http://kb.digibase.ca/index.php?title=DBSA:2014-0003&feed=atom&action=historyDBSA:2014-0003 - Revision history2024-03-29T14:05:14ZRevision history for this page on the wikiMediaWiki 1.31.1http://kb.digibase.ca/index.php?title=DBSA:2014-0003&diff=551&oldid=prevKradorex Xeron at 15:47, 17 February 20142014-02-17T15:47:40Z<p></p>
<table class="diff diff-contentalign-left" data-mw="interface">
<col class="diff-marker" />
<col class="diff-content" />
<col class="diff-marker" />
<col class="diff-content" />
<tr class="diff-title" lang="en">
<td colspan="2" style="background-color: #fff; color: #222; text-align: center;">← Older revision</td>
<td colspan="2" style="background-color: #fff; color: #222; text-align: center;">Revision as of 15:47, 17 February 2014</td>
</tr><tr><td colspan="2" class="diff-lineno" id="mw-diff-left-l38" >Line 38:</td>
<td colspan="2" class="diff-lineno">Line 38:</td></tr>
<tr><td class='diff-marker'> </td><td style="background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>Despite the fact this mechanism may have legitimate purpose, this is an uninformed information disclosure and should be approached with caution as any potential for disclosure.</div></td><td class='diff-marker'> </td><td style="background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>Despite the fact this mechanism may have legitimate purpose, this is an uninformed information disclosure and should be approached with caution as any potential for disclosure.</div></td></tr>
<tr><td class='diff-marker'> </td><td style="background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"></td><td class='diff-marker'> </td><td style="background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"></td></tr>
<tr><td class='diff-marker'>−</td><td style="color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>If there are confidential or other similar websites that you have recently visited, to prevent potential disclosure of the number of websites you visit or potentially associating yourself with others that visit those sites, it is advised to clear your DNS cache:</div></td><td class='diff-marker'>+</td><td style="color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>If there are confidential or other similar websites that you have recently visited, to prevent potential disclosure of the number of websites you visit or potentially associating yourself with others that visit those sites, it is advised to clear your DNS cache <ins class="diffchange diffchange-inline">prior to starting the Valve software</ins>:</div></td></tr>
<tr><td class='diff-marker'> </td><td style="background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"></td><td class='diff-marker'> </td><td style="background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"></td></tr>
<tr><td class='diff-marker'> </td><td style="background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>'''Under Windows XP:'''</div></td><td class='diff-marker'> </td><td style="background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>'''Under Windows XP:'''</div></td></tr>
</table>Kradorex Xeronhttp://kb.digibase.ca/index.php?title=DBSA:2014-0003&diff=550&oldid=prevKradorex Xeron at 15:46, 17 February 20142014-02-17T15:46:31Z<p></p>
<table class="diff diff-contentalign-left" data-mw="interface">
<col class="diff-marker" />
<col class="diff-content" />
<col class="diff-marker" />
<col class="diff-content" />
<tr class="diff-title" lang="en">
<td colspan="2" style="background-color: #fff; color: #222; text-align: center;">← Older revision</td>
<td colspan="2" style="background-color: #fff; color: #222; text-align: center;">Revision as of 15:46, 17 February 2014</td>
</tr><tr><td colspan="2" class="diff-lineno" id="mw-diff-left-l42" >Line 42:</td>
<td colspan="2" class="diff-lineno">Line 42:</td></tr>
<tr><td class='diff-marker'> </td><td style="background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>'''Under Windows XP:'''</div></td><td class='diff-marker'> </td><td style="background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>'''Under Windows XP:'''</div></td></tr>
<tr><td class='diff-marker'> </td><td style="background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>* Press [Windows Key] + [R]</div></td><td class='diff-marker'> </td><td style="background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>* Press [Windows Key] + [R]</div></td></tr>
<tr><td class='diff-marker'>−</td><td style="color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>* <del class="diffchange diffchange-inline">'''</del>Enter into Run: '''cmd''' — hit enter.</div></td><td class='diff-marker'>+</td><td style="color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>* Enter into Run: '''cmd''' — hit enter.</div></td></tr>
<tr><td class='diff-marker'> </td><td style="background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>* Enter into the Command Line: '''ipconfig /flushdns''' — hit enter</div></td><td class='diff-marker'> </td><td style="background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>* Enter into the Command Line: '''ipconfig /flushdns''' — hit enter</div></td></tr>
