, anyone can check the code, it is open source, i forked it

No it's not clean! My friend tried your "fix", and got all his items stolen in a couple of minutes. He checked his transaction history, and everything was transferred to this bot account : https://steamcommunity.com/profiles/76561199439296569 We contacted Steam Support to ban this bot account, but nothing happened yet. Moreover, Steam claims that : "Steam Support does not restore lost items", so my friend is screwed. @therepower "anyone can check the code", yes but there is no proof that the "Release2.rar" file is the actual build of the source, and you added a mailicous code that use the user's token to transfer items. TL;DR : DON'T USE THIS SDA FIX, IT WILL STEAL YOUR ITEMS

You don't need to use my fix anymore, Jessecar fixed the original version, If you think my version is malicious just change your pw.

-- Update the account you posted is the official account of tradeit.gg, contact them

@therepower Could we have a quick chat? I want to solve this case once and for all. Just provide me an email or any social network ID where I can contact you, or add me on Discord : tour1st#6985

tour1st avatar Jul 10 '23 18:07 tour1st

@therepower Still waiting for your answer...

tour1st avatar Jul 20 '23 05:07 tour1st

@therepower Still waiting for your answer...

@therepower Bump

tour1st avatar Aug 05 '23 14:08 tour1st

@therepower Still waiting for your answer...

@therepower Bump

@therepower Bump again

tour1st avatar Aug 13 '23 18:08 tour1st