<tr><td class='diff-marker'> </td><td style="background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>* Close the Command Line and start Steam as normal.</div></td><td class='diff-marker'> </td><td style="background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>* Close the Command Line and start Steam as normal.</div></td></tr>
</table>Kradorex Xeronhttp://kb.digibase.ca/index.php?title=DBSA:2014-0003&diff=549&oldid=prevKradorex Xeron at 15:45, 17 February 20142014-02-17T15:45:43Z<p></p>
<table class="diff diff-contentalign-left" data-mw="interface">
<col class="diff-marker" />
<col class="diff-content" />
<col class="diff-marker" />
<col class="diff-content" />
<tr class="diff-title" lang="en">
<td colspan="2" style="background-color: #fff; color: #222; text-align: center;">← Older revision</td>
<td colspan="2" style="background-color: #fff; color: #222; text-align: center;">Revision as of 15:45, 17 February 2014</td>
</tr><tr><td colspan="2" class="diff-lineno" id="mw-diff-left-l31" >Line 31:</td>
<td colspan="2" class="diff-lineno">Line 31:</td></tr>
<tr><td class='diff-marker'> </td><td style="background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"></td><td class='diff-marker'> </td><td style="background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"></td></tr>
<tr><td class='diff-marker'> </td><td style="background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>==Description==</div></td><td class='diff-marker'> </td><td style="background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>==Description==</div></td></tr>
<tr><td class='diff-marker'>−</td><td style="color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>Steam is a game software platform developed and published by the Valve Corporation that is capable of playing multiple games through a single common platform. Recently there was a disclosure that the Valve Anti-Cheat System (VAC) acquires the content of the Windows DNS cache and processes <del class="diffchange diffchange-inline">it</del>. Each entry is hashed and submitted to Valve-controlled servers likely for the purpose of checking to ensure cheats or malicious websites are not being utilized to tamper with the platform.</div></td><td class='diff-marker'>+</td><td style="color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>Steam is a game software platform developed and published by the Valve Corporation that is capable of playing multiple games through a single common platform. Recently there was a disclosure that the Valve Anti-Cheat System (VAC) acquires the content of the Windows DNS cache and processes <ins class="diffchange diffchange-inline">each entry sequentially</ins>. Each entry is hashed and submitted to Valve-controlled servers likely for the purpose of checking to ensure cheats or malicious websites are not being utilized to tamper with the platform<ins class="diffchange diffchange-inline">. Notwithstanding the hashing, this has the effect of disclosing information about what websites are visited and possibly provides a method of statistical analysis of those visitations</ins>.</div></td></tr>
<tr><td class='diff-marker'> </td><td style="background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"></td><td class='diff-marker'> </td><td style="background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"></td></tr>
<tr><td class='diff-marker'> </td><td style="background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>The hashing algorithm utilized is md5.</div></td><td class='diff-marker'> </td><td style="background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>The hashing algorithm utilized is md5.</div></td></tr>
</table>Kradorex Xeronhttp://kb.digibase.ca/index.php?title=DBSA:2014-0003&diff=547&oldid=prevKradorex Xeron at 15:33, 17 February 20142014-02-17T15:33:15Z<p></p>
<table class="diff diff-contentalign-left" data-mw="interface">
<col class="diff-marker" />
<col class="diff-content" />
<col class="diff-marker" />
<col class="diff-content" />
<tr class="diff-title" lang="en">
<td colspan="2" style="background-color: #fff; color: #222; text-align: center;">← Older revision</td>
<td colspan="2" style="background-color: #fff; color: #222; text-align: center;">Revision as of 15:33, 17 February 2014</td>
</tr><tr><td colspan="2" class="diff-lineno" id="mw-diff-left-l31" >Line 31:</td>
<td colspan="2" class="diff-lineno">Line 31:</td></tr>
<tr><td class='diff-marker'> </td><td style="background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"></td><td class='diff-marker'> </td><td style="background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"></td></tr>
<tr><td class='diff-marker'> </td><td style="background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>==Description==</div></td><td class='diff-marker'> </td><td style="background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>==Description==</div></td></tr>
<tr><td class='diff-marker'>−</td><td style="color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>Steam is a game software platform developed and published by the Valve Corporation that is capable of playing multiple games through a single common platform. Recently there was a disclosure that the Valve Anti-Cheat System (VAC) acquires the content of the Windows DNS cache and processes it. Each entry is hashed and submitted to Valve-controlled servers likely for the purpose of checking to ensure cheats or malicious websites are not being utilized.</div></td><td class='diff-marker'>+</td><td style="color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>Steam is a game software platform developed and published by the Valve Corporation that is capable of playing multiple games through a single common platform. Recently there was a disclosure that the Valve Anti-Cheat System (VAC) acquires the content of the Windows DNS cache and processes it. Each entry is hashed and submitted to Valve-controlled servers likely for the purpose of checking to ensure cheats or malicious websites are not being utilized <ins class="diffchange diffchange-inline">to tamper with the platform</ins>.</div></td></tr>
<tr><td class='diff-marker'> </td><td style="background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"></td><td class='diff-marker'> </td><td style="background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"></td></tr>
<tr><td class='diff-marker'>−</td><td style="color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div><del class="diffchange diffchange-inline">Processing prior to submission </del>is <del class="diffchange diffchange-inline">hashed via </del>md5 <del class="diffchange diffchange-inline">and submitted to the VAC servers</del>.</div></td><td class='diff-marker'>+</td><td style="color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div><ins class="diffchange diffchange-inline">The hashing algorithm utilized </ins>is md5.</div></td></tr>
<tr><td class='diff-marker'> </td><td style="background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"></td><td class='diff-marker'> </td><td style="background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"></td></tr>
<tr><td class='diff-marker'> </td><td style="background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>==Mitigation/Solution==</div></td><td class='diff-marker'> </td><td style="background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>==Mitigation/Solution==</div></td></tr>
<tr><td class='diff-marker'>−</td><td style="color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>Despite the fact this mechanism may have legitimate purpose, <del class="diffchange diffchange-inline">there </del>is an uninformed information disclosure and should be approached with caution as any potential for disclosure.</div></td><td class='diff-marker'>+</td><td style="color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>Despite the fact this mechanism may have legitimate purpose, <ins class="diffchange diffchange-inline">this </ins>is an uninformed information disclosure and should be approached with caution as any potential for disclosure.</div></td></tr>
<tr><td class='diff-marker'> </td><td style="background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"></td><td class='diff-marker'> </td><td style="background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"></td></tr>
<tr><td class='diff-marker'> </td><td style="background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>If there are confidential or other similar websites that you have recently visited, to prevent potential disclosure of the number of websites you visit or potentially associating yourself with others that visit those sites, it is advised to clear your DNS cache:</div></td><td class='diff-marker'> </td><td style="background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>If there are confidential or other similar websites that you have recently visited, to prevent potential disclosure of the number of websites you visit or potentially associating yourself with others that visit those sites, it is advised to clear your DNS cache:</div></td></tr>
</table>Kradorex Xeronhttp://kb.digibase.ca/index.php?title=DBSA:2014-0003&diff=546&oldid=prevKradorex Xeron at 15:31, 17 February 20142014-02-17T15:31:11Z<p></p>
<table class="diff diff-contentalign-left" data-mw="interface">
<col class="diff-marker" />
<col class="diff-content" />
<col class="diff-marker" />
<col class="diff-content" />
<tr class="diff-title" lang="en">
<td colspan="2" style="background-color: #fff; color: #222; text-align: center;">← Older revision</td>
<td colspan="2" style="background-color: #fff; color: #222; text-align: center;">Revision as of 15:31, 17 February 2014</td>
</tr><tr><td colspan="2" class="diff-lineno" id="mw-diff-left-l24" >Line 24:</td>
<td colspan="2" class="diff-lineno">Line 24:</td></tr>
<tr><td class='diff-marker'> </td><td style="background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>'''Severity:''' LOW</div></td><td class='diff-marker'> </td><td style="background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>'''Severity:''' LOW</div></td></tr>
<tr><td class='diff-marker'> </td><td style="background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"></td><td class='diff-marker'> </td><td style="background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"></td></tr>
<tr><td class='diff-marker'>−</td><td style="color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>'''Rationale:''' Information submitted is hashed<del class="diffchange diffchange-inline">.</del></div></td><td class='diff-marker'>+</td><td style="color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>'''Rationale:''' Information submitted is hashed <ins class="diffchange diffchange-inline">prior to submission</ins></div></td></tr>
<tr><td class='diff-marker'> </td><td style="background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"></td><td class='diff-marker'> </td><td style="background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"></td></tr>
<tr><td class='diff-marker'> </td><td style="background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>'''Spread of Issue:''' SINGLE-PLATFORM MODERATE</div></td><td class='diff-marker'> </td><td style="background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>'''Spread of Issue:''' SINGLE-PLATFORM MODERATE</div></td></tr>
</table>Kradorex Xeronhttp://kb.digibase.ca/index.php?title=DBSA:2014-0003&diff=545&oldid=prevKradorex Xeron: Created page with "{{DBSAHEAD | TITLE=Valve Anti-Cheat System (VAC) Scans Windows DNS Caches | KEYWORDS=Valve, Steam, Information Disclosure, DNS }} '''DBSA ID:''' {{PAGENAME}} '''Regarding:''..."2014-02-17T15:30:09Z<p>Created page with "{{DBSAHEAD | TITLE=Valve Anti-Cheat System (VAC) Scans Windows DNS Caches | KEYWORDS=Valve, Steam, Information Disclosure, DNS }} '''DBSA ID:''' {{PAGENAME}} '''Regarding:''..."</p>
<p><b>New page</b></p><div>{{DBSAHEAD<br />
| TITLE=Valve Anti-Cheat System (VAC) Scans Windows DNS Caches<br />
| KEYWORDS=Valve, Steam, Information Disclosure, DNS<br />
}}<br />
<br />
'''DBSA ID:''' {{PAGENAME}}<br />
<br />
'''Regarding:''' Valve Anti-Cheat System (VAC) Scans Windows DNS Caches<br />
<br />
'''Writeup:''' [[User:Kradorex Xeron|Kradorex Xeron]] ([[User talk:Kradorex Xeron|talk]]) 10:30, 17 February 2014 (EST)<br />
<br />
'''Date:''' 2014 02 17<br />
<br />
'''Last Modified:''' {{REVISIONTIMESTAMP}} by {{REVISIONUSER}}<br />
<br />
'''Who should take note:''' All Steam Users<br />
<br />
==Classification==<br />
<br />
'''Priority:''' MODERATE<br />
<br />
'''Rationale:''' Information is disclosed to a remote party without user awareness<br />
<br />
'''Severity:''' LOW<br />
<br />
'''Rationale:''' Information submitted is hashed.<br />
<br />
'''Spread of Issue:''' SINGLE-PLATFORM MODERATE<br />
<br />
'''Rationale:''' There are many users of the Steam game software platform under Windows<br />
<br />
==Description==<br />
Steam is a game software platform developed and published by the Valve Corporation that is capable of playing multiple games through a single common platform. Recently there was a disclosure that the Valve Anti-Cheat System (VAC) acquires the content of the Windows DNS cache and processes it. Each entry is hashed and submitted to Valve-controlled servers likely for the purpose of checking to ensure cheats or malicious websites are not being utilized.<br />
<br />
Processing prior to submission is hashed via md5 and submitted to the VAC servers.<br />
<br />
==Mitigation/Solution==<br />
Despite the fact this mechanism may have legitimate purpose, there is an uninformed information disclosure and should be approached with caution as any potential for disclosure.<br />
<br />
If there are confidential or other similar websites that you have recently visited, to prevent potential disclosure of the number of websites you visit or potentially associating yourself with others that visit those sites, it is advised to clear your DNS cache:<br />
<br />
'''Under Windows XP:'''<br />
* Press [Windows Key] + [R]<br />
* '''Enter into Run: '''cmd''' — hit enter.<br />
* Enter into the Command Line: '''ipconfig /flushdns''' — hit enter<br />
* Close the Command Line and start Steam as normal.<br />
<br />
'''Under Windows Vista/7:'''<br />
* Open the Start Menu<br />
* Enter into the bottom search box: '''command'''<br />
* Right Click Command Line and Start as Administrator (if UAC enabled), start normally otherwise.<br />
* Enter into the Command Line: '''ipconfig /flushdns''' — hit enter<br />
* Close the Command Line and start Steam as normal.<br />
<br />
'''Under Windows 8/8.1:'''<br />
* Press [Windows Key] + [F]<br />
* Enter into the search box: '''cmd''' — hit enter<br />
* Right Click on the cmd result<br />
* Click the Advanced button at the bottom and Run as Administrator<br />
* Enter into the Command Line: '''ipconfig /flushdns''' — hit enter<br />
* Close the Command Line and start Steam as normal.<br />
<br />
==References==<br />
* http://www.twitlonger.com/show/n_1s0hb3n<br />
* http://www.playerattack.com/news/2014/02/17/report-valve-anti-cheat-scans-your-dns-history/<br />
<br />
[[Category:DBSA|2014]]</div>Kradorex Xeron